Project

General

Profile

Activity

From 12/27/2016 to 01/25/2017

01/25/2017

09:40 PM Bug #7164: NTP page allows adding more time server rows than it saves to the configuration
I can't answer the question of why other than it is generally not recommended to specify a large number of time serve... Jack Booth
09:30 PM Bug #7164: NTP page allows adding more time server rows than it saves to the configuration
Why is the page limited to 10 servers? Is this limitation enforced elsewhere in the system? Anonymous
09:28 PM Bug #7164: NTP page allows adding more time server rows than it saves to the configuration
PR https://github.com/pfsense/pfsense/pull/3446 Jack Booth
09:19 PM Bug #7164 (Resolved): NTP page allows adding more time server rows than it saves to the configuration
The NTP configuration page has a button to add more time servers to use as a time source. Only 10 servers are saved t... Jack Booth
04:56 PM Bug #7149: igb driver queue related crashes
I also can confirm this issue on my box as well.
I have 6 igb (Intel pro 1000) interfaces (4 on the asus mainboard...
Philipp Haefelfinger
03:14 PM Bug #7157: Traffic graphs cause the tab to crash when run in the background
Pretty sure they will crash in the foreground also.. Think ive found a leak in the code though.
The nv.utils.inherit...
Pi Ba
02:40 PM Bug #7075 (Feedback): firewall states show negative value for total bytes processed
Should be fixed now: https://github.com/pfsense/FreeBSD-ports/commit/2f5f4b5ac53ead4c12761273a3cc332b08806e26
Unfo...
Luiz Souza
02:31 PM Bug #6630: Set Defaults for Graphs - Traffic/WAN + Packets/WAN doesn't work
Not seeing this issue either, Set as Defaults is working fine for me too. Malcolm Hussain-Gambles
02:29 PM Bug #6132: race condition in OpenVPN startup
Fresh install and one OpenVPN server seems to work fine for me with fresh install from Dec and no probs with latest b... Malcolm Hussain-Gambles
02:25 PM Bug #7151: Interface Group Name hint is misleading
"Only letters (A-Z), digits (0-9), '-' and '_' are allowed. The group name cannot end with a digit." appears in lates... Malcolm Hussain-Gambles
01:37 PM Bug #6820 (Feedback): Configure WAN Interface Boot Delay
I was seeing this issue on all my test VMs too but on recent snapshots it seems to be OK, probably some change have f... Renato Botelho
01:29 PM Bug #6811 (Resolved): pkg_edit.php rowhelper is broken with multiple distinct rowhelpers per page.
3 months with no complains is like enough time to consider it fixed Renato Botelho
01:24 PM Bug #7036 (Not a Bug): 2.4 ZFS on RCC-VE 2440 hangs
After internal tests, we could install it successfully on 2440 using ZFS. Discussion will continue on forum thread li... Renato Botelho
01:22 PM Bug #6911 (Rejected): no network on hyperv-v 2012 R1
There is no much we can do at this point for a release that seems to be unsupported by Microsoft according https://su... Renato Botelho
01:20 PM Bug #6880: Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
Ok great, I will definitely try 2.4b then. If you happen to know which commits are relevant to that fix I'd love to l... → luckman212
01:17 PM Bug #6880: Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
Its not, it's a problem that appears from time to time and is quite intermittent. In 2.4b changes have been made whic... Martin Wasley
11:08 AM Bug #6880: Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
I have a dual WAN 2.3.2-p1 system with only one of the WANs configured for DHCP6 (not PPPoE, just Ethernet) and I am ... → luckman212
12:44 PM Feature #7159 (Feedback): Auto correct checksum and missing special characters for NTP GPS initialization commands.
PR has been merged, thanks! Renato Botelho
11:08 AM Bug #5993: dhcp6c not started until an RA received
And the fixes are for dhcp6c the WAN client, not dhcpd the LAN server. Different things.
First, enable dhcp6c debu...
Martin Wasley
10:52 AM Bug #7163: IGMP Proxy does not valid inputs
If someone confirms what the validation requirements are, I can make it so. Phillip Davis
10:51 AM Bug #7163 (Resolved): IGMP Proxy does not valid inputs
IGMP Proxy Edit
Threshold: no validation is done, I can put "abc" "-42"... - I think it must be a positive integer...
Phillip Davis
08:49 AM Bug #7143: filterdns is triggering every 16 seconds for hosts even when the DNS record has not changed
This only happens when config file uses the directive 'cmd', in this case, ipsec session is using it:... Renato Botelho
08:43 AM Bug #5319: Error message "No config named" in charon daemon
With 2.3.2, in a hub and spoke model of IPsec tunnels, when the hub was restarted, about 10 percent of the spoke mode... Alex Vergilis
07:58 AM pfSense Packages Bug #6988: SNORT Package PHP memory error
Your logs are way too huge! Configure something sane on Logs Mgmt tab. (You can override the memory limit in https://... Kill Bill
07:47 AM Bug #7162 (Rejected): XMLRPC lock in backup node if offline
That is not a supported configuration, in part due to the issues you have noted. Without connectivity for the seconda... Jim Pingle
03:45 AM Bug #7162 (Rejected): XMLRPC lock in backup node if offline
I have 2 Netgate SG-4860 installed with pfsense v. 2.3.2_1, with 1 carp vip on wan. The backup machine, however, rema... Stefano Aldeni
07:23 AM Bug #7124 (Confirmed): Kernel panic when configuring 6to4 on a interface
Renato Botelho
05:56 AM Bug #7123 (Resolved): Kernel panic when setting TCP MD5 Password in OpenBGP
Renato Botelho
05:10 AM Bug #7123: Kernel panic when setting TCP MD5 Password in OpenBGP
Renato Botelho wrote:
> Possible fix was cherry-picked to FreeBSD-src, please try again on next snapshot
Great, t...
Rolf Sommerhalder
04:31 AM pfSense Packages Bug #6305: Quagga problems updating routes / mistakenly showing "kernel"-routes while they are not
https://github.com/pfsense/FreeBSD-ports/pull/265 - that's not a real solution obviously, so kindly leave this bug op... Kill Bill
01:47 AM Bug #7145: rc.newwanipv6 running in all cases, even for a renew
Use this too, just makes the logging a little tidier. If this is implemented then the dhcp6withoutRA PR I have curren... Martin Wasley
01:04 AM Bug #7145: rc.newwanipv6 running in all cases, even for a renew
Yes, attached..
As dhcp6c only calls the script function when the above reply states happen you don't get quite as...
Martin Wasley

01/24/2017

10:03 PM Feature #4606: PKI : CA signing external CSR
I'd also love to see this functionality. Many Ubiquiti devices only support outputting a CSR instead of importing a k... Andy Sayler
05:18 PM Bug #7145: rc.newwanipv6 running in all cases, even for a renew
Got a source patch for that? If I do manage to try it, I am not keen on running binaries from outside sources. Jim Pingle
02:40 PM Bug #7145: rc.newwanipv6 running in all cases, even for a renew
Try this...
These are pulled from the reply state, and are what is displayed in dhcp6c logs, well mine at least. T...
Martin Wasley
12:31 PM Bug #7145: rc.newwanipv6 running in all cases, even for a renew
It would probably be good enough if dhcp6c properly populated REASON with what actually happened. If it's a simple re... Jim Pingle
12:19 PM Bug #7145: rc.newwanipv6 running in all cases, even for a renew
I can have a look at dhcp6c, easy enough to add something. What do you want it do do, set an env stating what trigger... Martin Wasley
10:21 AM Bug #6448: Mousing over aliases on disabled rules makes hint difficult to read
This is fixed in the following commit: https://github.com/pfsense/pfsense/commit/d9bad9e8863bb91cb568b3b41470e22a20d9... Jared Dillard
10:10 AM Bug #6448 (Feedback): Mousing over aliases on disabled rules makes hint difficult to read
Applied in changeset commit:d9bad9e8863bb91cb568b3b41470e22a20d9fa6e. Anonymous
09:49 AM Bug #7128: system_advanced_network.php - fugly IPv6 over IPv4 input field alignment
Hmmm? This just broke the vertical alignment altogether and did nothing with the input field?
!https://i.imgsafe.o...
Kill Bill
09:43 AM Bug #7086: stale zfs file systems
Thank you. Vladimir Suhhanov
05:24 AM Bug #7086: stale zfs file systems
Vladimir Putin wrote:
> What are the risks to continue using updated versions without reinstall?
There are no ris...
Renato Botelho
09:42 AM Bug #6836: Wrong queue length on "/status_queues.php" page under heavy traffic
Sorry, I see no reason, just outrage and not from my side. Vladimir Suhhanov
05:34 AM Bug #6836 (Rejected): Wrong queue length on "/status_queues.php" page under heavy traffic
rejected for reasons shown in-thread. Jim Thompson
09:41 AM Feature #6914: unbound access-control lists
Merged. Kill Bill
08:49 AM pfSense Packages Bug #6490 (Rejected): Squid Reverse Proxy: Disabling an entry on the "Redirects" tab creates duplicate entries for the previous entry in the squid config
Jim Pingle
08:35 AM pfSense Packages Bug #6490: Squid Reverse Proxy: Disabling an entry on the "Redirects" tab creates duplicate entries for the previous entry in the squid config
Cannot reproduce, plus suspect it's more or less a duplicate of another non-reproducible issue filed by the same user... Kill Bill
07:25 AM pfSense Packages Bug #7161 (Resolved): pfSense-pkg-bind9 changelog pointing to non-existent location
The changelog link should point to https://github.com/pfsense/FreeBSD-ports/tree/devel/dns/pfSense-pkg-bind9 while it... Kill Bill
07:11 AM pfSense Packages Feature #3754 (Closed): Add APC Back-UPS CS to NUT
Jim Pingle
07:08 AM pfSense Packages Feature #3754: Add APC Back-UPS CS to NUT
No feedback, related to ancient package version, plus apparently not a pfSense issue either. Retest with current pack... Kill Bill
06:35 AM pfSense Packages Bug #5869: Squid non-functional in transparent mode in 2.3
Here’s the mail I got recently for my problem
I was not able to get to these sites at the time of my first post but ...
john Smith
03:40 AM Bug #7149: igb driver queue related crashes
Rolf Sommerhalder wrote:
...
> This morning, we have added this potential work around on three systems. No crashes ...
Rolf Sommerhalder

01/23/2017

11:28 PM Feature #7159: Auto correct checksum and missing special characters for NTP GPS initialization commands.
PR https://github.com/pfsense/pfsense/pull/3433 Jack Booth
09:30 PM Feature #7159 (Resolved): Auto correct checksum and missing special characters for NTP GPS initialization commands.
The current NTP GPS configuration has a field for users to customize the GPS initialization commands. These NMEA comm... Jack Booth
10:05 PM Todo #7160 (Resolved): Mark Required Fields on GUI Pages
Redmine 7083 provided the infrastructure to mark GUI fields as "required" and the UI implementation underlines fields... Phillip Davis
07:59 PM Bug #7086: stale zfs file systems
What are the risks to continue using updated versions without reinstall? Vladimir Suhhanov
05:20 AM Bug #7086: stale zfs file systems
Tobias Wigand wrote:
> Fresh install worked without problems. Can't say anything about the original problem, not eno...
Renato Botelho
04:34 PM Bug #6630 (Feedback): Set Defaults for Graphs - Traffic/WAN + Packets/WAN doesn't work
This is not longer an issue. It must have been fixed in a previous commit. Jared Dillard
03:45 PM Feature #7158 (Rejected): Captive Portal should have logs facilities for blocked sites
Whenever I have problems connecting to sites from client software that does not have proxy settings there is no way t... Jose Torres
03:11 PM Bug #7156: Change in 'Block bogon networks' or 'Block private netowrks' GUI options kills routing entries for OpenVPN interfaces.
It could probably be documented in a way that calls more attention to it, but it is mentioned in the documentation wh... Jim Pingle
03:06 PM Bug #7156: Change in 'Block bogon networks' or 'Block private netowrks' GUI options kills routing entries for OpenVPN interfaces.
How is one supposed to know that this is a requirement? It's exactly not self-evident that changing something as sim... Karl Fife
02:23 PM Bug #7156 (Rejected): Change in 'Block bogon networks' or 'Block private netowrks' GUI options kills routing entries for OpenVPN interfaces.
Any time you save/apply changes on an assigned OpenVPN interfaces you have to restart the VPN. It's always been that ... Jim Pingle
01:57 PM Bug #7156 (Rejected): Change in 'Block bogon networks' or 'Block private netowrks' GUI options kills routing entries for OpenVPN interfaces.
It appears that toggling in the 'Block bogon networks' and/or 'Block private netowrks' GUI option kills the automatic... Karl Fife
03:07 PM Bug #7157 (Resolved): Traffic graphs cause the tab to crash when run in the background
When the "Keep graphs updated when on inactive tab" option is selected for traffic graphs it can cause the tab to loc... Jared Dillard
11:14 AM Bug #7155 (Resolved): services_dhcp_relay.php: Section hide/show gets out of synch with enable checkbox
Replace ->toggle code with jQuery for reliability Anonymous
11:11 AM Bug #5993: dhcp6c not started until an RA received
Barring unforeseen changes, you should not expect the behaviour to change between now and the release version. I've b... Daryl Morse
02:20 AM Bug #5993: dhcp6c not started until an RA received
Thanks.
I'm on the 2.4 snapshot and upon reboot I have to disable and enable the DHCPv6 server for it to properly ...
J L
12:53 AM Bug #5993: dhcp6c not started until an RA received
J L wrote:
> Daryl Morse wrote:
> > I installed the additional patch that Martin provided to address the request fo...
Daryl Morse
12:29 AM Bug #5993: dhcp6c not started until an RA received
Daryl Morse wrote:
> I installed the additional patch that Martin provided to address the request for changes. I've ...
J L
11:00 AM Bug #6958 (Feedback): services_dhcp_relay.php: Needs to be converted to more recent rowhelper standard
Applied in changeset commit:81fd21019cd0de8300fa0480cff1973d58d28e03. Anonymous
10:22 AM pfSense Packages Bug #6350: Auto Config Backup - Uncaught Exception
Steve Beaver wrote:
> Fixed by populating version table when info request fails
I don't remember what package ver...
Simon Trigona
09:10 AM pfSense Packages Bug #6350 (Feedback): Auto Config Backup - Uncaught Exception
Fixed by populating version table when info request fails Anonymous
10:00 AM Bug #7128: system_advanced_network.php - fugly IPv6 over IPv4 input field alignment
Applied in changeset commit:b33d32a500fe722035de3efc6a6d50c8cdae6f16. Anonymous
09:53 AM Bug #7128 (Feedback): system_advanced_network.php - fugly IPv6 over IPv4 input field alignment
Anonymous
09:24 AM Bug #6864 (Resolved): Error checking rejects IPv6 addresses with upper case A-F.
Anonymous
09:10 AM Bug #7151 (Feedback): Interface Group Name hint is misleading
Applied in changeset commit:351ef3ef2ac1bbcfb0643a5efc46a3970d06d78c. Phillip Davis
12:05 AM Bug #7151: Interface Group Name hint is misleading
Assuming the real requirement is what is in the validation code, I updated the front-end GUI text in:
https://github...
Phillip Davis
09:07 AM Bug #7119: Changing LAGG attributes results in a panic/crash
Here, it still panics + dumps + reboots same as it did originally. Jim Pingle
01:01 AM Bug #7119: Changing LAGG attributes results in a panic/crash
To be more precise: pfSense does not exactly "crash", as it is still ping-able. And SSH shells that were open from be... Rolf Sommerhalder
09:06 AM pfSense Packages Bug #6968 (Rejected): Snort VRT Rules Fail to automatically update SSL read error
Jim Pingle
05:09 AM pfSense Packages Bug #6968: Snort VRT Rules Fail to automatically update SSL read error
Upstream server issue, has nothing to do with pfSense. Close please. Kill Bill
08:32 AM Bug #7150 (Feedback): shell option before 1st reboot/wizard - can't login
It should be fixed on next round of snapshots Renato Botelho
07:50 AM Bug #6967: DH Groups 22, 23, 24 missing from Phase 2 selection GUI
Applied in changeset commit:0be9d722226790674bd35c8087286442e5766232. Anonymous
07:48 AM Bug #6967 (Feedback): DH Groups 22, 23, 24 missing from Phase 2 selection GUI
Anonymous
05:43 AM Bug #7121 (Resolved): freshclam.conf advanced editing, configuring value of "Checks" has no effect on crontab entry
Renato Botelho
05:13 AM Bug #7121: freshclam.conf advanced editing, configuring value of "Checks" has no effect on crontab entry
All that could be done here is fixed with https://github.com/pfsense/FreeBSD-ports/pull/254 and https://github.com/pf... Kill Bill
04:51 AM Bug #7149: igb driver queue related crashes
On Supermicro SuperServers 5018D-FN8T with X10SDV-TP8F motherboards, that feature six igb and two ix NICs, we experie... Rolf Sommerhalder

01/22/2017

10:33 PM Bug #7154: firewall_nat_edit JS function check_for_aliases()
I suspect the requirement might be:
If the user enters a port alias in any of destination from/to (dest begin, des...
Phillip Davis
10:27 PM Bug #7154 (Resolved): firewall_nat_edit JS function check_for_aliases()
The code in this function seems to be ineffective. e.g. it has sequences like:
@
if ($('#dstbeginport_cust').val...
Phillip Davis
05:26 PM Bug #7153 (Resolved): pkg-utils.inc - register_all_installed_packages() does not handle packages that are missing XML
After seeing "Running last steps of Status_Traffic_Totals installation" on every reboot, I did some digging into the ... Kill Bill
10:57 AM Bug #6852: Commit 8f86722 breaks DHCPv6 leases status page
does reverting this commit in 2.3.3 with a patch (i dont know how) fix this its really annoying not having this popul... Michael Kellogg
10:01 AM Bug #7147: pfsense-utils.inc - is_ipaddr_configured() does not work properly with some IPv6 formats
I'll take this one. Luiz Souza
03:52 AM Bug #7147: pfsense-utils.inc - is_ipaddr_configured() does not work properly with some IPv6 formats
Yes, option (c) is the most flexible - let users put in whatever format they like (within reason) and deal with it in... Phillip Davis
03:32 AM Bug #7147: pfsense-utils.inc - is_ipaddr_configured() does not work properly with some IPv6 formats
I'd rather avoid input validation here. Would just upset users for no good reason. Kill Bill
03:17 AM Bug #7147: pfsense-utils.inc - is_ipaddr_configured() does not work properly with some IPv6 formats
There are a few approaches to a full fix throughout the system:
a) Catch this at input validation, always store a "c...
Phillip Davis
03:08 AM Bug #7147: pfsense-utils.inc - is_ipaddr_configured() does not work properly with some IPv6 formats
PR https://github.com/pfsense/pfsense/pull/3414 should fix the particular bug reported here and make a start on fixin... Phillip Davis
02:28 AM Bug #7147: pfsense-utils.inc - is_ipaddr_configured() does not work properly with some IPv6 formats
Yeah, they definitely should be compressed before comparing. I hit this case since I've copied the local LAN IP from ... Kill Bill
02:18 AM Bug #7147: pfsense-utils.inc - is_ipaddr_configured() does not work properly with some IPv6 formats
Net_IPv6 validation allows compressed addresses that are not strictly in the "correct" compressed form.
e.g.
2001:2...
Phillip Davis
09:58 AM Bug #7152 (New): Unbound / DNS Resolver issue if "Register DHCP static mappings in the DNS Resolver" set before wildcard DNS custom options
Tested on:
2.3.2-RELEASE-p1 (amd64)
built on Tue Sep 27 12:13:07 CDT 2016
FreeBSD 10.3-RELEASE-p9
To create ...
Rudolph Sand
08:04 AM Bug #7151 (Resolved): Interface Group Name hint is misleading
On the Interface Groups Edit page, Group Name field, it says "No numbers or spaces are allowed. Only characters: a-zA... Phillip Davis
06:03 AM Bug #7150 (Resolved): shell option before 1st reboot/wizard - can't login
_(Posted "on forum":https://forum.pfsense.org/index.php?topic=124335.0 and confirmed by another user)_
Default cle...
Stilez y
02:55 AM Bug #7149 (Resolved): igb driver queue related crashes
Some 2.4 installations tend to crash out of nowhere related to igb driver queues.
Setting...
Anonymous

01/21/2017

05:41 PM Feature #4242: Two Factor or OTP Authentication for Admin Interface
Ping. I'd love this as a built in feature! I'm using the local database and dont want to get into managing another sy... Dan Journo
12:03 PM Bug #5993: dhcp6c not started until an RA received
I installed the additional patch that Martin provided to address the request for changes. I've tested both patches to... Daryl Morse
09:38 AM Bug #7086: stale zfs file systems
Fresh install worked without problems. Can't say anything about the original problem, not enough knowledge in that ar... Anonymous
08:50 AM Bug #7148 (Duplicate): Spoofed mac addresses on VLAN interfaces apply to the same physical interface
I was replacing a virtual machine with a physical pfSense box. In effort to minimize the change experienced by the ne... Øyvind Hvidsten
04:15 AM Bug #6099: igmpproxy does not recognize upstream interface
You can find the sources to build the FreeBSD/pfSense package at: https://github.com/pfsense/FreeBSD-ports/tree/devel... Harald Gutmann

01/20/2017

04:54 PM Bug #7147 (Resolved): pfsense-utils.inc - is_ipaddr_configured() does not work properly with some IPv6 formats
This one is working:... Kill Bill
04:28 PM Bug #6099: igmpproxy does not recognize upstream interface
Greg Myran wrote:
> > Where can I download the latest version of IGMPProxy? Or is the only way to upgrade my pfSense...
Lars Veldcholte
04:20 PM Bug #6099: igmpproxy does not recognize upstream interface

> Where can I download the latest version of IGMPProxy? Or is the only way to upgrade my pfSense to the dev version...
Greg Myran
02:42 PM Bug #5993: dhcp6c not started until an RA received
Martin Wasley wrote:
> PR #3410
I've been testing this PR since this morning. I've found that pfsense reliably ac...
Daryl Morse
12:52 PM Bug #5993: dhcp6c not started until an RA received
PR #3410 Martin Wasley
02:02 PM Bug #7119: Changing LAGG attributes results in a panic/crash
Snapshots from this morning still crash with igb hardware NICs. Rolf Sommerhalder
11:18 AM Bug #7119: Changing LAGG attributes results in a panic/crash
I couldn't reproduce it on a VM using em driver, probably something specific to igb as mentioned Renato Botelho
11:24 AM Bug #7146: install_cron_job() causes inexplicable issues when saving package configuration
Saw that, just merged+cherry-picked it all around.
FYI: Uses of install_cron_job in packages:...
Jim Pingle
11:06 AM Bug #7146: install_cron_job() causes inexplicable issues when saving package configuration
Thanks for looking into this. Meanwhile, I did https://github.com/pfsense/FreeBSD-ports/pull/261 since it's generally... Kill Bill
10:52 AM Bug #7146: install_cron_job() causes inexplicable issues when saving package configuration
I don't see anything in the base system that would be affected by removing the write_config() from install_cron_job()... Jim Pingle
10:50 AM Bug #7146: install_cron_job() causes inexplicable issues when saving package configuration
The squid issue seems indeed fixed by nuking the @<custom_add_php_command>@ tag. Still would seem desirable to let ju... Kill Bill
10:28 AM Bug #7146: install_cron_job() causes inexplicable issues when saving package configuration
There may yet be a problem with install_cron_job() doing a write the way it does, but the squid problem appears to be... Jim Pingle
08:50 AM Bug #7146: install_cron_job() causes inexplicable issues when saving package configuration
I reproduced this on multiple 2.3.3 boxes.Anything but */$minutes * * * * causes the issue. E.g., tried just changing... Kill Bill
08:41 AM Bug #7146: install_cron_job() causes inexplicable issues when saving package configuration
Oddly enough I can't seem to reproduce this, at least on 2.4.
I suspect adding this just after the install_cron_jo...
Jim Pingle
05:58 AM Bug #7146 (Closed): install_cron_job() causes inexplicable issues when saving package configuration
So, this commit https://github.com/pfsense/FreeBSD-ports/pull/254 caused Squid to be unable to save the configuration... Kill Bill
09:23 AM Bug #7086 (Feedback): stale zfs file systems
A fresh install using next round of snapshots is required to validate the fix. Thanks! Renato Botelho
05:30 AM Bug #7086 (Assigned): stale zfs file systems
Yes, it broke ZFS install and I see why. I'll push a fix soon Renato Botelho
02:55 AM Bug #7086: stale zfs file systems
Tried a fresh install, maybe there is a problem with this change?
It gave me...
Anonymous
05:56 AM Bug #7083: Put back some visual hint for required fields
I have added a new function to pfSenseHelpers.js to allow an input to be dynamically set as required (or not). e.g.:
...
Anonymous
01:06 AM Bug #7083: Put back some visual hint for required fields
Dependency between Dial On Demand checkbox and Idle Timeout field Phillip Davis
12:35 AM Bug #7083: Put back some visual hint for required fields
Sometimes the "required" status of a field is data dependent and needs to be set/cleared as the page loads depending ... Phillip Davis
05:22 AM Bug #7121: freshclam.conf advanced editing, configuring value of "Checks" has no effect on crontab entry
The change broke saving General settings in Squid. https://forum.pfsense.org/index.php?topic=124218.0; will get that ... Kill Bill

01/19/2017

10:23 PM Bug #7075: firewall states show negative value for total bytes processed
Yes, that is true. It depends on what "long" does in the environment in which the C is compiled. When compiled in the... Phillip Davis
05:55 PM Bug #7075: firewall states show negative value for total bytes processed
This isn't a PHP problem. pfSense_get_pf_rules() is a PHP function written in C as part of php56-pfSense-module. It c... Matt Perry
09:06 AM Bug #7075: firewall states show negative value for total bytes processed
These are both 32-bit installs (i386). So MAXINT will be int(2147483647) (2 gig). The numbers are returned by:
$rule...
Phillip Davis
09:20 PM Feature #4606: PKI : CA signing external CSR
+1 - I would very much like the ability to use the pfSense managed CA for signing my other internal CSRs within my ne... Ian Gallagher
03:36 PM Feature #5549 (Resolved): Additional DNS entries in General Setup would be good for 3 or more WAN's
This seems to work fine as-is. No need to check/validate someone's unintentional misconfiguration. At least it did er... Jim Pingle
03:25 PM Feature #6591 (Resolved): Configurable DDNS check IP services
Works well. I setup my own and tested it out, it queried the script as expected and used the result. Jim Pingle
03:10 PM Bug #7139 (Resolved): User with some pages plus Help cannot use page help
Works, thanks! Jim Pingle
06:30 AM Bug #7139 (Feedback): User with some pages plus Help cannot use page help
Applied in changeset commit:166540830275318c8dec9199d8a9ee0e605f606a. Phillip Davis
03:52 AM Bug #7139: User with some pages plus Help cannot use page help
The "?" or the Help menu item "About this page" point to a URL like:
help.php?page=services_dhcp.php
The code tha...
Phillip Davis
03:48 AM Bug #7139 (Resolved): User with some pages plus Help cannot use page help
1) Create a new user "u1". Give the user some page privs (e.g. Services-DHCP) plus "Help - all pages".
2) Logout of ...
Phillip Davis
03:10 PM Bug #7141 (Resolved): There is no way to grant just access to Services->UPNP
Works, thanks! Jim Pingle
06:30 AM Bug #7141 (Feedback): There is no way to grant just access to Services->UPNP
Applied in changeset commit:a5a899e4388f2737a6d1cdc82c7325c20fb72ee4. Phillip Davis
05:52 AM Bug #7141: There is no way to grant just access to Services->UPNP
Mentioned in forum https://forum.pfsense.org/index.php?topic=123520.0
PR https://github.com/pfsense/pfsense/pull/3402
Phillip Davis
05:27 AM Bug #7141 (Resolved): There is no way to grant just access to Services->UPNP
If you add the privs for pkg.php, pkg_edit.php then all the various package menu items of packages that use package X... Phillip Davis
03:08 PM Bug #7136 (Resolved): OpenVPN not binding to IP Aliases -> NO LOGS generated
Failed without the new code, works fine with the fix in place. Looks good. Jim Pingle
06:30 AM Bug #7136 (Feedback): OpenVPN not binding to IP Aliases -> NO LOGS generated
Applied in changeset commit:ddf99718d5f1f4545483c39d3759fdfbb788b0fb. Phillip Davis
12:44 AM Bug #7136: OpenVPN not binding to IP Aliases -> NO LOGS generated
Yes, the code does not even try to start such an OpenVPN instance, thus there are no logs.
This PR fixes it on my te...
Phillip Davis
02:51 PM Bug #7133 (Resolved): services_router_advertisements.php: Interface drop-down is not showing the user-configured interface name
Works now Jim Pingle
02:23 PM Bug #7112: Traffic Graphs resets graph when browser tab changes
https://github.com/pfsense/pfsense/pull/3384 Michael Kellogg
01:55 PM Bug #7112: Traffic Graphs resets graph when browser tab changes
Pablo Trincavelli wrote:
> The new traffic graphs resets graphs when the actual browser tab is changed, so the graph...
Michael Newton
01:32 PM Bug #6099: igmpproxy does not recognize upstream interface
I have the same issue to IPTV as Alexandre, and have the same version. Is there anyway to update the patch fix for IG... Jeremy Lewis
01:19 PM Bug #6099: igmpproxy does not recognize upstream interface
Alexandre Paradis wrote:
> Is the change also available to 2.3.3 branch ?
I have the same question. Where can I f...
Lars Veldcholte
01:29 PM Bug #2073: APIPA broadcasts forwarded by route-to
Jim Pingle wrote:
> There is no GUI knob to disable it, but there is a setting. You can set it in the config.xml dir...
Brandon Jackson
12:59 PM Bug #7086 (Feedback): stale zfs file systems
I've reviewed which volumes are created during install on ZFS and also made changes on rc script to mount /var and /t... Renato Botelho
11:55 AM Bug #5993: dhcp6c not started until an RA received
As they say, this has been an experience.
This whole 5993 started because we needed dhcp6 before RA, and a quick f...
Martin Wasley
11:28 AM Bug #7119 (Confirmed): Changing LAGG attributes results in a panic/crash
Still crashes on the latest factory snapshot: Wed Jan 18 19:49:46 CST 2017 Jim Pingle
11:28 AM Bug #7083 (Resolved): Put back some visual hint for required fields
Renato Botelho
11:02 AM Bug #7083: Put back some visual hint for required fields
Works nicely (tested with a recent 2.3.3 snapshot and bunch of packages - squid, ntopng, shellcmd, ftpproxy). Thanks. Kill Bill
10:51 AM Bug #7083: Put back some visual hint for required fields
!required.jpg! Anonymous
10:30 AM Bug #7083: Put back some visual hint for required fields
Applied in changeset commit:57026d17d43a096c3a594a248c183a6889e7956d. Anonymous
10:28 AM Bug #7083: Put back some visual hint for required fields
pkg_edit.php has been updated to automatically add the '*' if <required> is set Anonymous
10:26 AM Bug #7083 (Feedback): Put back some visual hint for required fields
Added:
When composing an element with a form.class or via XML, prepend a '*' to the title to indicate a required f...
Anonymous
11:18 AM Bug #7134 (Resolved): Crash in the gui related to widget
Your fix looks good, Phil. The system I could replicate this on is no longer producing errors after a gitsync.
Thanks!
Jim Pingle
09:32 AM Bug #7145 (Resolved): rc.newwanipv6 running in all cases, even for a renew
dhcp6c calls its script for every action, a new binding or a renew and so on. The problem is that rc.newwanipv6 is ru... Jim Pingle
09:23 AM Bug #7144: Intel NIC loosing connection until reboot
Either way -- driver or hardware (chip or that unit) -- it's not something we can address. It needs replicated in Fre... Jim Pingle
09:19 AM Bug #7144: Intel NIC loosing connection until reboot
Jim Pingle wrote:
> On the contrary, this is almost certainly a hardware issue, or at least a driver issue:
> "Jan ...
Guy Van Sanden
09:17 AM Bug #7144 (Rejected): Intel NIC loosing connection until reboot
On the contrary, this is almost certainly a hardware issue, or at least a driver issue:
"Jan 19 12:09:14 kernel ...
Jim Pingle
09:13 AM Bug #7144 (Rejected): Intel NIC loosing connection until reboot
Hi
I have a pfsense appliance from applianceshop.eu (https://www.applianceshop.eu/security-appliances/19-rack-app...
Guy Van Sanden
08:28 AM Bug #7143 (Closed): filterdns is triggering every 16 seconds for hosts even when the DNS record has not changed
filterdns is triggering every 16 seconds whether the record has changed or not. It happens for IPsec entries and FQDN... Jim Pingle
08:15 AM Bug #7142 (Resolved): IPv6: Floating rules on 6rd enabled WAN interfaces doesn't get bound to wan_stf
Found a bug in the handling of floating rules when they need to be applied to 6rd enabled interfaces (which are split... Kewin Christensen
04:26 AM Bug #7140 (Resolved): User with page-help-all as first priv is redirected to Dashboard Help
1) Create a new user.
2) Add "WebCfg - Help pages" priv for the user.
3) Add some other page privs for the user.
4...
Phillip Davis
02:47 AM Bug #7138 (Assigned): Pfsense wide dhcpv6 client doesn't recognise ifid statement
Right now a user cannot set a specific ipv6 address on a tracked interface. The interface id is autogenerated based o... Bogdan P

01/18/2017

10:38 PM Bug #7134: Crash in the gui related to widget
If you have just the Interface Statistics widget on the dashboard (and not the Interfaces widget also) then you still... Phillip Davis
02:00 PM Bug #7134 (Feedback): Crash in the gui related to widget
Applied in changeset commit:ffb0c1822875bc0ea1e2b7b73109fa0f97c0b6d2. Jim Pingle
01:43 PM Bug #7134 (Confirmed): Crash in the gui related to widget
This also happens on 2.3.3 Jim Pingle
01:41 PM Bug #7134 (Resolved): Crash in the gui related to widget
From thread : https://forum.pfsense.org/index.php?topic=124155.0
Other people seems to have the same bug.
My ...
Alexandre Paradis
10:26 PM pfSense Packages Bug #7127: Authentication fail in AutoConfigBackup package
Confirmed. I just installed version 1.47 and it now works just fine with the mixed case ID. Thanks!!!
... um, y...
Brian Davidson
08:41 PM Bug #7124: Kernel panic when configuring 6to4 on a interface
Just want to confirm that this appears to have kept my box from booting. But would restart over and over. No logs to... Chris Palmer
05:45 PM Feature #7137 (Duplicate): Add support for Sierra MC7455
pleace add support for Sierra Wireless MC7455 card, thx
Details:
usbconfig -u 1 -a 4 dump_device_desc
ugen1....
Daniel Ziehmayer
05:26 PM Bug #7136 (Resolved): OpenVPN not binding to IP Aliases -> NO LOGS generated
Steps to replicate:
- Create an IP Alias on any interface e.g. 127.0.0.2 on Localhost
- Attempt to bind OpenVPN ser...
James Webb
03:32 PM pfSense Packages Bug #7130 (Resolved): Lightsquid 3.0.4_2 HTTP 500
Works Jim Pingle
09:51 AM pfSense Packages Bug #7130: Lightsquid 3.0.4_2 HTTP 500
I'll grab this back for testing once the new package is available Jim Pingle
09:49 AM pfSense Packages Bug #7130 (Feedback): Lightsquid 3.0.4_2 HTTP 500
3.0.4_3 should be fixed Renato Botelho
09:23 AM pfSense Packages Bug #7130: Lightsquid 3.0.4_2 HTTP 500
Looks like we're missing the latest change to the Makefile for www/lightsquid from earlier this week, CGI.pm was remo... Jim Pingle
09:17 AM pfSense Packages Bug #7130 (Confirmed): Lightsquid 3.0.4_2 HTTP 500
Jim Pingle
01:59 AM pfSense Packages Bug #7130 (Resolved): Lightsquid 3.0.4_2 HTTP 500
As title says, when one clicks on Open Lightsquid HTTP error 500 appers. Greg M
02:46 PM Bug #2073: APIPA broadcasts forwarded by route-to
There is no GUI knob to disable it, but there is a setting. You can set it in the config.xml directly or via PHP (e.g... Jim Pingle
02:40 PM Bug #2073: APIPA broadcasts forwarded by route-to
Except with no way to disable this rule, this can affect bridged interfaces, and since the rule is processed so far i... Brandon Jackson
02:44 PM Bug #7135: Crash in PHP widget module interface_statistics.widget.php
My bad, sorry for the duplicate. Phil Scarr
02:43 PM Bug #7135 (Duplicate): Crash in PHP widget module interface_statistics.widget.php
Duplicate of #7134 which has a fix already. Jim Pingle
02:38 PM Bug #7135 (Duplicate): Crash in PHP widget module interface_statistics.widget.php
When returning to the dashboard page, I frequently receive a PHP error warning:
[17-Jan-2017 14:53:51 America/Chic...
Phil Scarr
01:20 PM Bug #7133 (Feedback): services_router_advertisements.php: Interface drop-down is not showing the user-configured interface name
Applied in changeset commit:790e2a2fad1da3fe6bdd6c858ede2d9e3f34a84a. Jim Pingle
01:16 PM Bug #7133 (Resolved): services_router_advertisements.php: Interface drop-down is not showing the user-configured interface name
On services_router_advertisements.php, for the "RA Interface" selection, the internal name (e.g. OPT1) is shown for t... Jim Pingle
12:57 PM Bug #6992 (Resolved): ZoneEdit DDNS does not update to CARP IP
I created a zoneedit account (it's free, and you can just make up a domain when testing without actually pointing any... Jim Pingle
12:43 PM Bug #7123 (Feedback): Kernel panic when setting TCP MD5 Password in OpenBGP
Possible fix was cherry-picked to FreeBSD-src, please try again on next snapshot Renato Botelho
12:28 PM Bug #6874 (Resolved): Dynamic DNS w/ DNSimple
Tested, works. Error and success conditions are logged properly. Jim Pingle
12:03 PM Bug #6751 (Resolved): Route53 DynDNS Problems / Replace Route53 DynDNS Module
Tested Route53, it updates records properly now. Jim Pingle
12:03 PM Bug #5054 (Resolved): Dynamic DNS - Route53 errors should probably be more verbose
Tested Route53, it updates records properly now. Jim Pingle
12:02 PM Bug #3973 (Resolved): Route 53 dynamic DNS provider fails to update record
Tested Route53, it updates records properly now. Jim Pingle
11:03 AM Bug #7119 (Feedback): Changing LAGG attributes results in a panic/crash
I've cherry-picked FreeBSD-src patches that should fix it:
https://svnweb.freebsd.org/base?view=revision&revision=...
Renato Botelho
10:26 AM Bug #7126 (Resolved): Dynamic DNS Widget links for RFC2136 entries are incorrect
Works Jim Pingle
09:42 AM Bug #7132 (Resolved): PPPoE IP Alias
If you create a new IP Alias on a PPPoE interface, alias address is never added to pppoe0 interface.
Gladiston Justini
09:36 AM Bug #7131 (Resolved): DHCP v4&v6 DDNS missing options
After revision 391d63da the dhcpv6 server settings allows the user to chose between allow, deny or ignore client upda... Bogdan P
09:08 AM Bug #7003 (Resolved): autoboot_delay on 2.4.0
Works fine now, it's there after install Jim Pingle
05:31 AM Bug #7003: autoboot_delay on 2.4.0
Confirmed fix on today's snapshot, keeping it as feedback to hear from JimP test results as well Renato Botelho
07:09 AM Bug #6298 (Duplicate): OpenVPN IPv4/6 Local network(s) initial display state
I can't reproduce it even on 2.3.x. This appears to have been duplicated by #6482 which has been fixed. Jim Pingle
07:02 AM Bug #6298 (Feedback): OpenVPN IPv4/6 Local network(s) initial display state
I've tested it on 2.4.0 and didn't see the issue. Could you please try to replicate it on current snapshots and if yo... Renato Botelho
06:06 AM Bug #4310: Limiters + HA results in hangs on secondary
One more here, we always have limiters and HA and we are forced to use the queues. If someone makes a mistake of assi... Jose Duarte
05:22 AM Feature #7122 (Feedback): Add filters to various dashboard widgets
All PRs merged, thanks! Renato Botelho
01:44 AM Feature #7122: Add filters to various dashboard widgets
Bored enough :) PR https://github.com/pfsense/pfsense/pull/3395 Phillip Davis
04:33 AM Bug #7129 (Resolved): system_advanced_notifications.php - Cannot save settting - growl passwords must match
Renato Botelho
03:10 AM Bug #7129: system_advanced_notifications.php - Cannot save settting - growl passwords must match
Merged, can be closed. Thanks. Kill Bill
02:04 AM Feature #4470: RA page in GUI
Hello!
It would be great to implement those 2:
AdvRDNSSLifetime
AdvDNSSLLifetime
Thanks!
Greg M

01/17/2017

09:57 PM Bug #7075: firewall states show negative value for total bytes processed
I'm also seeing this problem in the latest release.
2.3.2-RELEASE-p1 (i386)
built on Tue Sep 27 12:13:32 CDT 2016...
Matt Perry
09:41 PM pfSense Packages Bug #7127 (Resolved): Authentication fail in AutoConfigBackup package
Had confirmation from others internally that it worked on the new version with mixed case login names. Jim Pingle
11:04 AM pfSense Packages Bug #7127 (Feedback): Authentication fail in AutoConfigBackup package
I pushed a fix for this just now. Once version 1.47 shows up for you, reinstall and test it again.
https://github....
Jim Pingle
09:40 PM Bug #6663 (Resolved): IPv6 OpenVPN client is down after reboot
Updated a VM that had two UPD6 OpenVPN servers on a HE.net GIF WAN and they were both running after the update. On ol... Jim Pingle
12:45 PM Bug #6663: IPv6 OpenVPN client is down after reboot
I've mispelled ticket # on commit:5280fd8d21c71c6997e1855f8b96265bd81ccb99 Renato Botelho
12:37 PM Bug #6663 (Feedback): IPv6 OpenVPN client is down after reboot
It happened in cases where specific IPv6 is selected to bind and interface is in 'tentative' state, as happened in th... Renato Botelho
01:47 PM Feature #7122: Add filters to various dashboard widgets
@Phil: In case you are bored, could you do one for SMART Status? Did one originally for 2.2.x (https://github.com/pfs... Kill Bill
12:32 AM Feature #7122: Add filters to various dashboard widgets
OpenVPN Widget filtering in PR https://github.com/pfsense/pfsense/pull/3392 Phillip Davis
01:10 PM Bug #7003 (Feedback): autoboot_delay on 2.4.0
Fixed installer bits, it should be fine on next round of snapshots Renato Botelho
12:49 PM pfSense Packages Bug #6603 (Confirmed): pfblockerng's Unbound modifications leave system broken post-config restore
Jim Pingle
12:42 PM pfSense Packages Bug #6603: pfblockerng's Unbound modifications leave system broken post-config restore
Definitely wrong ticket reference in the above commit. Kill Bill
12:40 PM pfSense Packages Bug #6603 (Feedback): pfblockerng's Unbound modifications leave system broken post-config restore
Applied in changeset pfsense:commit:5280fd8d21c71c6997e1855f8b96265bd81ccb99. Renato Botelho
11:10 AM Bug #7117 (Feedback): Bump sched buckets limiter log spam in console
should be fixed in the latest snapshot.
https://github.com/pfsense/FreeBSD-src/commit/c941deabf9dd3d86632ccfdade9d...
Luiz Souza
07:21 AM Bug #5993: dhcp6c not started until an RA received
PR issued, should be the end of this one. Martin Wasley
03:18 AM Bug #7129: system_advanced_notifications.php - Cannot save settting - growl passwords must match
Clearly caused by password management in browsers (or password management extensions such as LastPass) helpfully pre-... Kill Bill
02:48 AM Bug #7129 (Resolved): system_advanced_notifications.php - Cannot save settting - growl passwords must match
- I never enabled/configured/touched this (IOW, this should certainly default to disabled, I'd imagine the number of ... Kill Bill
02:30 AM Bug #7128 (Resolved): system_advanced_network.php - fugly IPv6 over IPv4 input field alignment
This really look stupid, is it possible to put it below the checkbox somehow? I'd personally just remove the form gro... Kill Bill

01/16/2017

10:57 PM Feature #7122: Add filters to various dashboard widgets
Dynamic DNS Widget filtering in PR https://github.com/pfsense/pfsense/pull/3386
Commit https://github.com/pfsense/pf...
Phillip Davis
07:03 PM Feature #4209: Releasing DHCP on WAN interface should send a release
PR
Status / Interfaces - Relinquish DHCP Lease
https://github.com/pfsense/pfsense/pull/3390 (2.4)
https://github.c...
NOYB NOYB
01:55 PM Todo #7125 (Resolved): fullbogons ipv4 list not up to date
The list on the server was having a problem updating, which we have corrected. The hosted list is current now, shortl... Jim Pingle
09:44 AM Todo #7125 (Resolved): fullbogons ipv4 list not up to date
Pfsense bogons list is not up to date:
https://files.pfsense.org/lists/fullbogons-ipv4.txt - Tue Nov 22 04:50:02 ...
Vladimir Lind
12:50 PM Bug #7126 (Feedback): Dynamic DNS Widget links for RFC2136 entries are incorrect
Applied in changeset commit:47b35618f025082b5504eae5518d89c772ae8bd5. Phillip Davis
11:56 AM Bug #7126: Dynamic DNS Widget links for RFC2136 entries are incorrect
PR https://github.com/pfsense/pfsense/pull/3388 Phillip Davis
11:06 AM Bug #7126 (Resolved): Dynamic DNS Widget links for RFC2136 entries are incorrect
The Dynamic DNS Widget also displays RFC2136 entries these days. But it has an "ondblclick" for each row that always ... Phillip Davis
11:54 AM pfSense Packages Bug #7127 (Resolved): Authentication fail in AutoConfigBackup package
When I sign in to the PFSense Gold web portal, I enter my ID as mix of upper and lower case letters: BrianKDav. To ... Brian Davidson
08:41 AM Bug #6625: firewall forwards all traffic through wan interface, via default gateway, even if alternative route had been installed
Jim Pingle wrote:
> That doesn't change the situation. You're posting on closed duplicate tickets and the floating r...
Gaëtan SLONGO
08:35 AM Bug #6625: firewall forwards all traffic through wan interface, via default gateway, even if alternative route had been installed
That doesn't change the situation. You're posting on closed duplicate tickets and the floating rules do solve the pro... Jim Pingle
08:32 AM Bug #6625: firewall forwards all traffic through wan interface, via default gateway, even if alternative route had been installed
Jim Pingle wrote:
> This is a bug reporting system, not a support or discussion platform. Please post on the forum o...
Gaëtan SLONGO
08:26 AM Bug #6625: firewall forwards all traffic through wan interface, via default gateway, even if alternative route had been installed
This is a bug reporting system, not a support or discussion platform. Please post on the forum or via some other supp... Jim Pingle
08:25 AM Bug #6625: firewall forwards all traffic through wan interface, via default gateway, even if alternative route had been installed
Jim Pingle wrote:
> We have, it is.
OK so what would be the solution? Because using floating rules has no effect....
Gaëtan SLONGO
08:23 AM Bug #6625: firewall forwards all traffic through wan interface, via default gateway, even if alternative route had been installed
We have, it is. Jim Pingle
08:22 AM Bug #6625: firewall forwards all traffic through wan interface, via default gateway, even if alternative route had been installed
Jim Pingle wrote:
> Duplicate of #1136
Note sure it is really a duplicate. And the #1136 is very old (and seems n...
Gaëtan SLONGO
08:20 AM Bug #6625 (Duplicate): firewall forwards all traffic through wan interface, via default gateway, even if alternative route had been installed
Duplicate of #1136 Jim Pingle
08:19 AM Bug #6625: firewall forwards all traffic through wan interface, via default gateway, even if alternative route had been installed
Remko Lodder wrote:
> We have setup a new pfSense box that will route our VPN traffic between endpoints.
> That goe...
Gaëtan SLONGO
07:57 AM Bug #7015: IPsec not working behind NAT
Vladimir Putin wrote:
> Could it be related to https://redmine.pfsense.org/issues/6937 ?
I believe not. We just f...
Renato Botelho
07:34 AM Bug #6974: radvd enabled on a disconnected interface kills RA completely on all interfaces
Not really sure why's this assigned to me. Either it's a bug in radvd or in pfSense. Either way, I won't fix it. Also... Kill Bill
06:57 AM Bug #6406: Web process becomes unresponsive producing 502 Bad Gateway nginx
We upgraded 2 days ago from 2.2.x to 2.3.1p1.
Same issue and no pfB installed.
We have upgraded only one of our t...
Romain Cabassot
06:40 AM Bug #7120 (Feedback): Wrong file permissions on /var/tmp and missing sticky bit when using /var as RAM disk
Applied in changeset commit:fc1caa413543c9a616ef08061a5861f57a1c0881. Renato Botelho
06:33 AM Bug #7033: Hidden rule break the policy routing
Jim Pingle wrote:
> Duplicate of #1136
>
> If you must have a second gateway on WAN, add floating rules to match ...
Gaëtan SLONGO

01/15/2017

10:43 PM pfSense Packages Feature #6022: Consider MLVPN for bonded VPN
There appears to be a port for MLVPN now:
https://www.freshports.org/net/mlvpn/
This could be used as a basis for...
Adam Gibson
03:03 PM Bug #6982 (Resolved): Nested Aliases with FQDNs do not populate parent table in some cases
Jim Pingle
03:01 PM Bug #6982: Nested Aliases with FQDNs do not populate parent table in some cases
This looks good to me.
Thought there was still an issue but it just turns out one of my test fqdns (www.cnn.com) h...
Chris Linstruth
02:53 PM pfSense Packages Feature #4461: Squid options too late in squid.conf
See... Volker Kuhlmann
02:44 PM pfSense Packages Feature #4461 (Rejected): Squid options too late in squid.conf
Jim Pingle
02:43 PM pfSense Packages Feature #4461: Squid options too late in squid.conf
No such luck needed, said deficient software is no longer involved, and no loss for me, no-one would have done anythi... Volker Kuhlmann
02:24 PM pfSense Packages Feature #4461: Squid options too late in squid.conf
Thanks for "feedback". Pull requests go to https://github.com/pfsense/FreeBSD-ports/, good luck. Kill Bill
02:08 PM pfSense Packages Feature #4461: Squid options too late in squid.conf
Services like plesk control panels do not run on a standard SSL port like 443. Rather than opening several other port... Volker Kuhlmann
07:41 AM pfSense Packages Feature #4461 (Feedback): Squid options too late in squid.conf
Jim Pingle
02:50 AM pfSense Packages Feature #4461: Squid options too late in squid.conf
I have hard time understanding what kind of exceptions is being requested here or what's being used by the OP that's ... Kill Bill
01:45 PM Bug #7124 (Resolved): Kernel panic when configuring 6to4 on a interface
Kernel panic when configuring 6to4 on a interface
pfSense on virtualbox: 2.4.0-BETA (amd64) built on Sat Jan 14 10:3...
Pi Ba
11:59 AM Bug #7031 (Resolved): Cannot configure OpenVPN on a DHCP interface that has not received an IP address
Works Jim Pingle
11:57 AM Bug #6915 (Resolved): unbound logging not working after reboot or "Reset log files"
Works Jim Pingle
10:13 AM Bug #7015: IPsec not working behind NAT
Could it be related to https://redmine.pfsense.org/issues/6937 ? Vladimir Suhhanov
09:18 AM pfSense Packages Feature #556 (Resolved): siproxd: add carp virtual IPs as interface candidates
Config looks right now Jim Pingle
06:54 AM Feature #5549: Additional DNS entries in General Setup would be good for 3 or more WAN's
So that sort of config should have failed the input validation already prior to his change. The code considers anythi... Phillip Davis
04:16 AM pfSense Packages Bug #5594: Captive portal patch does not work anymore
Orsiris de Jong wrote:
> Anyone willing to update the patch ?
Updating the patch is a waste of time. If such func...
Kill Bill
02:18 AM Bug #7119: Changing LAGG attributes results in a panic/crash
Jim Pingle wrote:
> On 2.4, when changing attributes of an assigned LAGG such as the mode or membership, the firewal...
Rolf Sommerhalder

01/14/2017

09:53 PM Bug #7123: Kernel panic when setting TCP MD5 Password in OpenBGP
Rolf Sommerhalder wrote:
> Setting a TCP6 MD5 password in OpenBGP package triggers a panic in pfSense-2.4 amd64 snap...
Rolf Sommerhalder
08:50 AM Bug #7123 (Resolved): Kernel panic when setting TCP MD5 Password in OpenBGP
Setting a TCP6 MD5 password in OpenBGP package triggers a panic in pfSense-2.4 amd64 snapshot from yesterday (Fri 13.... Rolf Sommerhalder
04:30 PM Bug #6896: unbound root.key file corruption possibly related to full file system
I just had the same issue. /var/ was at 100%. After trying to recreate the root.key, and noticing that dhcpd.conf cou... Thaddeus Covert
03:35 PM Feature #5549: Additional DNS entries in General Setup would be good for 3 or more WAN's
ok already had manually added staic route for 8.8.8.8 and 8.8.4.4 causes failure in error checking Michael Kellogg
03:08 PM Feature #5549: Additional DNS entries in General Setup would be good for 3 or more WAN's
that error happens re-saving current setup with 4 dns servers Michael Kellogg
03:06 PM Feature #5549: Additional DNS entries in General Setup would be good for 3 or more WAN's
getting this error whe trying to add more dns servers
A gateway can not be assigned to DNS '8.8.8.8' server which ...
Michael Kellogg
01:07 AM Feature #5549: Additional DNS entries in General Setup would be good for 3 or more WAN's
Note: I kept this in the General Setup page where it has been since eternity. Just made it so a variable number of DN... Phillip Davis
11:00 AM pfSense Packages Feature #556: siproxd: add carp virtual IPs as interface candidates
Good catch, thanks. Kill Bill
09:42 AM pfSense Packages Feature #556: siproxd: add carp virtual IPs as interface candidates
The PR was close but it needed some backend changes as well, otherwise it was putting blank values in the configurati... Jim Pingle
10:48 AM Bug #7121: freshclam.conf advanced editing, configuring value of "Checks" has no effect on crontab entry
safebrowsing was never enabled in my setup. I also didn't investigate further. Alexander Berkes
10:37 AM Bug #7121: freshclam.conf advanced editing, configuring value of "Checks" has no effect on crontab entry
Alexander Berkes wrote:
> That really makes no sense in the minute crontab column and it definitely leads to multipl...
Kill Bill
10:27 AM Bug #7121: freshclam.conf advanced editing, configuring value of "Checks" has no effect on crontab entry
Thanks for the git link. That makes things more clear.
Sorry I couldn't remember the exact value of the crontab en...
Alexander Berkes
07:36 AM Bug #7121: freshclam.conf advanced editing, configuring value of "Checks" has no effect on crontab entry
This hopefully makes things more obvious: https://github.com/pfsense/FreeBSD-ports/pull/254
@OP: No, the above PR ...
Kill Bill
06:52 AM Bug #7121: freshclam.conf advanced editing, configuring value of "Checks" has no effect on crontab entry
"Checks" in freshclam.conf is not using/configuring cron, at all. Switching to manual config and changing freshclam.c... Kill Bill
05:35 AM Bug #7121: freshclam.conf advanced editing, configuring value of "Checks" has no effect on crontab entry
Yeah you are right, I am talking about the squid package, but especially the freshclam component. Freshclam is execut... Alexander Berkes
02:27 AM Bug #7121: freshclam.conf advanced editing, configuring value of "Checks" has no effect on crontab entry
Assuming you are talking about Squid, it's not supposed to do anything with cron. You are totally on your own, this f... Kill Bill
10:34 AM Bug #6915 (Feedback): unbound logging not working after reboot or "Reset log files"
PR merged, works fine. Will wait for it to be in snaps before one last test. Jim Pingle
09:44 AM Bug #6915: unbound logging not working after reboot or "Reset log files"
Jim Pingle wrote:
> It works from the Settings tab if you reset all log files, but it doesn't work if you clear the ...
Kill Bill
10:11 AM pfSense Packages Feature #3303 (Resolved): Allow quagga ospf stub, not so stub and totally stub areas
Seems to work Jim Pingle
09:20 AM pfSense Packages Feature #7000: ntopng historical data needs to be reworked
PR to hide this defunct stuff from GUI meanwhile: https://github.com/pfsense/FreeBSD-ports/pull/255 Kill Bill
08:57 AM pfSense Packages Bug #4736 (Resolved): ladvd crashes, dumps core
Problem on the ticket no longer happens, anything else belongs on a new ticket. Closing. Jim Pingle
08:57 AM pfSense Packages Bug #6346 (Rejected): Squid Proxy Server Service randomly stops
Jim Pingle
08:56 AM pfSense Packages Bug #5534 (Resolved): Captive Portal stop sending accounting updates to free radius
Unable to reproduce, lack of feedback, closing. Jim Pingle
08:55 AM pfSense Packages Bug #5614 (Resolved): mailreport - emails are going out when manually triggered, but not via cron
Unable to reproduce, lack of feedback, closing. Jim Pingle
08:31 AM Bug #6927 (Resolved): 1 to 1 NAT allows entry of mixed IP addresses
Yes, this should have a 2.4 target. And it's already been tested, but I tested it again on a current snapshot and it'... Jim Pingle
01:45 AM Bug #6927: 1 to 1 NAT allows entry of mixed IP addresses
Target version could be set to 2.4.0 and then some independent person test. Phillip Davis
08:09 AM pfSense Packages Feature #4752 (Feedback): SQUID. Exception for speed limits
Jim Pingle
08:03 AM pfSense Packages Feature #4752: SQUID. Exception for speed limits
Merged; test please and report back. Kill Bill
08:08 AM pfSense Packages Feature #6965 (Resolved): suricata + snort - making custom passlist additive to the default one
Jim Pingle
08:05 AM pfSense Packages Feature #6965: suricata + snort - making custom passlist additive to the default one
Apparently the issue was not with the package, nested aliases now work. Close please. Kill Bill
01:42 AM pfSense Packages Feature #5052: Avahi Proxy Package: Add option to disable/control cache size.
This has a target version of 2.4.0 - is that really intended? Phillip Davis
01:37 AM Bug #6864: Error checking rejects IPv6 addresses with upper case A-F.
interfaces.php also has addrtolower() Phillip Davis
01:28 AM Bug #7031: Cannot configure OpenVPN on a DHCP interface that has not received an IP address
This just needs an independent person to test it. Phillip Davis
01:24 AM Feature #7122: Add filters to various dashboard widgets
The following are completed:
Services Widget UI changes: https://github.com/pfsense/pfsense/pull/3370
Interfaces Wi...
Phillip Davis
01:14 AM Feature #7122 (Resolved): Add filters to various dashboard widgets
Some dashboard widgets can end up with a lot of rows or columns of data to display on bigger systems. It would be nic... Phillip Davis

01/13/2017

08:47 PM Bug #7121 (Resolved): freshclam.conf advanced editing, configuring value of "Checks" has no effect on crontab entry
When configuring clamav advanced options, changing the value of "Checks" has no effect on the crontab entry of freshclam Alexander Berkes
08:31 PM Bug #7120 (Resolved): Wrong file permissions on /var/tmp and missing sticky bit when using /var as RAM disk
When pfsense (full install) is configured to use /var as RAM disk, the directory permissions of /var/tmp are set to 7... Alexander Berkes
03:26 PM Bug #6920 (Resolved): Upgrading to 2.4 with a stale package .inc file can prevent the system from fully booting after upgrade
Seems to be fixed now. I put a file in /usr/local/pkg/ that would work on 2.3.3 and break on 2.4, and it did not affe... Jim Pingle
03:03 PM Bug #6915 (Assigned): unbound logging not working after reboot or "Reset log files"
It works from the Settings tab if you reset all log files, but it doesn't work if you clear the log specifically whil... Jim Pingle
02:53 PM Bug #7003 (Assigned): autoboot_delay on 2.4.0
It's still missing after installing from a current snapshot. /boot/loader.conf contains only:... Jim Pingle
02:51 PM Feature #5549 (Feedback): Additional DNS entries in General Setup would be good for 3 or more WAN's
PR has been merged, thanks! Renato Botelho
02:15 PM Bug #3560 (Resolved): Disabled Static Route not fully disabled
Works Jim Pingle
12:41 PM pfSense Packages Bug #5524 (Resolved): bind package is patching /etc/inc/system.inc (syslog configuration)
Jim Pingle
12:39 PM Bug #6840 (Resolved): Upgrade ISC dhcpd to 4.3.5 to address missing hostname workaround
New version is there, workarounds are gone. Seems fine. Jim Pingle
12:17 PM Bug #6984 (Resolved): NTP/ACLs - Delete button partially invisible + rowhelper handling broken
Seems fine now, the behavior is correct and the button has space around it. Jim Pingle
12:16 PM Bug #7102: This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
do you want me to update my snapshot and test? Chris Collins
08:46 AM Bug #7102 (Resolved): This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
Fixed Jim Pingle
12:14 PM pfSense Packages Bug #6527 (Resolved): Squid 3.5 - Deprecated "ssl_bump server-first all" don't allow SNI in transparent mode with HTTPS/SSL Interception
Jim Pingle
12:14 PM pfSense Packages Feature #6593 (Resolved): squid: allow user to configure DH key size, SINGLE_DH_USE, NO-SSLv3, Cipher-Suites - performance improvement hint
Jim Pingle
12:14 PM pfSense Packages Bug #6592 (Resolved): squid does NOT use EDH and EECDH cipher suites because "tls-dh" is not configured and so these ciphers are silently dropped - see squid documentation
Jim Pingle
12:12 PM Bug #6357 (Resolved): Dynamic DNS (RFC2136) updates always considered successful
Seems to work all around. It logs correctly when it is updating, and if it fails that is also logged. It is checking ... Jim Pingle
11:42 AM Bug #6717: Status / DHCPv6 Leases Issues
I'm not able to comment on item 2 in the original list due to a dhcpv6 bug in windows 10, but it appears that the lea... Daryl Morse
09:04 AM Bug #6717 (Resolved): Status / DHCPv6 Leases Issues
Seems to be fine. No errors on the page with or without leases, with or without RAM disks enabled. Jim Pingle
10:46 AM Feature #7069 (Resolved): Provide knob to disable state display in Diagnostics > States until a filter has been submitted.
Works Jim Pingle
10:46 AM Todo #7084 (Resolved): Intel IEEE 802.11ac wireless network driver
Jim Pingle
10:44 AM Bug #7118 (Resolved): ICMP rule with ICMP type "any" fails to load
OK, nevermind, I ran it again and it's fine. The sync didn't pick that up.
github has been spazzing out today, the...
Jim Pingle
10:41 AM Bug #7118 (New): ICMP rule with ICMP type "any" fails to load
This still fails for me after a gitsync.
There were error(s) loading the rules: /tmp/rules.debug:189: syntax err...
Jim Pingle
06:30 AM Bug #7118 (Feedback): ICMP rule with ICMP type "any" fails to load
Applied in changeset commit:007cfb6ab6d7733c7a98d8fc5baae59028753107. Phillip Davis
01:16 AM Bug #7118: ICMP rule with ICMP type "any" fails to load
Works fine now. Many thanks, Phil! Anonymous
12:55 AM Bug #7118: ICMP rule with ICMP type "any" fails to load
Pull request to fix: https://github.com/pfsense/pfsense/pull/3377 Phillip Davis
12:33 AM Bug #7118 (Resolved): ICMP rule with ICMP type "any" fails to load
Creating a pass rule with ICMP and ICMP type any prevents the ruleset from being loaded.
The following rule is gener...
Anonymous
10:33 AM Feature #7051 (Resolved): Allow control of what users can view and/or clear notices
Works well now as far as I can see. Jim Pingle
10:32 AM Bug #7043 (Resolved): If user does not have crash_reporter page access the crash reported link is useless
Works fine, a user without access doesn't get the link. Jim Pingle
10:26 AM Bug #7119 (Resolved): Changing LAGG attributes results in a panic/crash
On 2.4, when changing attributes of an assigned LAGG such as the mode or membership, the firewall panics and reboots.... Jim Pingle
10:19 AM Feature #7111 (Resolved): Add protocol selection to radius server configuration
Works well Jim Pingle
10:16 AM Feature #7097 (Resolved): Authentication cache for LDAP and RADIUS
Works well for LDAP. RADIUS already caches the groups in $_SESSION so don't be surprised if you don't see re-auth req... Jim Pingle
10:07 AM Bug #7015: IPsec not working behind NAT
Also seeing this after upgrading to 2.4.
Initially unable to ping across the tunnel but a packet capture showed pi...
Steve Wheeler
09:48 AM Bug #7089 (Resolved): Opposite of + or - is occurring when selecting time zone
New descriptions are more clear, options are labeled in a way that is hopefully obvious. Jim Pingle
09:18 AM Bug #7042 (Resolved): DHCP client configures wrong address in some circumstances (setfirst support missing from ifconfig)
Seems to be solid all-around. Jim Pingle
09:16 AM Bug #6930 (Resolved): DHCP server should be disabled for /31 and /32
Seems to be good here. Jim Pingle
09:08 AM Feature #6793 (Resolved): Add pound package to the pfSense repository
It's been available in the repo for a while. Closing. Jim Pingle
09:07 AM Feature #6746 (Resolved): Option to select dark or misc background for Traffic Graphs when a dark theme is selected.
All graphs look fine now with the dark theme (widget, graph page, and monitoring), they do respect theme colors. Jim Pingle
09:06 AM pfSense Packages Todo #7055: Update OpenVPN Client Export package with OpenVPN 2.4
If you checked "push compression to the client" then the server will push the setting to the client and it shouldn't ... Jim Pingle
09:03 AM pfSense Packages Todo #7055: Update OpenVPN Client Export package with OpenVPN 2.4
Jim - unknown if this is expected behavior, but the Client Export does not put compression settings in the client fil... Jeff Wischkaemper
08:49 AM pfSense Packages Todo #7055 (Resolved): Update OpenVPN Client Export package with OpenVPN 2.4
Works fine. Jim Pingle
08:56 AM Bug #4418: IPsec mobile clients - bogus "p" appended to search domain
This still happens in 2.3.2-RELEASE-p1. Had to add a dummy second domain to fix it like the others.
resolver #3
...
Aaron Holtzman
08:48 AM Bug #6778 (Resolved): CloudFlare Dynamic DNS fails when domain name uses a Second Level TLD
No confirmation, but no complaints. Other posts on the forum indicate CloudFlare is working in general on 2.4 now. Jim Pingle
08:37 AM Bug #7088 (Resolved): DHCP does not accept input into MAC Control Fields.
Works Jim Pingle
08:32 AM Bug #7081 (Resolved): Search Domains not populating from RA using SLAAC
Works Jim Pingle
05:01 AM Feature #4632: Support for Multipath TCP (MPTCP)
I also would like to see it in PfSense.
I'm using MPTCP to bond my three connections (2x VDSL + LTE). It works per...
Sven Oesterle

01/12/2017

08:49 PM Bug #6153 (Resolved): RFC 2136 Client fails to update more than 1 record
Works for me. Two RFC2136 entries on WAN both get updated now. I wiped the cache files and tested using /etc/rc.dyndn... Jim Pingle
03:34 PM Bug #6153: RFC 2136 Client fails to update more than 1 record
Pingle has a way to validate the changes Renato Botelho
03:30 PM Bug #6153 (Feedback): RFC 2136 Client fails to update more than 1 record
Applied in changeset commit:ed680fda05f2d2d17a59d2893a6ae45e0cbef164. Renato Botelho
08:30 PM Bug #6991 (Resolved): IPv6 traffic hitting a rule with policy routing and NPt fails/disappears
Seems to work fine. Rules that resulted in no traffic passing before now pass traffic as expected. Jim Pingle
11:12 AM Bug #6991 (Feedback): IPv6 traffic hitting a rule with policy routing and NPt fails/disappears
Fixed by: https://github.com/pfsense/FreeBSD-src/commit/65e7874e6faa4fdfd1fb6893d75d8db196a2f599 Luiz Souza
06:55 PM Feature #6045 (Resolved): Updates that do not require a reboot should run reroot
Seems OK for now. Jim Pingle
08:16 AM Feature #6045 (Feedback): Updates that do not require a reboot should run reroot
pfSense-upgrade 0.12 will not reroot on ZFS systems Renato Botelho
06:30 PM Bug #7105 (Resolved): ICMP type selection is assuming IPv6 when it should assume IPv4
Works Jim Pingle
08:50 AM Bug #7105 (Feedback): ICMP type selection is assuming IPv6 when it should assume IPv4
Applied in changeset commit:da2a39e2961d22a403df464534b52bf6dbf9cf01. Renato Botelho
04:34 PM Bug #7116: a floating 'match' rule on LAN does not put traffic from a broswer on a clientpc into a shaper queue
I confirm this behaviour. Chris Collins
02:46 PM Bug #7116 (Resolved): a floating 'match' rule on LAN does not put traffic from a broswer on a clientpc into a shaper queue
a floating 'match' rule on LAN does not put traffic from a broswer on a clientpc into a shaper queue.
Using Virtua...
Pi Ba
02:59 PM Bug #7117 (Resolved): Bump sched buckets limiter log spam in console
When a limiter is used with source mask, it creates a lot of system log entries over time when active and applied to ... Brandon Jaffe
10:11 AM Bug #6937: Inbound traffic on enc0 is not creating a state with mobile IPsec
Please read this https://forum.pfsense.org/index.php?topic=117827 Vladimir Suhhanov
08:30 AM Feature #7115 (Rejected): Firewall logs duration
Use remote syslog to retain logs. Or look into the syslog-ng package. Jim Pingle
08:27 AM Feature #7115 (Rejected): Firewall logs duration
It would be nice if the firewall log records are archived in the new version Landforces turkuaz
08:05 AM Todo #7084 (Feedback): Intel IEEE 802.11ac wireless network driver
pfSense kernel already has all intel wireless cards / firmwares built-in as you can see at:
https://github.com/pfs...
Renato Botelho
07:54 AM Bug #6340 (Feedback): fsck hangs boot in background, fails to produce any action, resulting in broken firewall
We were misusing fsck -F option. It's supposed to be used when you plan to run background fsck after filesystems are ... Renato Botelho

01/11/2017

10:42 PM Bug #6937: Inbound traffic on enc0 is not creating a state with mobile IPsec
Found the same problem on a 2 weeks old SG-1000. Kinda annoying since mobile ipsec is the reason I bought it. Jun Wang
08:21 PM Bug #7110 (Resolved): Empty custom NTP ACL produces syntax error in /var/etc/ntpd.conf
Jim Pingle
08:05 PM Bug #7110: Empty custom NTP ACL produces syntax error in /var/etc/ntpd.conf
Can confirm that fix works on current 2.3.3 snapshot. Thanks, Jim! John Silva
08:00 AM Bug #7110 (Feedback): Empty custom NTP ACL produces syntax error in /var/etc/ntpd.conf
Applied in changeset commit:d90beba66f545af414f00124ba32a9ae087a29d2. Jim Pingle
08:18 PM pfSense Packages Bug #7114: OpenBGP - remote syslog output incomplete
Thanks, Jim.
Confirmed with WireShark to be a limitation of free Kiwi syslog server.
Phil Biggs
07:49 PM pfSense Packages Bug #7114 (Rejected): OpenBGP - remote syslog output incomplete
Remote syslog server data is sent immediately as the log entries happen. There are no limits imposed on the data, it ... Jim Pingle
07:33 PM pfSense Packages Bug #7114 (Rejected): OpenBGP - remote syslog output incomplete
2.3.2-RELEASE-p1 (full install).
I have a table which is updated via OpenBGP and currently contains more than 90...
Phil Biggs
04:46 PM Bug #6712 (Resolved): services_unbound.php Host Overrides don't change any unbound configuration
Looks good now. Forwarder hosts go in /etc/hosts, Resolver hosts go in /var/unbound/host_entries.conf and they appear... Jim Pingle
10:51 AM Bug #6712: services_unbound.php Host Overrides don't change any unbound configuration
Assigning to Jim Pingle for testing Renato Botelho
10:50 AM Bug #6712 (Feedback): services_unbound.php Host Overrides don't change any unbound configuration
Applied in changeset commit:ac446eac051c4514666f9904bbdd0609468f2fc5. Renato Botelho
04:35 PM Bug #6422 (Duplicate): PHP Fatal error: Call to undefined function gettext() in /etc/inc/rrd.inc on line 60
Duplicate of #6758 Jim Pingle
04:30 PM Bug #6422: PHP Fatal error: Call to undefined function gettext() in /etc/inc/rrd.inc on line 60
Seems to be caused by a file permissions issue.
See https://redmine.pfsense.org/issues/6758
To fix this:
<pr...
Glenn Provoost
08:49 AM Feature #5549: Additional DNS entries in General Setup would be good for 3 or more WAN's
PR https://github.com/pfsense/pfsense/pull/3373
It seems to work too easily, what have I forgotten?
Phillip Davis
05:59 AM Bug #7113 (New): Interface name in Traffic Graphs
The interface name is not displayed in the traffic graphs, only the real interface name is displayed, lan, wan, opt1,... Pablo Trincavelli
05:58 AM Bug #7112 (Resolved): Traffic Graphs resets graph when browser tab changes
The new traffic graphs resets graphs when the actual browser tab is changed, so the graphs starts from the right axis... Pablo Trincavelli
05:38 AM Feature #7069 (Feedback): Provide knob to disable state display in Diagnostics > States until a filter has been submitted.
PR has been merged, thanks! Renato Botelho
05:30 AM Feature #7111 (Feedback): Add protocol selection to radius server configuration
Applied in changeset commit:9da4a575f8ff670f4d79bb0b6c19e8ca3f3a3cdc. Renato Botelho
05:19 AM Feature #7111: Add protocol selection to radius server configuration
Submitted at https://github.com/pfsense/pfsense/pull/2687 Renato Botelho
05:19 AM Feature #7111 (Resolved): Add protocol selection to radius server configuration
Add the hability to select protocol (PAP, MD5-CHAP, MS-CHAPv1 and MS-CHAPv2) on Radius server configuration. Renato Botelho
03:02 AM Feature #7099: Make breadcrumbs clickable
Yes, for packages with XML the pkg.php and pkg_edit.php try to put some reasonable breadcrumb links in (try the Notes... Phillip Davis
02:50 AM Feature #7099: Make breadcrumbs clickable
Phil: That looks great, thanks! I guess the same can be used for packages (the PHP files I mean, not XML), right? Kill Bill
01:03 AM Feature #7099: Make breadcrumbs clickable
Proposed solution is out for review/test https://github.com/pfsense/pfsense/pull/3369 Phillip Davis

01/10/2017

08:29 PM Bug #4310: Limiters + HA results in hangs on secondary
I would agree with Vladimir. Just would like to know if this will be definitely be fixed in 2.4 or pushed out furthe... James Kohout
08:21 PM Bug #7110 (Resolved): Empty custom NTP ACL produces syntax error in /var/etc/ntpd.conf
On the NTPD ACL tab [Services/NTP/ACLs] the blank default entry under Custom Access Restrictions results in addition ... John Silva
07:59 PM Bug #6986 (Resolved): reply-to is not functioning on pfSense 2.4
I tested this on two systems that previously reproduced the problem 100% of the time, and now they both work. Looks g... Jim Pingle
07:22 PM Bug #6986 (Feedback): reply-to is not functioning on pfSense 2.4
Fixed by https://github.com/pfsense/FreeBSD-src/commit/114dc4a89011a560c32421ca842ca73f5b29d449 Luiz Souza
09:17 AM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
definitely like the idea of adding a decision layer the would then open options to create a daemon for other method... Michael Kellogg
06:48 AM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
I posted a bounty: https://forum.pfsense.org/index.php?topic=123741.0 → luckman212
08:56 AM pfSense Packages Bug #7104: Rules created by traffic shaper wizard dont do anything
Jim if you want to test these new findings up to you but here is an update.
I have discovered the match rules crea...
Chris Collins
08:23 AM Feature #7098 (Resolved): RAM Disk Management
Seems to work alright on a couple test boxes here. Jim Pingle
06:57 AM pfSense Packages Bug #7109: Squid 0.4.29_1 not Exist
Tank you,
now all is ok
Claudio Berselli
06:52 AM pfSense Packages Bug #7109 (Rejected): Squid 0.4.29_1 not Exist
This sort of error will clear up on its own after a few moments, or run "pkg update -f" if it keeps happening.
Whe...
Jim Pingle
06:45 AM pfSense Packages Bug #7109 (Rejected): Squid 0.4.29_1 not Exist
If tray to install Squid 0.4.29_1 I have this error:... Claudio Berselli
06:50 AM pfSense Packages Bug #6878: how to use snort, squid and squid_guard with a ram disk
The thinking was: Without NanoBSD, more people will be running a full install on unreliable media like CF/SD, so we n... Jim Pingle
04:24 AM pfSense Packages Bug #6878: how to use snort, squid and squid_guard with a ram disk
Jim Pingle wrote:
> Seems to be working.
Yeah, this seems to be working, except that noone is getting the fixes. ...
Kill Bill
06:30 AM Bug #5993: dhcp6c not started until an RA received
Richard Patterson asked me by email to explain in more detail why I want to make these changes, here is my email to h... Martin Wasley
05:22 AM Bug #5993: dhcp6c not started until an RA received
OK, it seems we have a solution. It involves a change to dhcp6c, another new flag is added!
The flag, currently 'x...
Martin Wasley

01/09/2017

10:21 PM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
I agree that the "right" way to handle this would be to have dpinger remain dumb (for lack of a better term) and simp... → luckman212
08:28 PM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
I agree with this analysis. To make this happen, there needs to be a layer between groups of dpinger process(es) and ... Phillip Davis
07:42 PM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
Luke opened an issue with dpinger. For reference, I've copied the response here.
-----
Hey Luke,
I understan...
Denny Page
10:06 PM pfSense Packages Bug #6305: Quagga problems updating routes / mistakenly showing "kernel"-routes while they are not
Affected me too. I tried settings with OpenVPN server + OpenVPN client.
Both:
Pfsense 2.3.2-RELEASE-p1
Quagga_OS...
winmasta winmasta
09:22 PM Feature #7098: RAM Disk Management
Upgraded RAM disk enabled system. Working fine.
Thanks
NOYB NOYB
08:01 AM Feature #7098 (Feedback): RAM Disk Management
PR has been merged, thanks! Renato Botelho
09:17 PM Bug #7108: ntp does not keep time on virtualized pfsense
Trying with TSC-low now. That seems to have done the trick! The time offset is staying relatively stable now. Tha... John Silva
07:50 PM Bug #7108 (Not a Bug): ntp does not keep time on virtualized pfsense
OpenNTPD isn't better, it's worse. Jim Thompson
06:53 PM Bug #7108: ntp does not keep time on virtualized pfsense
Try with TSC or TSC-low. Anyway, this ain't a pfSense bug, needs to go upstream. Kill Bill
05:45 PM Bug #7108: ntp does not keep time on virtualized pfsense
Relevant logs:... John Silva
05:40 PM Bug #7108 (Not a Bug): ntp does not keep time on virtualized pfsense
I run pfsense virtualized under FreeBSD bhyve. I've read all of the normal advice and have implemented the usual wor... John Silva
07:55 PM pfSense Packages Bug #7107: IPv6 blocklists generate IPv4 auto-rules
I'll wait for a confirmed fix for the 'vtype' bug. The aliases are working fine for me, especially since I really on... John Silva
07:44 PM pfSense Packages Bug #7107: IPv6 blocklists generate IPv4 auto-rules
*Update:* Its going to be a little more involved to fix this issue... Best to use "Alias type" rules, until the next... BBcan177 .
07:22 PM pfSense Packages Bug #7107: IPv6 blocklists generate IPv4 auto-rules
Thanks for the report... I can confirm that there is a bug for the IPv6 Tab. The GeoIP tab doesn't have this issue th... BBcan177 .
06:32 PM pfSense Packages Bug #7107: IPv6 blocklists generate IPv4 auto-rules
Yes. I configured the list in the IPv6 tab of pfBlockerNG. When "List Action" is set to "Deny Both" the firewall ru... John Silva
06:21 PM pfSense Packages Bug #7107: IPv6 blocklists generate IPv4 auto-rules
Did you add these Lists in the IPv6 pfBlockerNG Tab? BBcan177 .
05:35 PM pfSense Packages Bug #7107 (Resolved): IPv6 blocklists generate IPv4 auto-rules
I set up some IPv6 blocklists with pfblocker and noticed that the autorules it created were created as IPv4 protocol ... John Silva
06:54 PM Bug #6257: Kernel panic with ALTQ
Also experiencing a very similar crash every few days in the igb driver queue thread after updating to 2.4.0 as long ... Nash Kaminski
05:25 PM Bug #7106 (Not a Bug): TLS SMTP notification messages fail with expired certificate
Am using pfsense 2.3.3 development snapshot 2017-01-08.
When configuring SMTP notifications using STARTTLS over tc...
John Silva
03:11 PM Bug #7105 (Resolved): ICMP type selection is assuming IPv6 when it should assume IPv4
I had an older rule which did not have an ipprotocol type set inside, which is quite common with configurations that ... Jim Pingle
02:46 PM Bug #6986: reply-to is not functioning on pfSense 2.4
It's still not working here. Port forwards only work on the WAN with the default gateway. Configuration is unchanged ... Jim Pingle
02:15 PM Bug #6986: reply-to is not functioning on pfSense 2.4
JimP, I cannot reproduce this bug with todays snapshot. This is a fresh install with two WANs (DHCP) and two port fo... Luiz Souza
02:18 PM Bug #7102: This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
ok thanks for taking the time to find the cause.
I respect you want to sort of filter things out on the forum firs...
Chris Collins
12:40 PM Bug #7102 (Feedback): This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
Applied in changeset commit:fc47d47ae50e6b549b2ac38ded2576106be66504. Jim Pingle
12:34 PM Bug #7102 (Assigned): This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
I found a way to reproduce this one, it's a different problem. If all of the ALTQ-capable interfaces were assigned an... Jim Pingle
12:35 PM Bug #7066: vmx(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3
OK I put that back on #7102, it's all unrelated to this ticket. This ticket is now (again) only for vmx(4) lacking AL... Jim Pingle
10:38 AM Bug #7050 (Resolved): Limiter with PFsense 2.4 transparent proxy
Renato Botelho
10:25 AM Bug #7050: Limiter with PFsense 2.4 transparent proxy
Luiz Otavio O Souza wrote:
> Fixed in the latest snapshot.
>
> https://github.com/pfsense/FreeBSD-src/commit/994e...
Nelson Junior
10:30 AM Bug #6882 (Needs Patch): bsnmpd uses all available CPU with hostres module active in some cases
The workaround is present and prevents the problem case from causing harm.
Rather than close this out, I'll leave...
Jim Pingle
10:09 AM Bug #6835 (Resolved): firewall_nat_out_edit.php Translation section hidden
Jim Pingle
10:09 AM Bug #6711 (Resolved): diag_states_summary # States and # States twice (explain one is per protocol)
Jim Pingle
09:54 AM Bug #6949 (Resolved): username/password not used by proxy support
Works on the latest snap including the patch. Jim Pingle
05:49 AM Bug #6949 (Feedback): username/password not used by proxy support
Done. Last commit was cherry-picked Renato Botelho
08:34 AM pfSense Packages Bug #7104: Rules created by traffic shaper wizard dont do anything
I did not explain how they work because this is not a support system, nor is it a discussion platform. All of this be... Jim Pingle
08:32 AM pfSense Packages Bug #7104: Rules created by traffic shaper wizard dont do anything
Jim Pingle wrote:
> The forum is the best place to discuss this until a real bug is identified. It is not about keep...
Chris Collins

01/08/2017

11:35 PM Bug #6990: DDNS IPs not updating after a system restart
Hi,
yesterday, January 8, my customers router shut down due to a power loss.
When the power returned the router boo...
Muchacha Grande
09:01 PM Feature #7069: Provide knob to disable state display in Diagnostics > States until a filter has been submitted.
New pull request: https://github.com/pfsense/pfsense/pull/3367 Chris Linstruth
08:02 PM Bug #7066: vmx(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3
Firewall-Traffic Shaper-By Interface. I didn't check the others. If I see traffic in the queues then AltQ should be ... Greg Siemon
07:50 PM Bug #7066: vmx(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3
What page does the error show on, exactly? I can't replicate any problem where that error shows up on a firewall that... Jim Pingle
07:13 PM Bug #7066: vmx(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3
Jim Pingle wrote:
> If there is any issue with igb, I can't replicate it here. On an SG-8860 with igb running 2.4, I...
Greg Siemon
10:36 AM Bug #7066: vmx(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3
If there is any issue with igb, I can't replicate it here. On an SG-8860 with igb running 2.4, I can use ALTQ and it ... Jim Pingle
09:18 AM Bug #7066: vmx(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3
Chris Collins wrote:
> Jim ALTQ does looks its on the a downward path but still pfSense uses it and the traffic shap...
Jim Thompson
04:57 PM pfSense Packages Bug #7104: Rules created by traffic shaper wizard dont do anything
Yeah exactly, this is to file bug reports. Not "ooops something somehow won't work for me, definitely must be a bug" ... Kill Bill
04:54 PM pfSense Packages Bug #7104 (Rejected): Rules created by traffic shaper wizard dont do anything
The forum is the best place to discuss this until a real bug is identified. It is not about keeping ticket counts dow... Jim Pingle
04:43 PM pfSense Packages Bug #7104: Rules created by traffic shaper wizard dont do anything
Kill Bill wrote:
> May I suggest using https://forum.pfsense.org/index.php?board=26.0 until you have a *real* bug? '...
Chris Collins
04:42 PM pfSense Packages Bug #7104: Rules created by traffic shaper wizard dont do anything
I see match mentioned on this page https://home.nuug.no/~peter/pf/en/altqintro.html
But FreeBSD never updated PF t...
Chris Collins
04:38 PM pfSense Packages Bug #7104: Rules created by traffic shaper wizard dont do anything
May I suggest using https://forum.pfsense.org/index.php?board=26.0 until you have a *real* bug? 'cos this one ain't a... Kill Bill
04:26 PM pfSense Packages Bug #7104: Rules created by traffic shaper wizard dont do anything
Ok some more information. Step by step of my diagnostics.
1 - Run the wizard and choose the first option, keep as...
Chris Collins
04:12 PM pfSense Packages Bug #7104 (Rejected): Rules created by traffic shaper wizard dont do anything
The rules are created as match rules which is not passing them onto the specific queue.
I am talking about the rul...
Chris Collins
03:20 PM Bug #7050 (Feedback): Limiter with PFsense 2.4 transparent proxy
Fixed in the latest snapshot.
https://github.com/pfsense/FreeBSD-src/commit/994e779f035e9ed49909936d5773f930adfc40...
Luiz Souza
03:05 PM pfSense Packages Feature #4752: SQUID. Exception for speed limits
This is what 'Unrestricted IPs' on the ACLs tab was intended for; except that it never worked due a wrong check. Fixe... Kill Bill
01:21 PM Bug #7093: "Outgoing Network Interfaces" is broken in dns resolver settings
The configuration is not enough on its own because your interfaces are DHCP. We need to see the addresses on the inte... Jim Pingle
12:53 PM Bug #7093: "Outgoing Network Interfaces" is broken in dns resolver settings
is it sufficient to do a backup of the config and send you that backup?
The setup is this.
Dns resolver enabled...
Chris Collins
12:53 PM Bug #7102: This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
The ticket was rejected because I attempted the same configuration and found no problem on current 2.4 snapshots. I h... Jim Pingle
12:43 PM Bug #7102: This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
It is a bit of a wow that you have rejected a clear report telling you that there is a misleading message in the GUI.... Chris Collins
10:19 AM Bug #7102 (Rejected): This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
Then you'll need to provide a lot more detail about your NICs & the drivers they use (dmesg, ifconfig output, GUI ass... Jim Pingle
10:17 AM Bug #7102: This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
I can confirm 100% now ALTQ is working.
1 - if I apply the rules on cli is no error, if altq was broken it would s...
Chris Collins
09:03 AM Bug #7102: This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
The only place I see this message appear is when a NIC is in use that does NOT have ALTQ support (e.g. lagg, cpsw, et... Jim Pingle
11:06 AM pfSense Packages Bug #7103 (Rejected): Security issue regarding traffic shaper created by wizard
There is no security issue except the one you made by changing the rules. If there is a problem with the shaper rules... Jim Pingle
11:04 AM pfSense Packages Bug #7103 (Rejected): Security issue regarding traffic shaper created by wizard
So take this into consideration
The default dns resolver settings listen on "all" interfaces.
If I follow the...
Chris Collins
10:53 AM Feature #7007 (Resolved): Change default IPsec/strongswan log levels
Works Jim Pingle
09:25 AM Bug #6836: Wrong queue length on "/status_queues.php" page under heavy traffic
So show me what is applied here and please remove all not applicable redmine "Ts & Cs" links from this site also. Vladimir Suhhanov
09:21 AM Bug #6836: Wrong queue length on "/status_queues.php" page under heavy traffic
The Ts & Cs of the redmine project don't apply here Jim Thompson

01/07/2017

11:10 PM Bug #6836: Wrong queue length on "/status_queues.php" page under heavy traffic
Please point me to the some redmine EULA or law, why I can not use this name anymore like it was used for the 5 last ... Vladimir Suhhanov
12:26 PM Bug #6836 (Assigned): Wrong queue length on "/status_queues.php" page under heavy traffic
please close and reopen this as someone other than "Vladimir Putin".
not kidding.
Jim Thompson
10:55 PM Bug #7102: This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
Jim seems it is working, and its a GUI bug.
the command line doesnt give any errors, however I am not 100% sure as...
Chris Collins
10:11 PM Bug #7102: This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
Possibly yes as it seems also broken on realtek.
I tried to move both cables to the reX ports but it seems my re1 ...
Chris Collins
09:05 PM Bug #7102 (Duplicate): This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
Probably a duplicate of #7066 which appears to be a more general issue. Jim Pingle
09:04 PM Bug #7102 (Resolved): This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface
Is intel i350 interface
According to this url it can be patched to work. Can the patches please be made on the pf...
Chris Collins
10:28 PM Bug #7093 (Rejected): "Outgoing Network Interfaces" is broken in dns resolver settings
I cannot reproduce this on current 2.4 snapshots. I have tried a variety of outgoing and other interface configuratio... Jim Pingle
10:18 PM Bug #7066: vmx(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3
Jim ALTQ does looks its on the a downward path but still pfSense uses it and the traffic shaper is an established key... Chris Collins
12:13 PM Bug #7066: vmx(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3
Personally, I think ALTQ is dead. Jim Thompson
10:02 PM Bug #7037: CPU frequency in System Information
The info might well be redundant, but dynamic resizing from different values is poor design. Aslak Sande
08:00 PM Feature #7007 (Feedback): Change default IPsec/strongswan log levels
Applied in changeset commit:e470f72139ed54972465e653e27536687ce58b23. Jim Pingle
12:12 PM Feature #7007: Change default IPsec/strongswan log levels
assigned to Pingle for resolution. Jim Thompson
06:09 PM Bug #6949: username/password not used by proxy support
Looks like the patch on the FreeBSD bug entry was committed. We should be able to pull it in from there. Jim Pingle
06:00 PM Bug #6882 (Feedback): bsnmpd uses all available CPU with hostres module active in some cases
Applied in changeset commit:43de83978ed93c9a4886e2844e341af0f3fe9a05. Jim Pingle
01:15 PM Bug #7100 (Resolved): pkg_edit.php - $("#showadv").prop('value') not working
Anonymous
01:01 PM Bug #7100: pkg_edit.php - $("#showadv").prop('value') not working
Works! ;) Thanks. Kill Bill
12:50 PM Bug #7100 (Feedback): pkg_edit.php - $("#showadv").prop('value') not working
Applied in changeset commit:6d55e876755d422e97bacb336f52f577087aa71c. Anonymous
08:36 AM Bug #7100 (Resolved): pkg_edit.php - $("#showadv").prop('value') not working
This code somehow does not work: https://github.com/pfsense/pfsense/blob/master/src/usr/local/www/pkg_edit.php#L1521 ... Kill Bill
12:23 PM Bug #6974: radvd enabled on a disconnected interface kills RA completely on all interfaces

There is code in radvd to stop sending on interfaces that are no longer transmitting.
I don't know how difficult...
Jim Thompson
12:10 PM Bug #7013: Changing group scope to remote does not remove it from group file
you would have to teach each affected process to re-run initgroups(3); setgroups(2); in order for them all to have a ... Jim Thompson
12:05 PM Todo #7084: Intel IEEE 802.11ac wireless network driver
I don't think we have any hardware to test this with. Jim Thompson
11:06 AM Bug #7101: services_dyndns.php not updating via gateway group, ok with the interface
Sorry, a mistake in line 1...
"with 2 PPPoE connection I have defined 3 DDNS: DDNS1.selfip.net for WADSL, DDNS2.se...
Riccardo Di Sarcina
11:03 AM Bug #7101 (Duplicate): services_dyndns.php not updating via gateway group, ok with the interface
Hi,
with 2 connection I have defined 3 DDNS: DDNS1.selfip.net for WADSL, DDNS2.selfip.net for VDSL and DDNS.selfip...
Riccardo Di Sarcina
09:10 AM Feature #7099: Make breadcrumbs clickable
I wondered about that also, at the time of the bootstrap conversion, but there was enough going on that I never follo... Phillip Davis
06:54 AM Feature #7099 (Resolved): Make breadcrumbs clickable
Dunno if it's just me, but the entire feature is very much pointless when it's unusable for navigation. Seems pretty ... Kill Bill
08:40 AM Feature #7077: Display negotiated data encryption algorithm in OpenVPN connection status
Great news!
We'll keep an eye out for it
Jim Pingle
08:27 AM Feature #7077: Display negotiated data encryption algorithm in OpenVPN connection status
The proposal to add the info to status 2 / 3 has been accepted, and may make it into OVPN 2.4.1. I'll update this whe... Jeff Wischkaemper
06:30 AM Bug #7096: Unbound fails to start on boot if specific network devices are configured in the "Network Interfaces"
I have a proposal which should make it easier for development.
I suggest removing the interface selection as is (f...
Chris Collins
05:46 AM Feature #7098 (Resolved): RAM Disk Management
RAM Disk Management
https://github.com/pfsense/pfsense/pull/2902
1) Treat the RAM disk more like a permanent stor...
NOYB NOYB
01:20 AM Bug #5993: dhcp6c not started until an RA received
The removal of the extra dhc6c_interface_script call does cause a problem for some, those who use dhcpwithoutra and w... Martin Wasley

01/06/2017

11:20 PM Feature #7097 (Feedback): Authentication cache for LDAP and RADIUS
PR merged Jim Pingle
02:41 PM Feature #7097 (Resolved): Authentication cache for LDAP and RADIUS
Currently PFSense does not remember LDAP or RADIUS authentication to the admin portal between requests. This results ... Joash Lewis
11:16 PM Feature #7051 (Feedback): Allow control of what users can view and/or clear notices
PR merged Jim Pingle
11:54 AM Feature #7051: Allow control of what users can view and/or clear notices
This should fix it:
https://github.com/pfsense/pfsense/pull/3359
assuming it should be "fixed"
Phillip Davis
11:23 AM Feature #7051: Allow control of what users can view and/or clear notices
Ditto, but that VM had apparently been broken in that way for some time and I never noticed until this morning when I... Jim Pingle
11:17 AM Feature #7051: Allow control of what users can view and/or clear notices
The code checks for having the specific new privs to view/clear notices or the "all pages" access. If the "root" user... Phillip Davis
11:05 AM Feature #7051: Allow control of what users can view and/or clear notices
More info: This appears to have happened because the 'admin' user on that VM was somehow not a member of the 'admins'... Jim Pingle
11:02 AM Feature #7051 (Assigned): Allow control of what users can view and/or clear notices
The notice alert/bell isn't displayed to the admin user when this code is in place. If I revert it, they show up. Jim Pingle
02:28 PM Feature #6045: Updates that do not require a reboot should run reroot
Looks like reroot doesn't work with ZFS without changing vfs.root.mountfrom
https://bugs.freebsd.org/bugzilla/show...
Renato Botelho
12:56 PM Feature #6045 (Assigned): Updates that do not require a reboot should run reroot
reroot crashes with ZFS. We will have to detect that case and fall back to a traditional reboot (or see if we can get... Jim Pingle
01:43 PM Bug #7096 (Resolved): Unbound fails to start on boot if specific network devices are configured in the "Network Interfaces"
It starts fine if default ALL is selected.
But if specific interfaces are selected instead it prints bind errors a...
Chris Collins
11:51 AM pfSense Packages Todo #7055 (Feedback): Update OpenVPN Client Export package with OpenVPN 2.4
This is now live for 2.3.2_1 users as well. What little feedback I received was positive. We'll move forward from her... Jim Pingle
11:35 AM Feature #7095 (Resolved): Improve Remote Gateway field description for IPSec VPN Phase 1
I think it would be nice if it would be mentioned that 0.0.0.0 is a valid value for that field
So...
Philippe Schnyder
11:33 AM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
Luke Hamburg wrote:
> _"8.8.8.8 is not a good target"_ huhhh? Then why does https://doc.pfsense.org/index.php/Multi-...
Kill Bill
10:29 AM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
this is from the manual
Connection Health Check: Uses the following methods to check if the WAN interfaces are stil...
Michael Kellogg
10:20 AM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
let me add to this talk past experiences (as i have a couple of maybe the worst isps anywhere ) I had a old dual wan ... Michael Kellogg
10:05 AM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
Luiz:
_"If you monitor a couple of IPs and one of them is really down, the one you really need access, how you are...
→ luckman212
09:45 AM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
Phillip Davis wrote:
> I would like to see something like this also. I had been meaning to look at it a long time ag...
Luiz Souza
09:24 AM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
"excess traffic" -- a 0 byte payload ICMP? I don't think we can call that excess traffic :)
"too much time before...
→ luckman212
09:23 AM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
I would like to see something like this also. I had been meaning to look at it a long time ago! Maybe I will play wit... Phillip Davis
09:19 AM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
No matter how multiple targets are handled, it is worse off in some way (excess traffic, too much time before an outa... Jim Pingle
08:35 AM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
Can we get this one re-opened? This "bit" me badly yesterday at a customer site. Monitor IP of 8.8.8.8 started "flap... → luckman212
11:30 AM Bug #7034 (Resolved): NTP Orphan Mode stratum setting is not displayed in input field
Jim Pingle
11:22 AM Bug #7034: NTP Orphan Mode stratum setting is not displayed in input field
Just tested again with @2.4.0-BETA (amd64) built on Fri Jan 06 01:41:07 CST 2017, FreeBSD 11.0-RELEASE-p5@ and it's w... Thomas Rieschl
11:09 AM Bug #7094 (Duplicate): Unbound startup syntax is incorrect
This one is perhaps complicated to fix.
Currently if a unbound-control reload is issued then unbound will shutdown...
Chris Collins
11:05 AM Bug #7093 (Rejected): "Outgoing Network Interfaces" is broken in dns resolver settings
The "Outgoing Network Interfaces" incorrectly applies the WAN ipv6 link-local when ALL is not selected and also when ... Chris Collins
10:59 AM Feature #7092 (Closed): Kernel modules for alternate congestion control algorithms
These are provided via kernel modules cc_cubic and cc_htcp
I am aware pfsense when its not the endpoint these are ...
Chris Collins
10:38 AM Todo #7091 (Not a Bug): Write upgrade code to rename igb devices to em
As announced at [1] igb devices will become em devices on FreeBSD 12. We need to have some upgrade code ready to dete... Renato Botelho
10:17 AM Bug #6837: Gateway Failover does not failback
Wait, _what?_ Default gateway switching is an experimental feature? That checkbox has been there since at least 2.0.... → luckman212
09:12 AM Bug #7089: Opposite of + or - is occurring when selecting time zone
The thing needs to be kept in-line with what the "standard" tz-database distribution is doing. Otherwise, as Jim says... Phillip Davis
08:49 AM Bug #7089: Opposite of + or - is occurring when selecting time zone
pfSense is not other products. And the Etc zones are NOT what you want, likely ever. We have been tempted to remove o... Jim Pingle
08:37 AM Bug #7089: Opposite of + or - is occurring when selecting time zone
In every other environment I've worked in that I can think of, you can pick the -5 and it's correct. Why is this any ... Geoffrey Bricker
07:52 AM Bug #7089: Opposite of + or - is occurring when selecting time zone
You should not be picking what you think is an offset (but is really a special-use time zone). Pick a geographic zone... Jim Pingle
07:51 AM Bug #7089: Opposite of + or - is occurring when selecting time zone
Just so I can be clear, you're saying the intended behavior is that - is + and + is minus? Every other device I've ev... Geoffrey Bricker
06:01 AM Bug #7089 (Feedback): Opposite of + or - is occurring when selecting time zone
Changes were added to let user know about how it works, as proposed by Phil. Renato Botelho
12:59 AM Bug #7089: Opposite of + or - is occurring when selecting time zone
Suggested enhancement to UI:
https://github.com/pfsense/pfsense/pull/3354
Phillip Davis
08:51 AM Bug #6936: OpenVPN client boot race causes intermittent dependent rule failure.
There is a good chance this has been fixed by #6132 so it's worth trying on a current 2.4 snapshot. Jim Pingle
08:43 AM Bug #6936: OpenVPN client boot race causes intermittent dependent rule failure.
Gavin
Have you retested on a recent 2.4 snap?
→ luckman212
06:32 AM Bug #7090 (Not a Bug): Firewall rule is ignored when action is pass
Configuration error. Post on the forum for discussion. Jim Pingle

01/05/2017

11:38 PM Bug #7089: Opposite of + or - is occurring when selecting time zone
Also, 99.9% of users should be selecting a timezone based on a continent/city in their area. This makes summer time c... Phillip Davis
11:21 PM Bug #7089: Opposite of + or - is occurring when selecting time zone
https://en.wikipedia.org/wiki/Tz_database#Area
"The special area of "Etc" is used for some administrative zones, par...
Phillip Davis
08:22 PM Bug #7089: Opposite of + or - is occurring when selecting time zone
Oh and Yes, the time is also incorrect not just the + and the - Geoffrey Bricker
08:09 PM Bug #7089 (Resolved): Opposite of + or - is occurring when selecting time zone
I select ETC/GMT-5 on the web interface, and typing 'date' in shell shows the opposite, +5. I changed to -4, it went ... Geoffrey Bricker
11:21 PM Bug #7090 (Not a Bug): Firewall rule is ignored when action is pass
Hi,
I've got a firewall rule that reads:
States Protocol Source Port Destination Port Gateway Queue Schedule De...
Walter Steinlein
06:30 PM Bug #7081 (Feedback): Search Domains not populating from RA using SLAAC
Applied in changeset commit:1794ecbb8b37fc97bd1d2fe6ab7ecc19d87a9a68. Jim Pingle
10:45 AM Bug #7081: Search Domains not populating from RA using SLAAC
The field "radomainsearchlist" in the GUI is not referenced anywhere in the backend. Needs some research/testing Jim Pingle
10:40 AM Bug #7081 (Resolved): Search Domains not populating from RA using SLAAC
When I enter nameservers in the DNS list for Router Advertisements in unmanaged mode the client will populate with th... Matthew Fine
05:30 PM Bug #7088 (Feedback): DHCP does not accept input into MAC Control Fields.
Applied in changeset commit:80e7011fddd29a387c4c84b68c8c49dce4494729. Jim Pingle
05:19 PM Bug #7088: DHCP does not accept input into MAC Control Fields.
This affects the main DHCP settings page not just the pools
is_macaddr() lost its $partial parameter/support require...
Jim Pingle
04:15 PM Bug #7088 (Confirmed): DHCP does not accept input into MAC Control Fields.
Jim Pingle
04:03 PM Bug #7088 (Resolved): DHCP does not accept input into MAC Control Fields.
"If a mac allow list is specified, it must contain only valid partial MAC addresses."
Attempted input (I also trie...
Shane Poteet
04:09 PM pfSense Packages Bug #7087 (Rejected): DNSBL service does not start
Is pfBlocker actually installed, enabled, and properly configured?
Please post on the forum in the pfBlockerNG boa...
Jim Pingle
03:51 PM pfSense Packages Bug #7087: DNSBL service does not start
Other errors:... Brenden Smerbeck
03:48 PM pfSense Packages Bug #7087 (Rejected): DNSBL service does not start
Noticed this while configuring 2.4. dnsbl service does not start, and the .pid file has no value. Brenden Smerbeck
01:10 PM Bug #7053 (Resolved): OpenVPN Client Specific Overrides - GUI Omissions and Errors
Jim Pingle
12:37 PM Bug #7086 (Resolved): stale zfs file systems
I am not sure if this is a bug or a feature. Seems the 'Auto install'-values are used from the native FreeBSD while p... Ekki Gehm
12:29 PM Feature #7085 (New): Edit Firewall Rules Seperator
Once a Firewall Rule Separator is added you cannot edit it. You have to delete and add it again to make any changes. Adam Piasecki
12:02 PM Todo #7084 (Resolved): Intel IEEE 802.11ac wireless network driver
Hey folks,
I wonder if it would be possible to include the if_iwm.ko and related firmware .kos. They are new as of...
Ekki Gehm
11:35 AM Bug #7083 (Resolved): Put back some visual hint for required fields
Pretty sure the convention was that the @<fielddescr>@ for a @<required/>@ field was shown in bold in pfSense before ... Kill Bill
11:15 AM Bug #7082: pkg_edit.php - impossible to use default_value with rowhelperfield
I'm kinda unsure that the <default_value> works like that even for non-rowhelperfield fields. :-) What I see in packa... Kill Bill
11:04 AM Bug #7082: pkg_edit.php - impossible to use default_value with rowhelperfield
I will investigate.
I presume the desired functionality is that if the element has no current (stored) value, the ...
Anonymous
11:00 AM Bug #7082 (New): pkg_edit.php - impossible to use default_value with rowhelperfield
I mean, things like:... Kill Bill
10:52 AM Bug #5673: pkg_edit - Rowhelper descriptions are not printing
So, is it possible to have the @<description>@ tag printed somehow? (As a hover on the @<fielddescr>@ or whatever?) W... Kill Bill
10:48 AM Bug #6972 (Resolved): "Are you sure you wish to?" prompts and other issues with deleting networks from network-type aliases
Renato Botelho
10:34 AM Bug #6972: "Are you sure you wish to?" prompts and other issues with deleting networks from network-type aliases
Looks all good here. Thanks. ;) Kill Bill
08:15 AM Bug #6972: "Are you sure you wish to?" prompts and other issues with deleting networks from network-type aliases
Fixed. Please retest. Anonymous
10:45 AM Bug #7080 (Resolved): pkg_edit.php - rowhelper fielddescr disappears when last row is deleted
Jim Pingle
10:38 AM Bug #7080: pkg_edit.php - rowhelper fielddescr disappears when last row is deleted
Well, this was apparently another manifestation of Bug #6972. The issue seems gone with ea02e3cf5d54c9f1ebbe09d9fa552... Kill Bill
08:25 AM Bug #7080 (Feedback): pkg_edit.php - rowhelper fielddescr disappears when last row is deleted
Unable to reproduce with Safari, Firefox or Chrome. Am I doing something wrong?
!rowhelper.gif!
Anonymous
08:10 AM Bug #7080 (Resolved): pkg_edit.php - rowhelper fielddescr disappears when last row is deleted
An example: https://github.com/pfsense/FreeBSD-ports/blob/devel/www/pfSense-pkg-squid/files/usr/local/pkg/squid_rever... Kill Bill
10:38 AM Bug #7050: Limiter with PFsense 2.4 transparent proxy
yeah, sort of. this is a fallout of 4326 not being properly tested under all conditions (nat, binat and rdr) - they ... Luiz Souza
08:00 AM Feature #7077: Display negotiated data encryption algorithm in OpenVPN connection status
"verbosity 4"? As in the system logs? Sure, it's in the logs, sure, but scraping logs isn't proper status output. It ... Jim Pingle
07:52 AM Feature #7077: Display negotiated data encryption algorithm in OpenVPN connection status
Their initial reply is that it's available if you use verbosity 4... which is correct, but not entirely useful. I'm a... Jeff Wischkaemper
07:49 AM pfSense Packages Bug #6950 (Resolved): Auto Config Backup always reports success
Renato Botelho
04:04 AM pfSense Packages Bug #6950: Auto Config Backup always reports success
Works (at least for cases where write_config() returns false, and there's not really much else that could be done here.) Kill Bill
07:20 AM Bug #7033: Hidden rule break the policy routing
Jim Pingle wrote:
> Duplicate of #1136
>
> If you must have a second gateway on WAN, add floating rules to match ...
Maxence Sartiaux
06:17 AM pfSense Packages Feature #6951 (Resolved): Disable Auto Config Backup without uninstalling
Renato Botelho
04:01 AM pfSense Packages Feature #6951: Disable Auto Config Backup without uninstalling
Merged and works, can be closed. Kill Bill

01/04/2017

11:16 PM pfSense Packages Todo #7055: Update OpenVPN Client Export package with OpenVPN 2.4
I just pushed this to 2.3.3 as well for more testing. Jim Pingle
07:58 AM pfSense Packages Todo #7055: Update OpenVPN Client Export package with OpenVPN 2.4
A new version of OpenVPN client export for pfSense 2.4 with OpenVPN 2.4 is up now for testing.
Key changes:
* Ope...
Jim Pingle
10:50 PM Bug #6962 (Resolved): GUI allows selecting missing diffe-helman Paremeters for OpenVPN
I fixed this up among the other OpenVPN improvements this week. Jim Pingle
09:10 PM Todo #7054 (Resolved): Update OpenVPN to 2.4.0
Jim Pingle
09:10 PM Bug #7034 (Feedback): NTP Orphan Mode stratum setting is not displayed in input field
Applied in changeset commit:531c348639adb8b7e7d190e8fdab709fea61f61a. Jim Pingle
09:00 PM Bug #7034 (Confirmed): NTP Orphan Mode stratum setting is not displayed in input field
Yep, something isn't quite right with how it's doing validation. Jim Pingle
03:45 PM Bug #7034: NTP Orphan Mode stratum setting is not displayed in input field
I just tested it with the current nightly (@2.4.0-BETA (amd64) built on Wed Jan 04 13:38:53 CST 2017; FreeBSD 11.0-RE... Thomas Rieschl
08:00 PM Bug #7053 (Feedback): OpenVPN Client Specific Overrides - GUI Omissions and Errors
Applied in changeset commit:b6dd335e6b81c89f2e4dd63cbd638853ebe2a275. Jim Pingle
07:51 PM Feature #7061 (Resolved): OpenVPN 2.4 supports pushing IPv6, allow the GUI to define IPv6 OpenVPN DNS servers to push to clients.
Jim Pingle
07:34 PM Bug #6099: igmpproxy does not recognize upstream interface
Is the change also available to 2.3.3 branch ? Alexandre Paradis
09:00 AM Bug #6099: igmpproxy does not recognize upstream interface
Luiz Otavio O Souza wrote:
> Ooops. Sorry for the breakage.
>
> Fixed in the latest version.
>
> Thanks for t...
Lars Veldcholte
05:51 AM Bug #6099 (Resolved): igmpproxy does not recognize upstream interface
Renato Botelho
07:14 PM Feature #7077: Display negotiated data encryption algorithm in OpenVPN connection status
I'll see what I can do and report back. Jeff Wischkaemper
07:09 PM Feature #7077: Display negotiated data encryption algorithm in OpenVPN connection status
Nothing in particular comes to mind, it would be nice to see all of the known parameters for connecting clients/serve... Jim Pingle
06:45 PM Feature #7077: Display negotiated data encryption algorithm in OpenVPN connection status
Will do. Is there something specific I can ask for over there that would make it easier for you? Jeff Wischkaemper
05:31 PM Feature #7077 (Needs Patch): Display negotiated data encryption algorithm in OpenVPN connection status
We have no way to detect that currently. OpenVPN does not report that in any of their status output. Open a feature r... Jim Pingle
03:59 PM Feature #7077 (Resolved): Display negotiated data encryption algorithm in OpenVPN connection status
NCP is great. Not knowing what cipher NCP negotiated is less great.
It would be excellent to add something on the...
Jeff Wischkaemper
06:48 PM Bug #7079 (Closed): ClamAV C-ICAP causing Kernel Panic and System Crash
Running ClamAV causes sporadic kernel panics and resets with the following syntax:... Brenden Smerbeck
06:44 PM Feature #7078: Allow reordering of client specific overrides in OpenVPN
Organization, primarily. I have about 100 of them which are are generally speaking associated with different sites. I... Jeff Wischkaemper
05:27 PM Feature #7078: Allow reordering of client specific overrides in OpenVPN
For what purpose? They are all mutually exclusive. Jim Pingle
05:02 PM Feature #7078 (New): Allow reordering of client specific overrides in OpenVPN
It would be useful to rearrange the client specific overrides in OpenVPN. Jeff Wischkaemper
06:22 PM Feature #7072 (Resolved): vpn_openvpn_server.php / vpn_openvpn_client.php : Add controls to OpenVPN for Negotiable Crypto Parameters
Looks good Jim Pingle
04:26 PM Feature #7072 (Feedback): vpn_openvpn_server.php / vpn_openvpn_client.php : Add controls to OpenVPN for Negotiable Crypto Parameters
Fixed Anonymous
03:38 PM Feature #7072 (Assigned): vpn_openvpn_server.php / vpn_openvpn_client.php : Add controls to OpenVPN for Negotiable Crypto Parameters
There's one little problem left with the NCP list control. Clicking in empty area on the right side adds a "null" ent... Jim Pingle
01:50 PM Feature #7072 (Feedback): vpn_openvpn_server.php / vpn_openvpn_client.php : Add controls to OpenVPN for Negotiable Crypto Parameters
Applied in changeset commit:fa351dd3c13e65dfabfb0f2ac2ed72b332276892. Jim Pingle
01:12 PM Feature #7072: vpn_openvpn_server.php / vpn_openvpn_client.php : Add controls to OpenVPN for Negotiable Crypto Parameters
See also:
* commit:bd07fbdb4b81fc358b8fa55b06469dde7a3870df
* commit:6c00adf3316d2c5214f7e9cf2e5f138c32845d58
* co...
Jim Pingle
02:37 PM Bug #6972: "Are you sure you wish to?" prompts and other issues with deleting networks from network-type aliases
To reproduce:
1/ Edit some alias
*2/ Add some rows*
3/ Now, try to delete them (or the previously existing rows)...
Kill Bill
02:33 PM Bug #6972: "Are you sure you wish to?" prompts and other issues with deleting networks from network-type aliases
I am unable to reproduce this in the updated version. Clicking the trash can icon previously did not delete for me, b... Anonymous
02:08 PM Bug #6972 (Assigned): "Are you sure you wish to?" prompts and other issues with deleting networks from network-type aliases
Renato Botelho
01:35 PM Bug #6972: "Are you sure you wish to?" prompts and other issues with deleting networks from network-type aliases
OK, got to testing. As a good news, the annoying prompt is gone. The second symptom (unable to delete added rows when... Kill Bill
12:14 PM Bug #7074 (Resolved): Due to OpenVPN protocol selection changes, automatic port number guessing/adjustment is not working
I tried a few combinations and it all worked. Creating a new instance or using the wizard properly guessed the next h... Jim Pingle
08:00 AM Bug #7074 (Feedback): Due to OpenVPN protocol selection changes, automatic port number guessing/adjustment is not working
Applied in changeset commit:f69e098f41bb3937b244b557969009535a911ef4. Renato Botelho
06:48 AM Bug #7074: Due to OpenVPN protocol selection changes, automatic port number guessing/adjustment is not working
I'll work on it Renato Botelho
12:13 PM pfSense Packages Bug #6527 (Feedback): Squid 3.5 - Deprecated "ssl_bump server-first all" don't allow SNI in transparent mode with HTTPS/SSL Interception
PR has been merged to 2.4.0 and 2.3.3 snapshots Renato Botelho
11:32 AM Feature #7071 (Resolved): Add TLS Encryption (--tls-crypt) as an optional TLS Key usage type for OpenVPN 2.4
Works Jim Pingle
10:54 AM Bug #7076 (Duplicate): Packets accepted by IP but rejected because "Allow IP options" is disabled are not logged
Hi,
I added a rule to allow multicast traffic by IP without "Allow IP options" enabled (because I did not yet know...
JJ Meijer
10:46 AM Bug #6906 (Resolved): Issues with /tmp and /var in RAM on 2.4
Works fine on two different systems here, thanks! Jim Pingle
08:13 AM Bug #6906 (Feedback): Issues with /tmp and /var in RAM on 2.4
The issue was happening on ZFS and should be fixed after commit:b712dd529e2445fc20e983815a80a4e8ea109760 Renato Botelho
10:19 AM Bug #5993: dhcp6c not started until an RA received
OK, had a look around that bit of code. This is what I have found:
1. RTSOLD still launches multiple dhcp6c client...
Martin Wasley
02:41 AM Bug #5993: dhcp6c not started until an RA received
The dhcpc before RA was originally my fix for an issue we have with Sky ISP in the U.K. I got very busy with work and... Martin Wasley
09:55 AM Bug #6856 (Duplicate): "Force Config Settings" buton on master causes slave to loss IP alises on lo0
Duplicate of #7010 which is already fixed. Jim Pingle
01:14 AM Bug #4310: Limiters + HA results in hangs on secondary
Dear Luiz! Can we expect real fix in 2.4? We are waiting for it too long, and this is a really critical problem, sinc... Vladimir Usov

01/03/2017

11:30 PM Bug #7050: Limiter with PFsense 2.4 transparent proxy
Luiz Otavio O Souza wrote:
> The issue here is limiter (dummynet) and pf redir on the same interface.
> The transpa...
Kill Bill
05:45 PM Bug #7050 (Confirmed): Limiter with PFsense 2.4 transparent proxy
The issue here is limiter (dummynet) and pf redir on the same interface.
The transparent proxy adds a rdr rule to ...
Luiz Souza
09:23 PM Bug #7066: vmx(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3
I also see this on Hyper-V virtual NICs (not legacy). Perhaps this is a more generalized issue?
Michael OBrien
05:14 PM Bug #7066: vmx(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3
This appears to be caused by r263259 in FreeBSD 11 - Add Tx/Rx multiqueue support to vmx(4).
I believe that ALTQ d...
Greg Siemon
05:46 PM Bug #6594: Package reinstallation post-config restore hangs if no Internet connectivity
I was just hit by this as well. In my case I am preparing to replace a device at a remote site. I used pfsense's rest... Pig Monkey
04:44 PM Bug #6099: igmpproxy does not recognize upstream interface
No problem, sh** happens ;-)
I updated my box today to version 2.4.0.b.20170103.0147.
Checked igmpproxy for new b...
Philipp Haefelfinger
01:03 PM pfSense Packages Bug #6987: ntopng needs Google API key for GeoIP map
It is working on 2.3.3 snapshots as well. Kill Bill
11:21 AM pfSense Packages Bug #6987: ntopng needs Google API key for GeoIP map
Thanks, that's the information I was missing.
Stuart Wyatt
08:29 AM pfSense Packages Bug #6987: ntopng needs Google API key for GeoIP map
ntopng 2.4 is available on pfSense 2.4, and it works there. If/when the package is updated on other branches it will ... Jim Pingle
08:16 AM pfSense Packages Bug #6987: ntopng needs Google API key for GeoIP map
The bug referenced the need for ntopng version 2.4 to resolve the problem, so why is it being closed when version 2.2... Stuart Wyatt
05:28 AM pfSense Packages Bug #6987 (Closed): ntopng needs Google API key for GeoIP map
Renato Botelho
03:46 AM pfSense Packages Bug #6987: ntopng needs Google API key for GeoIP map
Apparently no patching required with ntopng-2.4.2016.10.14 - you can configure the API key in Preferences - Users - G... Kill Bill
11:53 AM Bug #7075 (Resolved): firewall states show negative value for total bytes processed
As seen in the screenshot, the "Firewall >> Rules >> LAN" page shows a negative number for total bytes processed by a... Bryan Stenson
11:42 AM Feature #4821: PPPoE WANs do not take full advantage of NIC driver queues for receiving traffic
According to this
https://lists.freebsd.org/pipermail/freebsd-net/2013-May/035564.html
Script that can solve CPU 1...
Vladimir Suhhanov
11:10 AM Bug #7073 (Resolved): OpenVPN 2.4: client-cert-not-required is deprecated, replace with "verify-client-cert none"
Works Jim Pingle
11:10 AM Bug #7073 (Feedback): OpenVPN 2.4: client-cert-not-required is deprecated, replace with "verify-client-cert none"
Applied in changeset commit:4cfd15a94a97445d1334ad87bddf0c3700f74bf2. Jim Pingle
10:38 AM Bug #7073 (Resolved): OpenVPN 2.4: client-cert-not-required is deprecated, replace with "verify-client-cert none"
In OpenVPN 2.4 "client-cert-not-required" is deprecated, the new functional equivalent directive is "verify-client-ce... Jim Pingle
11:10 AM Bug #7068 (Resolved): Prevent GCM encryption from being selected for Shared Key modes in OpenVPN
Works Jim Pingle
11:09 AM Feature #7064 (Resolved): Add LZO4 options for OpenVPN 2.4
Seems to work in every combination I've thrown at it. Jim Pingle
10:58 AM Bug #7074 (Resolved): Due to OpenVPN protocol selection changes, automatic port number guessing/adjustment is not working
After the protocol selection changes needed for #7062, the OpenVPN server page is not adjusting the port numbers like... Jim Pingle
09:56 AM Feature #7072 (Resolved): vpn_openvpn_server.php / vpn_openvpn_client.php : Add controls to OpenVPN for Negotiable Crypto Parameters
OpenVPN 2.4 automatically attempts to negotiate crypto between the client and server, due to this, the tunnel can end... Jim Pingle
09:40 AM Feature #7071 (Feedback): Add TLS Encryption (--tls-crypt) as an optional TLS Key usage type for OpenVPN 2.4
Applied in changeset commit:c854afcc3d7830414a2514a640248a5b239569a3. Jim Pingle
09:27 AM Feature #7071 (Resolved): Add TLS Encryption (--tls-crypt) as an optional TLS Key usage type for OpenVPN 2.4
OpenVPN 2.4 added --tls-crypt which works similar to --tls-auth, but also encrypts the control channel. It does not r... Jim Pingle
08:00 AM Bug #6357 (Feedback): Dynamic DNS (RFC2136) updates always considered successful
Applied in changeset commit:3bfb38f99cd1c15b5d502b3dbabc913226550d9c. Renato Botelho
07:24 AM Bug #6357 (Assigned): Dynamic DNS (RFC2136) updates always considered successful
Renato Botelho
05:30 AM Todo #7054 (Feedback): Update OpenVPN to 2.4.0
Basic updates are complete, now dealing with specific changes in separate tickets Renato Botelho
05:26 AM Bug #7070 (Duplicate): Sync username for xmlrmc seems considerate
Already fixed on 2.4.0 - see #809 Renato Botelho
05:01 AM Bug #7070 (Duplicate): Sync username for xmlrmc seems considerate
On master I do the folowing configuration:
!pfsense.png!
I have the folowing log on master :
@/rc.filter_sync...
Lilian Deloche
03:49 AM pfSense Packages Bug #7067: usbhid-ups - no such file or directory
There is no such thing needed, simply reboot after installing the package. Kill Bill
03:29 AM Feature #7069: Provide knob to disable state display in Diagnostics > States until a filter has been submitted.
https://github.com/pfsense/pfsense/pull/3344 Chris Linstruth
12:53 AM Feature #7069 (Resolved): Provide knob to disable state display in Diagnostics > States until a filter has been submitted.
Diagnostics > States becomes cumbersome on systems with large state tables. Provide a mechanism to suppress the displ... Chris Linstruth
12:10 AM Feature #2358: NAT64 support
UPVOTE!
First of all, thank you for the great open source firewall product. As Apple starts to require all the new...
DB Tsai

01/02/2017

09:48 PM Bug #6906 (Assigned): Issues with /tmp and /var in RAM on 2.4
On a freshly installed VM I activated the option and when it rebooted, it came up all the way but it shows no package... Jim Pingle
09:20 AM Bug #6906 (Feedback): Issues with /tmp and /var in RAM on 2.4
I've used wrong ticket # in commit log. Relevant commits are:
commit:9bf6cdc135ddf108bc08f048687130c09cd09f4b and ...
Renato Botelho
09:20 PM Bug #7068 (Feedback): Prevent GCM encryption from being selected for Shared Key modes in OpenVPN
Applied in changeset commit:c13c0fd0fe547fa8e35997d7ede7f8a6b33088fa. Jim Pingle
09:18 PM Bug #7068 (Resolved): Prevent GCM encryption from being selected for Shared Key modes in OpenVPN
OpenVPN 2.4 supports GCM encryption but it cannot be used in Shared Key mode. If you attempt to activate it, OpenVPN ... Jim Pingle
08:30 PM Feature #7064 (Feedback): Add LZO4 options for OpenVPN 2.4
Applied in changeset commit:a4b3624650aa46c9dc4a20afc5b522c6b9191904. Jim Pingle
08:11 PM Bug #1994 (Rejected): Remove priority on HFSC
HFSC support priorities just as any other scheduler:
hfsc Hierarchical Fair Service Curve. Queues attached ...
Luiz Souza
09:20 AM Bug #1994: Remove priority on HFSC
Is there any possibility to change the target to 2.4.1?
Or... just fix it somebody, please :)
Vladimir Suhhanov
02:34 PM Bug #7062 (Resolved): OpenVPN 2.4 treats "udp" and "tcp" as dual stack now, move old preference to udp4/tcp4
OpenVPN's man page and docs say it should work but it tosses an error on the bind directive.
It appears to do the ...
Jim Pingle
11:25 AM Bug #7062 (Assigned): OpenVPN 2.4 treats "udp" and "tcp" as dual stack now, move old preference to udp4/tcp4
This apparently still needs one more change. The IPv6 only modes need:... Jim Pingle
01:29 PM Bug #7057 (Resolved): Hidden field displays in browser
Anonymous
01:09 PM Bug #7066: vmx(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3
For what it's worth, I saw the same behavior with igb interfaces after restoring a 2.3 config with a shaper. Landon Timothy
09:49 AM Bug #7066 (Resolved): vmx(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3
Attempting to configure traffic shaping on a pfSense 2.4 VMware VM with vmx NICs results in an error:... Jim Pingle
12:54 PM Feature #7063 (Resolved): Add OpenVPN 2.4 ECDH options
I pushed a change with help text for DH & ECDH and also updated the doc wiki a bit: https://doc.pfsense.org/index.php... Jim Pingle
01:52 AM Feature #7063: Add OpenVPN 2.4 ECDH options
A little fix in https://github.com/pfsense/pfsense/pull/3340 Phillip Davis
11:39 AM Bug #6099: igmpproxy does not recognize upstream interface
Ooops. Sorry for the breakage.
Fixed in the latest version.
Thanks for the report.
Luiz Souza
11:24 AM Feature #7061: OpenVPN 2.4 supports pushing IPv6, allow the GUI to define IPv6 OpenVPN DNS servers to push to clients.
Works fine. Client receives IPv6 DNS servers if they are configured. Jim Pingle
11:19 AM Feature #2766 (Resolved): status_openvpn.php needs IPv6 support
Works! Jim Pingle
10:42 AM pfSense Packages Bug #7067 (Closed): usbhid-ups - no such file or directory
After installing NUT and connecting a generic (Costco) CyberPower UPS, I receive the following error in the log:
u...
Karl Janus
10:40 AM Bug #6972: "Are you sure you wish to?" prompts and other issues with deleting networks from network-type aliases
Applied in changeset commit:fab3c245cfb52964cebdab2ea47dddb21731352a. Anonymous
10:37 AM Bug #6972 (Feedback): "Are you sure you wish to?" prompts and other issues with deleting networks from network-type aliases
I am only able to reproduce this with Chrome but it should now be resolved. Anonymous
09:58 AM Bug #5976 (Assigned): Load cryptodev as a kernel module
reopening since crypto is not cryptodev. Pointy hat to me Renato Botelho
09:37 AM Bug #7065 (Resolved): OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
Renato Botelho
08:54 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
Working now.
Thanks again for the quick turnaround.
Jeff Wischkaemper
08:27 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
Now it˛`s all good.
Thanks again!
Greg M
08:00 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
Yes it's building right now, we restarted the snapshot builds to make sure it gets picked up. Jim Pingle
07:57 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
Thanks for the quick response on this Jim. I assume another snapshot will hit later this morning or early afternoon? Jeff Wischkaemper
07:50 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
That was probably from before the sync. Clear the error and check again. If you can, reboot and see if the error is g... Jim Pingle
07:45 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
I just have this now...
Crash report begins. Anonymous machine information:
amd64
11.0-RELEASE-p5
FreeB...
Greg M
07:44 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
OK. We will wait for it to show up in snapshots and re-test and then if it's OK there, this can be closed. Jim Pingle
07:43 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
Yep, all works now.
Thanks!
Greg M
07:36 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
I just pushed another change that should help, give it ~5-10 mins to show up on github and then gitsync or apply that... Jim Pingle
07:34 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
Greg M wrote:
> Ummm I`m on: 2.4.0.b.20170102.0439
> Issue persists.
Try to gitsync with master or wait next sna...
Renato Botelho
07:32 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
Ummm I`m on: 2.4.0.b.20170102.0439
Issue persists.
Greg M
07:29 AM Bug #7065 (Feedback): OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
This should be fixed by the PR that was merged a short while ago and is already in the latest snapshot. Update to the... Jim Pingle
07:26 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
I am seeing the same errors as Greg, though I'm using a DH of 4096 instead of 2048.
Problem is still occurring on...
Jeff Wischkaemper
07:24 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
Forgot to add...
If I use ECDH only it works...
Greg M
07:23 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
Hi!
I`m also affected.
First thing:
Crash report begins. Anonymous machine information:
amd64
11.0...
Greg M
07:05 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
The only error that could cause the settings to not be written is if you have selected DH parameters that do not have... Jim Pingle
01:12 AM Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
First problem I found is if you edit/save a client, it writes the protocol description to the config, rather than the... Phillip Davis
08:05 AM Bug #7059 (Resolved): firewall_rules_edit.php - strlen error when there are input errors
Looks good, no more strlen error. Jim Pingle
04:51 AM Bug #7059 (Feedback): firewall_rules_edit.php - strlen error when there are input errors
PR has been merged Renato Botelho
04:15 AM Bug #5218: CSRF magic modifies content in pfSense interface
No, it's back again on my installation (2.3.2), in my case while editing php files with embedded html Raffaele Candeliere

01/01/2017

11:34 PM Bug #7065 (Resolved): OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release
After upgrading to the latest release (20170101.1906), OpenVPN server conf files are not populated in the /var/etc di... Jeff Wischkaemper
06:58 PM Feature #7064 (Resolved): Add LZO4 options for OpenVPN 2.4
OpenVPN 2.4 added support for LZO4 which gets better performance and consumes less CPU... Jim Pingle
06:30 PM Feature #7063 (Feedback): Add OpenVPN 2.4 ECDH options
Applied in changeset commit:f888c35aa25b38cdf5b1a73fc65ed6959451bfe0. Jim Pingle
06:23 PM Feature #7063 (Resolved): Add OpenVPN 2.4 ECDH options
OpenVPN 2.4 added two ECDH-related options:
1. Settings "dh" to "none" tells OpenVPN to use only ECDH and not DH
...
Jim Pingle
06:03 PM Bug #7057: Hidden field displays in browser
Using the addGlobal() method is the best way to do this as Phil has demonstrated. That creates a simple input without... Anonymous
04:49 PM Feature #5549: Additional DNS entries in General Setup would be good for 3 or more WAN's
Yup. It'd be awesome if those settings were moved to the relevant place (i.e., DNS forwarder/resolver settings). This... Kill Bill
03:29 PM Feature #5549: Additional DNS entries in General Setup would be good for 3 or more WAN's
That's for the host resolver itself -- dnsmasq and unbound in forwarding mode will pick up more. Jim Pingle
03:01 PM Feature #5549: Additional DNS entries in General Setup would be good for 3 or more WAN's
Maybe someone could instead fix/nuke the misleading note from the GUI, instead of putting in more DNS servers that wi... Kill Bill
01:00 PM Feature #5549: Additional DNS entries in General Setup would be good for 3 or more WAN's
this is true add ipv6 and it has even more need
Michael Kellogg
04:00 PM Bug #7062 (Feedback): OpenVPN 2.4 treats "udp" and "tcp" as dual stack now, move old preference to udp4/tcp4
Applied in changeset commit:ca3666766588538934bedc6933934fbadb9249ef. Jim Pingle
03:47 PM Bug #7062 (Resolved): OpenVPN 2.4 treats "udp" and "tcp" as dual stack now, move old preference to udp4/tcp4
OpenVPN 2.4 changed the meaning of "udp" and "tcp" to be dual stack, listening on IPv6 on all interfaces at once. "lo... Jim Pingle
01:40 PM Feature #7061 (Feedback): OpenVPN 2.4 supports pushing IPv6, allow the GUI to define IPv6 OpenVPN DNS servers to push to clients.
Applied in changeset commit:6a638752c8a3861a3309c3dc8d557c8904ff84d6. Jim Pingle
01:31 PM Feature #7061 (Resolved): OpenVPN 2.4 supports pushing IPv6, allow the GUI to define IPv6 OpenVPN DNS servers to push to clients.
OpenVPN 2.4 supports pushing IPv6, allow the GUI to define IPv6 OpenVPN DNS servers to push to clients.
To me, I h...
Jim Pingle
11:58 AM Bug #7036: 2.4 ZFS on RCC-VE 2440 hangs
I also have the same issue on my RCC-VE 2440. I've tried with both Bios 06 and 08, same issue. It takes 15-20 minut... J Harnick
11:30 AM Feature #2766 (Feedback): status_openvpn.php needs IPv6 support
Applied in changeset commit:bffa3185a63cbdd727701704d3b82abd7c61a78c. Jim Pingle
09:16 AM Feature #2766: status_openvpn.php needs IPv6 support
It's finally there in OpenVPN 2.4!
And since it's caused the status page to report fields incorrectly, it needs to...
Jim Pingle
10:31 AM Bug #6340: fsck hangs boot in background, fails to produce any action, resulting in broken firewall

Turn off sync mode.
On a clean system, before an issue crops up. It will let UFS do what it does, and not genera...
ky41083 -
08:00 AM Todo #7060 (Rejected): Logically organise various backup/restore functions?
We don't like to move things just to move them, unless it's worth updating all of the documentation and other related... Jim Pingle
07:13 AM Todo #7060 (Rejected): Logically organise various backup/restore functions?
I'd like to do a quick reorganise of the various backup and restore functions in the GUI. While not a huge problem it... Stilez y
05:32 AM Feature #4632: Support for Multipath TCP (MPTCP)
Hello,
Could you please add this feature on 2.4.0 version?
serdar kekik
05:11 AM Bug #2247: Misleading security permission
Next round of possibilities in PR https://github.com/pfsense/pfsense/pull/3337 Phillip Davis

12/31/2016

10:33 PM Bug #7059: firewall_rules_edit.php - strlen error when there are input errors
Try PR https://github.com/pfsense/pfsense/pull/3334 Phillip Davis
09:31 AM Bug #7059 (Resolved): firewall_rules_edit.php - strlen error when there are input errors
Craft an invalid firewall rule, such as one set for IPv4 with an IPv6 src/dst, and when the input errors are displaye... Jim Pingle
07:45 AM Bug #7058: Alias type-checking issues
You cannot specify either one in the rule directly because it doesn't make sense. Use an alias with mixed contents in... Jim Pingle
07:31 AM Bug #7058: Alias type-checking issues
In which case flip the question on-end, why does the code (_firewall_rules_edit.php_) seem to disallow IPv4 and IPv6 ... Stilez y
07:01 AM Bug #7058 (Not a Bug): Alias type-checking issues
What's the bug here?
pf allows mixed aliases and only uses appropriate addresses when matching. We allow it becaus...
Jim Pingle
04:50 AM Bug #7058 (Not a Bug): Alias type-checking issues
pfSense really needs a more strongly type-checked alias system/API/library.
Current example: often these days a s...
Stilez y
07:25 AM Bug #6099: igmpproxy does not recognize upstream interface
edit: 31-12-2016
I've established a working setup, using the develop version, already on theh box.
When I disable...
Vincent Gijsen
05:04 AM Bug #6099: igmpproxy does not recognize upstream interface
Philipp Haefelfinger wrote:
> Is this commit in the latest build applied? If yes, there seems to be something buggy ...
Vincent Gijsen
07:23 AM Bug #2247: Misleading security permission
See "PR 3331":https://github.com/pfsense/pfsense/pull/3331 . Note added to assignment pages, probably suffices? Stilez y
05:50 AM Bug #2247: Misleading security permission
And as soon as you have "Diagnostics->Edit File" you can change whatever code you like, so you can add/modify code to... Phillip Davis
05:07 AM Bug #2247: Misleading security permission
I suppose that "WebCfg - All pages" includes shell command prompt, so it's clearly on reflection going to have shell ... Stilez y
05:27 AM Bug #7057: Hidden field displays in browser
PR https://github.com/pfsense/pfsense/pull/3329
I made the "Floating" field be created with the same construction as...
Phillip Davis
03:40 AM Bug #7057 (Resolved): Hidden field displays in browser
_firewall_rules_edit.php_ on Firefox 50.1, see attached screenshot
Html looks correct (contains "hidden" parameter...
Stilez y
05:11 AM Bug #2873: IPv6 rules, filter by protocol
As of 2.3.x the original issue is resolved (it's now allowed/valid) so this issue can be closed as resolved Stilez y

12/30/2016

08:51 PM Bug #6911: no network on hyperv-v 2012 R1
This is not so easy, there are a lot more relevant commits to MFC, a lot. Luiz Souza
05:17 AM Bug #6911: no network on hyperv-v 2012 R1
This seems to be relevant commit - https://svnweb.freebsd.org/base?view=revision&revision=306433
Assign to Luiz for ...
Renato Botelho
06:43 PM Bug #7053: OpenVPN Client Specific Overrides - GUI Omissions and Errors
I think I understand why the text under Remote networks is written the way it is now. Apologies for the misunderstan... Greg Siemon
06:20 PM Bug #7053: OpenVPN Client Specific Overrides - GUI Omissions and Errors
All of the settings are from the perspective of the server, even the override. The descriptions reflect this, they do... Jim Pingle
05:25 PM Bug #7053: OpenVPN Client Specific Overrides - GUI Omissions and Errors
Jim Pingle wrote:
> The wording of IPv4 Remote Networks is correct. The box defines a client-side network ("routed _...
Greg Siemon
10:10 AM Bug #7053: OpenVPN Client Specific Overrides - GUI Omissions and Errors
OpenVPN 2.4 makes it more obvious that you can't mix static IPv4 in an override with dynamic IPv6, so there is a grea... Jim Pingle
07:16 AM Bug #7053: OpenVPN Client Specific Overrides - GUI Omissions and Errors
The wording of IPv4 Remote Networks is correct. The box defines a client-side network ("routed _to_ this client") for... Jim Pingle
01:59 AM Bug #7053 (Resolved): OpenVPN Client Specific Overrides - GUI Omissions and Errors
The OpenVPN Client Specific Overrides page under OpenVPN settings only has a single Tunnel Network field. In fact t... Greg Siemon
02:37 PM Bug #6981: IPv6, rc.newwanipv6, flooding log and resets connection periodically
Happy to helped. Last good action for 2016.
Happy new year^^
Marcel Mayer
12:02 PM Bug #6981: IPv6, rc.newwanipv6, flooding log and resets connection periodically
It does work for me now - Marcel's hint to check "Request only an IPv6 prefix" was indeed correct. After two more reb... Arno Gramatke
11:00 AM Bug #7050: Limiter with PFsense 2.4 transparent proxy
Luiz good afternoon, I have two files as you requested, one working perfectly, which is called BKP_2.1.5_Functionando... Nelson Junior
09:36 AM Todo #7054 (Assigned): Update OpenVPN to 2.4.0
Package was updated as well Renato Botelho
07:33 AM Todo #7054 (Resolved): Update OpenVPN to 2.4.0
Update OpenVPN to 2.4.0 and make necessary adjustments. Noted after a quick look:
* Remove tun-ipv6 from config si...
Renato Botelho
08:08 AM Bug #7056: Add gpg keys to repo for proper iso download verification method
Ah, I had assumed it was simply two httpd's on the same box as they had an adjacent IP address.
Still however, if ...
John Smith
07:59 AM Bug #7056 (Duplicate): Add gpg keys to repo for proper iso download verification method
Duplicate of #4472
That said, a _copy_ of the hash is on the same server as the files, but the hash is also availa...
Jim Pingle
07:49 AM Bug #7056 (Duplicate): Add gpg keys to repo for proper iso download verification method
Currently there is no legitimate way to properly verify the .iso download has not been tampered with.
The sha256 f...
John Smith
07:40 AM pfSense Packages Todo #7055 (Resolved): Update OpenVPN Client Export package with OpenVPN 2.4
OpenVPN 2.4 has made a few changes to the Windows installer that may need accounting for. See https://community.openv... Jim Pingle
07:07 AM Bug #6982: Nested Aliases with FQDNs do not populate parent table in some cases
Port aliases work again with that last commit. Will leave it open waiting for feedback to make sure the original issu... Jim Pingle
05:50 AM Bug #6982 (Feedback): Nested Aliases with FQDNs do not populate parent table in some cases
Applied in changeset commit:631217f488c682ce4ffa8af5d0c54b03c016af46. Renato Botelho
05:49 AM Feature #7051 (Feedback): Allow control of what users can view and/or clear notices
PR has been merged, thanks! Renato Botelho

12/29/2016

08:28 PM Bug #6982 (Assigned): Nested Aliases with FQDNs do not populate parent table in some cases
This fix broke port aliases.
With this commit, port aliases are empty:...
Jim Pingle
08:03 PM Bug #6852: Commit 8f86722 breaks DHCPv6 leases status page
were the files I uploaded any help or is something more needed? Michael Kellogg
08:02 PM Bug #6594: Package reinstallation post-config restore hangs if no Internet connectivity
I'm running into this right now. Not a big network guy, just trying to replace our small business' router with a SG-4... Kevin Wojniak
05:05 PM Bug #6972: "Are you sure you wish to?" prompts and other issues with deleting networks from network-type aliases
I'll take care of it :) Anonymous
04:52 PM Bug #6972: "Are you sure you wish to?" prompts and other issues with deleting networks from network-type aliases
Renato Botelho wrote:
> It happens when you click on fa-trash icon. If you click on other areas of the button confir...
Kill Bill
12:28 PM Bug #6972 (Confirmed): "Are you sure you wish to?" prompts and other issues with deleting networks from network-type aliases
I've found the way to reproduce it. It happens when you click on fa-trash icon. If you click on other areas of the bu... Renato Botelho
04:59 PM Bug #7042 (Feedback): DHCP client configures wrong address in some circumstances (setfirst support missing from ifconfig)
Luiz Souza
03:19 PM Bug #6099: igmpproxy does not recognize upstream interface
Is this commit in the latest build applied? If yes, there seems to be something buggy with the fix.
I just updated m...
Philipp Haefelfinger
01:50 PM Bug #6920 (Feedback): Upgrading to 2.4 with a stale package .inc file can prevent the system from fully booting after upgrade
Applied in changeset commit:fef29f5aee32899b72886f8a0c00205bf0f2fc09. Renato Botelho
01:01 PM Bug #7052 (Rejected): Fails to monitor ipv6 gateway
From log... Roger Skjetlein
12:48 PM Feature #6746 (Feedback): Option to select dark or misc background for Traffic Graphs when a dark theme is selected.
New traffic graphs respect theme colors. Should be OK now Renato Botelho
12:33 PM pfSense Packages Feature #6831: Snort does not support aliases containing FQDN
Keeping it opened for reference but I'm not sure if Bill Meeks will implement it based on his comments on the forum t... Renato Botelho
09:44 AM Feature #6045: Updates that do not require a reboot should run reroot
Jim Pingle wrote:
> Doing a reroot style restart works nicely on its own, need to test it during an upgrade to know ...
Renato Botelho
09:27 AM Feature #6045: Updates that do not require a reboot should run reroot
Doing a reroot style restart works nicely on its own, need to test it during an upgrade to know for sure how it handl... Jim Pingle
08:53 AM Feature #6045 (Feedback): Updates that do not require a reboot should run reroot
Done. pfSense-upgrade 0.11 on recent 2.4.0 system will do the trick Renato Botelho
09:40 AM Bug #7050: Limiter with PFsense 2.4 transparent proxy
Nelson, can you submit (even privately if you prefer) a copy of your working settings for the 2.1.x version and also ... Luiz Souza
07:06 AM Bug #7050: Limiter with PFsense 2.4 transparent proxy
Not sure what's special about 2.4 here; this has _never_ worked since the hidden rules created by the package when se... Kill Bill
06:58 AM Bug #7050 (Resolved): Limiter with PFsense 2.4 transparent proxy
Good morning Luiz, is as follows, transparent proxy use with the limiter by ip, what happens is that when setada the ... Nelson Junior
07:53 AM Todo #7047 (Resolved): Update status.php with new info helpful to support staff
Seems to all be working and sufficient. Can add more later if needed. Jim Pingle
07:53 AM Bug #3454 (Resolved): Acknowledge all notices is presented to users who do not have privilege
Renato Botelho
07:19 AM Bug #3454: Acknowledge all notices is presented to users who do not have privilege
The changes here fix this bug report.
For a followon feature request to implement control of view/clear notices see:...
Phillip Davis
07:53 AM Feature #7046 (Resolved): Bring back a method of viewing the gateway status from the shell and status output
Works great Jim Pingle
07:48 AM Bug #7045 (Resolved): PHP Shell outputs startup message when running a playback script
Fixed Jim Pingle
07:21 AM Feature #7051: Allow control of what users can view and/or clear notices
Proposed code in PR https://github.com/pfsense/pfsense/pull/3322 Phillip Davis
07:16 AM Feature #7051 (Resolved): Allow control of what users can view and/or clear notices
Use case:
A user with minimal page privs (e.g. can just change their password, or access a few status pages or...) s...
Phillip Davis
05:58 AM pfSense Packages Bug #7049 (Rejected): Problema No Limiter Com Proxy Transparente 2.4 Beta
After talk with Nelson on facebook he agreed to open a new ticket in english Renato Botelho

12/28/2016

06:43 PM pfSense Packages Bug #7049 (Rejected): Problema No Limiter Com Proxy Transparente 2.4 Beta
boa noite, estou tendo problemas no limiter funcionando com proxy transparente, nas versões acima da 2.1.5, todas tes... Nelson Junior
01:40 PM pfSense Packages Bug #7048: Add IPv6 support to squid
Squid's own capabilities mean nothing here. You need support in the underlying OS to work with. Even if I made all th... Kill Bill
01:32 PM pfSense Packages Bug #7048: Add IPv6 support to squid
Regarding the comment, "The NAT used for transparent IPv4 proxy won't work, and there's nothing to hook into regardin... Matthew Hall
01:25 PM pfSense Packages Bug #7048: Add IPv6 support to squid
A couple of notes on this: The only part of Squid working with IPv6 is the reverse proxy (though, that's not advertis... Kill Bill
01:11 PM pfSense Packages Bug #7048: Add IPv6 support to squid
Corrected subject - This is not a "bypass" in the way that is stated. The squid package only supports IPv4 currently.... Jim Pingle
01:03 PM pfSense Packages Bug #7048 (Resolved): Add IPv6 support to squid
Missing IPv6 support in the squid package allows traffic to escape intended inspection and apparently also the firewa... Matthew Hall
01:13 PM Feature #7046 (Feedback): Bring back a method of viewing the gateway status from the shell and status output
Last part of this was implemented by #7046 Jim Pingle
12:50 PM Feature #7046 (Resolved): Bring back a method of viewing the gateway status from the shell and status output
Since the switch to dpinger, there is no easy way to view the gateway status from the shell. Having the gateway statu... Jim Pingle
01:10 PM Todo #7047 (Feedback): Update status.php with new info helpful to support staff
Applied in changeset commit:84fe48d414dc59ffd236b072000f07ea7423380e. Jim Pingle
01:02 PM Todo #7047 (Resolved): Update status.php with new info helpful to support staff
Items to add:
* The firewall platform and serial number
* ARP Table
* NDP Table
* Gateway status (See #7046)
* Z...
Jim Pingle
01:10 PM Bug #7045 (Feedback): PHP Shell outputs startup message when running a playback script
Applied in changeset commit:337822a39bfd89c011cfda4092a6e5e409a7dbcf. Jim Pingle
12:49 PM Bug #7045 (Resolved): PHP Shell outputs startup message when running a playback script
When running a playback script, there is extra output from pfSsh.php that is unnecessary:... Jim Pingle
11:34 AM Feature #7044 (Duplicate): Gateway Monitoring - Add More IPs
Jim Pingle
11:18 AM Feature #7044: Gateway Monitoring - Add More IPs
See #6989 Kill Bill
10:31 AM Feature #7044 (Duplicate): Gateway Monitoring - Add More IPs
I would like to request that it be possible to add more than one ip to monitor the gateway (s), today we have the pos... Douglas Silva
09:40 AM Bug #3454 (Feedback): Acknowledge all notices is presented to users who do not have privilege
Applied in changeset commit:fe80b3aac6ddd661c7a2daf52ad54f1722915590. Phillip Davis
12:45 AM Bug #3454: Acknowledge all notices is presented to users who do not have privilege
Bug fix PR https://github.com/pfsense/pfsense/pull/3319
I will raise another feature issue to discuss what could b...
Phillip Davis
09:30 AM Bug #7043 (Feedback): If user does not have crash_reporter page access the crash reported link is useless
Applied in changeset commit:c87eeb08acc6d5d0fd642e50990b93b7137657ee. Phillip Davis
02:00 AM Bug #7043: If user does not have crash_reporter page access the crash reported link is useless
PR https://github.com/pfsense/pfsense/pull/3321 Phillip Davis
01:59 AM Bug #7043 (Resolved): If user does not have crash_reporter page access the crash reported link is useless
When the user clicks "here" for more information, nothing happens, because they do not have carsh_reporter page acces... Phillip Davis
07:58 AM pfSense Packages Bug #7028: Squid - all javascript broken by bootstrap conversion
Steve Beaver wrote:
> Right. It is not "A new bug", it is the original bug that has just been fixed.
https://gith...
Luiz Gustavo S. Costa
07:56 AM pfSense Packages Bug #7028: Squid - all javascript broken by bootstrap conversion
Right. It is not "A new bug", it is the original bug that has just been fixed. Anonymous
07:49 AM pfSense Packages Bug #7028: Squid - all javascript broken by bootstrap conversion
None of those fixes are in 2.3.2 so it's just pointless to test anything there. Kill Bill
07:36 AM pfSense Packages Bug #7028: Squid - all javascript broken by bootstrap conversion
A new bug is revelead, see:
!http://i.imgur.com/U6Ggy4d.png!
The syntax is duplicated.
New installation from...
Luiz Gustavo S. Costa
05:22 AM Bug #6982 (Resolved): Nested Aliases with FQDNs do not populate parent table in some cases
Renato Botelho

12/27/2016

07:39 PM Bug #6982: Nested Aliases with FQDNs do not populate parent table in some cases
This is working well for me with changeset applied using system patches on 2.3.2_1 that I was using in my initial tes... Chris Linstruth
01:30 PM Bug #6982 (Feedback): Nested Aliases with FQDNs do not populate parent table in some cases
Applied in changeset commit:5d1cf6f5cf85c6371078e288172da1e05df1380c. Renato Botelho
06:21 PM pfSense Packages Bug #6527: Squid 3.5 - Deprecated "ssl_bump server-first all" don't allow SNI in transparent mode with HTTPS/SSL Interception
https://github.com/pfsense/FreeBSD-ports/pull/242
Kindly test and report back either here, and/or @ https://forum....
Kill Bill
03:44 PM Bug #7042: DHCP client configures wrong address in some circumstances (setfirst support missing from ifconfig)
Simplest way to reproduce this is to use a DNS Resolver override for "setfirst" and the firewall's domain, set to an ... Jim Pingle
03:31 PM Bug #7042 (Resolved): DHCP client configures wrong address in some circumstances (setfirst support missing from ifconfig)
In certain circumstances a DHCP client interface gets configured with an incorrect address. The address that should b... Jim Pingle
02:47 PM pfSense Packages Bug #7017 (Resolved): Squid NT Domain authentication is broken
Renato Botelho
02:19 PM pfSense Packages Bug #7017: Squid NT Domain authentication is broken
Broken feature gone -> can be closed. Thanks. Kill Bill
06:35 AM pfSense Packages Bug #7017 (Feedback): Squid NT Domain authentication is broken
PR has been merged, thanks! Renato Botelho
01:35 PM Bug #3560 (Feedback): Disabled Static Route not fully disabled
PR has been merged, thanks! Renato Botelho
06:04 AM Bug #3560: Disabled Static Route not fully disabled
See PR https://github.com/pfsense/pfsense/pull/3312 Phillip Davis
10:13 AM Feature #3151 (Resolved): Disable gateway monitoring actions without disabling gateway monitoring
Works here, too. Gateway status shows it going up/down but no actions are taken when it transitions. Jim Pingle
01:52 AM Feature #3151: Disable gateway monitoring actions without disabling gateway monitoring
Been working for me, but it would be good to get some feedback from anyone else who has tried/tested this. Phillip Davis
06:36 AM pfSense Packages Feature #6593 (Feedback): squid: allow user to configure DH key size, SINGLE_DH_USE, NO-SSLv3, Cipher-Suites - performance improvement hint
PR has been merged, thanks! Renato Botelho
06:36 AM pfSense Packages Bug #6592 (Feedback): squid does NOT use EDH and EECDH cipher suites because "tls-dh" is not configured and so these ciphers are silently dropped - see squid documentation
PR has been merged, thanks! Renato Botelho
 

Also available in: Atom