Project

General

Profile

Activity

From 03/09/2017 to 04/07/2017

04/07/2017

08:03 PM pfSense Packages Bug #6603: pfblockerng's Unbound modifications leave system broken post-config restore
maybe now I can only solve the ramfs related problem by completely backup /var and restore it on boot up, maybe with ... giskard rt
07:48 PM pfSense Packages Bug #7454: bridge is up after reboot while the enable interface box is not checked
Kill Bill wrote:
> giskard rt wrote:
> > I uncheck the enable box in the interface configuration tab, it works for ...
giskard rt
07:27 AM pfSense Packages Bug #7454 (Rejected): bridge is up after reboot while the enable interface box is not checked
Interfaces exist at the OS level even when they are not enabled. The GUI only controls settings applied to the interf... Jim Pingle
02:35 AM pfSense Packages Bug #7454: bridge is up after reboot while the enable interface box is not checked
giskard rt wrote:
> I uncheck the enable box in the interface configuration tab, it works for the change. however wh...
Kill Bill
01:28 AM pfSense Packages Bug #7454: bridge is up after reboot while the enable interface box is not checked
the similar problem also exist with some other add-ons, like:
1,squid, though it's not enabled, it generate a lot or...
giskard rt
12:52 AM pfSense Packages Bug #7454 (Rejected): bridge is up after reboot while the enable interface box is not checked
as described, I add an bridge to bind two different interface, but I do not want the bridge be brought up, so I unche... giskard rt
07:11 PM pfSense Packages Feature #7456: pfblockerNG add supportto add or modify self-modified easylist style rule
Kill Bill wrote:
> No idea what's this request about. If you are talking about the DNSBL feature, the "easylist styl...
giskard rt
07:29 AM pfSense Packages Feature #7456 (Rejected): pfblockerNG add supportto add or modify self-modified easylist style rule
Please post on the forum to discuss and confirm problems before opening issues here on Redmine. Jim Pingle
02:10 AM pfSense Packages Feature #7456: pfblockerNG add supportto add or modify self-modified easylist style rule
No idea what's this request about. If you are talking about the DNSBL feature, the "easylist style rule" support is a... Kill Bill
01:37 AM pfSense Packages Feature #7456 (Rejected): pfblockerNG add supportto add or modify self-modified easylist style rule
easylist rule is so convinient and the specific language variant rules cover almost all I need,
But pfblockerNG seem...
giskard rt
02:25 PM Feature #2456: Option to choose default tab in IPsec status Dashboard widget
I would also like to see this enhancement Chris Baker
09:32 AM Bug #7448 (Resolved): XMLRPC Sync failure notice is ugly/long exception from cURL rather than our usual custom message
This looks much better now. Failures have a short and meaningful error message instead of a stack trace. Jim Pingle
09:23 AM Bug #7424 (Resolved): status_carp.php: Reset Demotion Status button does not appear when the demotion value is negative
Button shows as expected now, and works properly. Jim Pingle
09:12 AM Bug #7145 (Resolved): rc.newwanipv6 running in all cases, even for a renew
This seems to behave much better now. On a DHCPv6 VM, before these changes I had a never-ending stream of rc.newwanip... Jim Pingle
09:06 AM pfSense Packages Bug #7341 (Resolved): New certificates fail with nsupdate on the first try
Jim Pingle
09:04 AM Bug #7401 (Resolved): custom_php_deinstall_command isn't being run during pkg post-deinstall because info.xml has already been removed by that step.
Jim Pingle
09:02 AM pfSense Packages Bug #7390 (Resolved): SquidGuard
Jim Pingle
07:30 AM Bug #7458 (Rejected): web interface very slow
Please post on the forum to discuss and confirm problems before opening issues here on Redmine. Jim Pingle
07:28 AM Bug #7458 (Rejected): web interface very slow
web interface very long open any menu item, if one gateway in gateway group is down or high loss
Ivan Pavlov
07:28 AM pfSense Packages Bug #7455 (Duplicate): Unbound DNS Resolver failed with pfBlockerNG after reboot with /var mounted on ramfs
Jim Pingle
02:21 AM pfSense Packages Bug #7455: Unbound DNS Resolver failed with pfBlockerNG after reboot with /var mounted on ramfs
Duplicate of Bug #6603 Kill Bill
01:14 AM pfSense Packages Bug #7455 (Duplicate): Unbound DNS Resolver failed with pfBlockerNG after reboot with /var mounted on ramfs
I'd like to say, the var on ramfs is very useful, but the way to handle it is not well considered to back up the var ... giskard rt
07:28 AM pfSense Packages Bug #7457 (Rejected): snort use too much resource
Please post on the forum to discuss and confirm problems before opening issues here on Redmine. This is not a bug. Jim Pingle
02:14 AM pfSense Packages Bug #7457: snort use too much resource
This is a bug tracker, please use https://forum.pfsense.org/index.php?board=61.0 for performance tuning tips. The mem... Kill Bill
01:48 AM pfSense Packages Bug #7457 (Rejected): snort use too much resource
first of all, As official wiki said, pfsense has removed layer7 packets filter feature after version 2.3 for the poor... giskard rt

04/06/2017

09:13 PM Bug #7413: status_dhcpv6_leases.php: Some DHCPv6 leases are not displayed in the GUI
Yeah, my DHCPv6 status page is only showing one lease, which happens to be a static reservation. None of the rest of ... Anonymous
10:54 AM pfSense Packages Bug #7453 (Closed): DNS-ovh need to save or display consumer key
Consumer key is generated at the first connection to OVH ([Thu Apr 6 17:46:00 CEST 2017] OVH consumer key is empty, L... Cédric Caron
07:50 AM Bug #7452 (Feedback): Adding a gateway from interfaces.php does not work
Applied in changeset commit:f3278171b199062279225631903685e608285d3a. Phillip Davis
06:55 AM Bug #7452: Adding a gateway from interfaces.php does not work
PR https://github.com/pfsense/pfsense/pull/3689 Phillip Davis
06:54 AM Bug #7452 (Resolved): Adding a gateway from interfaces.php does not work
After pressing the Add button, actually the new gateway is not created.
It uses AJAX to system_gateways_edit but the...
Phillip Davis

04/05/2017

09:11 PM Bug #7451 (Resolved): vpn_openvpn_client.php - Fields not hidden/processed correctly in chrome
In Chrome (Version 57.0.2987.133 (64-bit) Mac tested) when you edit an OpenVPN Client and switch to shared-key mode, ... Chris Linstruth
11:31 AM Bug #7450: Virtual IP replication before "applying" config
Jim Pingle wrote:
> That is expected. "Apply changes" only affects the host you are configuring. Changes are applied...
Pierre Blanes
11:27 AM Bug #7450 (Rejected): Virtual IP replication before "applying" config
That is expected. "Apply changes" only affects the host you are configuring. Changes are applied on sync to the secon... Jim Pingle
11:25 AM Bug #7450 (Rejected): Virtual IP replication before "applying" config
Hi;
the setup to reproduce is easy this is a HA cluster as described here : https://doc.pfsense.org/index.php/C...
Pierre Blanes
10:17 AM pfSense Packages Feature #7449 (New): feature request for openvpn-client-export package, add the support for openvpn up and down script, for mapping network drive
Hi,
hope i write this to the right place. Someone on the IRC suggested me to post my idea here.
Here is the off...
Geco-it Staff
09:51 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
The underlying program, rate, still doesn't work with IPv6 as far as I'm aware.
I'd love to see rate swapped out f...
Jim Pingle
09:31 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
When will this be resolved? This is a really old bug. Pim Pish
08:23 AM pfSense Packages Bug #7247 (Closed): Update net/ntopng to 2.4.2017.01.20
We just moved to the new quarterly ports branch so there are a number of updates to various things there now or comin... Jim Pingle
08:17 AM pfSense Packages Bug #7247: Update net/ntopng to 2.4.2017.01.20
... Kill Bill

04/04/2017

10:19 PM pfSense Packages Bug #7437: Mail Report package 3.1 removed support for STARTTLS
I just spent some time, installed pfSense 2.4 in Hyper-V and tested.
Yes, there is no STARTTLS setting anymore, wh...
Dmitry Gromov
02:55 PM Bug #7295 (Feedback): RFC2136 not updating at boot time
Can you please try it again on recent snapshots? There were fixes in this area and I couldn't reproduce it at home wh... Renato Botelho
02:00 PM Bug #7448 (Feedback): XMLRPC Sync failure notice is ugly/long exception from cURL rather than our usual custom message
Applied in changeset commit:593f052172b0969dfe9e9db755a9a41200e67ab1. Jim Pingle
01:47 PM Bug #7448: XMLRPC Sync failure notice is ugly/long exception from cURL rather than our usual custom message
To me, I have a patch. Jim Pingle
12:45 PM Bug #7448 (Resolved): XMLRPC Sync failure notice is ugly/long exception from cURL rather than our usual custom message
On 2.4, if an XMLRPC sync attempt fails, a notice is displayed by the firewall but it contains a cURL exception error... Jim Pingle
12:42 PM Bug #7015 (Assigned): IPsec not working behind NAT
Jim Pingle
12:40 PM Bug #7015: IPsec not working behind NAT
I’m testing routing all IPv4 and IPv6 LAN traffic through a remote VPN server and am having issues with IPv6 that mig... David Myers
11:19 AM Bug #7447: SquidGuard not filtered in Transparent Proxy mode
That is a different problem as it involves remote parent proxies. It already has a ticket. If that is your problem, t... Jim Pingle
11:16 AM Bug #7447: SquidGuard not filtered in Transparent Proxy mode
Good morning,
It does not seem to me that it's just
[[https://forum.pfsense.org/index.php?topic=128019.0]]
[[http...
Claudio Berselli
09:48 AM Bug #7447 (Rejected): SquidGuard not filtered in Transparent Proxy mode
Please post on the forum for diagnosis and discussion. The current version works for others, there is not a general p... Jim Pingle
09:45 AM Bug #7447 (Rejected): SquidGuard not filtered in Transparent Proxy mode
Good morning,
I realized that after a last update SquidGuard not filtered.
For safety, I made a clean machine and i...
Claudio Berselli
07:15 AM Bug #4669 (Feedback): QinQ virtual interfaces available for assignment where they shouldn't be
Jim Pingle
05:48 AM Bug #4669: QinQ virtual interfaces available for assignment where they shouldn't be
Merged, please test with latest 2.3.4/2.4 snapshot. Kill Bill
07:14 AM Bug #3710 (Feedback): Adding static DHCP leases doesn't cause BIND zones to update
Jim Pingle
05:52 AM Bug #3710: Adding static DHCP leases doesn't cause BIND zones to update
Merged, please test with latest 2.4 snapshot. Kill Bill
04:56 AM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
I don't know how tracert exactly works, but when using tracert it is resolving the "wrong" subdomain to the right one... xander bron

04/03/2017

02:12 PM pfSense Packages Bug #7438: Squid 0.4.36_2 Remote Cache Parent not working
@OP: Need some feedback here. Kill Bill
11:27 AM Bug #7116: a floating 'match' rule on LAN does not put traffic from a broswer on a clientpc into a shaper queue
Pass makes it work but of course it will also circumvent filtering on the firewall.
To make it work "and" not circum...
Chris Collins
10:23 AM Bug #7443: Issues Creating IPv6 Static Mappings
This issue is with the 2.4 beta. Daryl Morse
10:10 AM Bug #7178 (Closed): pfSense themes don't handle package XML field without <description> tag properly
Anonymous
10:10 AM Bug #7154 (Resolved): firewall_nat_edit JS function check_for_aliases()
Anonymous
10:00 AM Bug #7446 (Feedback): RFC2136 Dynamic DNS needs local directive so updates are sourced correctly
Applied in changeset commit:1bf69a00b9f6c1b8e98ed6dc4c78c8cb8403dc68. Anonymous
09:51 AM pfSense Packages Bug #7341 (Feedback): New certificates fail with nsupdate on the first try
Fixed by commit:45b4a966b4b0db69d32c697f683aef94e15f56a6
https://github.com/pfsense/FreeBSD-ports/commit/45b4a966b4b...
Jim Pingle
09:50 AM Bug #7445: pfSenseHelpers.js service naming restrictions plus lack of error handling
Applied in changeset commit:21a8edd7836baf1e4ee2f347fdc1bafb4d96c9d9. Anonymous
09:42 AM Bug #7445 (Feedback): pfSenseHelpers.js service naming restrictions plus lack of error handling
Now properly handles service names that contain hyphens Anonymous
09:44 AM Bug #7444 (Feedback): pfSenseHelpers.js typo breaks captive portal stop/start/restart
Fixed via PR 3687 Anonymous
08:29 AM Bug #7075 (Resolved): firewall states show negative value for total bytes processed
Jim Pingle
08:29 AM Bug #7231 (Resolved): Web UI does not properly remove priq shaping rules when deleting an interface which causes subsequent rule failures without warning in the UI
Jim Pingle
08:28 AM Bug #7254 (Resolved): Selection from long tab list that uses dropdown does not POST correctly
Jim Pingle
08:28 AM Bug #7316 (Resolved): Fail Boostrap format port in
Jim Pingle
08:27 AM Bug #7422 (Resolved): Typo in OpenVPN NCP description
Jim Pingle
08:26 AM Bug #7435 (Resolved): Cannot edit IP address in a host override
Jim Pingle
01:14 AM Feature #7441: Display start/end times for Static Mapping leases on DHCP Leases/DHCPv6 Leases
Add release and renew to actions. Daryl Morse

04/02/2017

06:15 PM Bug #7446: RFC2136 Dynamic DNS needs local directive so updates are sourced correctly
https://github.com/pfsense/pfsense/pull/3688 Chris Linstruth
03:53 PM Bug #7446 (Resolved): RFC2136 Dynamic DNS needs local directive so updates are sourced correctly
RFC2136 nsupdatecmds0 lacks the local directive so updates from other than the WAN with the default gateway fail.
Chris Linstruth
08:46 AM Bug #7445 (Resolved): pfSenseHelpers.js service naming restrictions plus lack of error handling
Code in pfSenseHelpers.js [1] introduced probably in this commit [2]
[1] https://github.com/pfsense/pfsense/blob/ma...
Kill Bill
02:46 AM Bug #7444 (Resolved): pfSenseHelpers.js typo breaks captive portal stop/start/restart
https://github.com/pfsense/pfsense/pull/3687 Kill Bill

04/01/2017

11:27 PM Bug #6340: fsck hangs boot in background, fails to produce any action, resulting in broken firewall
After power cycling an appliance running 2.4.0.b.20170401.1306 with UFS FS for over an hour, dozens of fsck's were tr... Anonymous
11:23 PM Bug #7443 (Resolved): Issues Creating IPv6 Static Mappings
There are a few issues creating IPv6 static mappings.
When entering the address for IPv4 static mapping, the entir...
Daryl Morse
09:36 PM Bug #6594: Package reinstallation post-config restore hangs if no Internet connectivity
On 2.4.0.b.20170401.1306, when a backup from 2.4.0.b.20170328.1156 is restored with no WAN connectivity the attached ... Anonymous
08:14 PM Bug #7075: firewall states show negative value for total bytes processed
Can not duplicate this behavior in 2.4.0.b.20170401.1306, only positive numbers in the States column Anonymous
08:01 PM Bug #7231: Web UI does not properly remove priq shaping rules when deleting an interface which causes subsequent rule failures without warning in the UI
On 2.4.0.b.20170401.1306, when attempting to delete an interface with traffic shaping configured, there is a warning ... Anonymous
07:52 PM Bug #7254: Selection from long tab list that uses dropdown does not POST correctly
Could not reproduce this on 2.4.0.b.20170401.1306 with twelve interfaces configured Anonymous
07:41 PM Bug #7316: Fail Boostrap format port in
On 2.4.0.b.20170401.1306 when editing a port alias, hovering over the Port field shows 'A port number, port number ra... Anonymous
07:37 PM Bug #7422: Typo in OpenVPN NCP description
Today's latest snapshot 2.4.0.b.20170401.1306 also does not have the 'z'. Anonymous
07:33 PM Bug #7435: Cannot edit IP address in a host override
I am not able to reproduce this in DNS Resolver (unbound) on 2.4.0.b.20170401.1306. Anonymous
06:21 PM pfSense Packages Bug #7440: Tinc package WEB GUI not picking up changes made on filesystem
Ok. Thank you. I can understand it would be difficult to write a parser for these config files, especially since they... Stephen Walker-Weinshenker
06:19 PM pfSense Packages Bug #7440: Tinc package WEB GUI not picking up changes made on filesystem
Put the settings in the GUI. That's how every part of pfSense works. Manual changes to files will always be overwritt... Jim Pingle
06:16 PM pfSense Packages Bug #7440: Tinc package WEB GUI not picking up changes made on filesystem
I understand that this is not the approved way to do things, but now that I have done it, is there any way to get the... Stephen Walker-Weinshenker
06:12 PM pfSense Packages Bug #7440 (Rejected): Tinc package WEB GUI not picking up changes made on filesystem
That's not how it's meant to work. All settings must go into the GUI, and the filesystem contents are written out fro... Jim Pingle
05:51 PM pfSense Packages Bug #7440 (Rejected): Tinc package WEB GUI not picking up changes made on filesystem
I have been setting up a tinc VPN using a pfsense firewall/router as one of the nodes and everything is working fine,... Stephen Walker-Weinshenker
06:05 PM Feature #7442 (New): Suggestions for Diagnostics / ARP Table and Diagnostics / NDP Table
Add status to NDP Table.
Add delete to NDP Table.
Add ping to ARP Table and NDP Table.
Add selection box so ...
Daryl Morse
06:05 PM Feature #7441 (New): Display start/end times for Static Mapping leases on DHCP Leases/DHCPv6 Leases
Display start and end for static leases. (Even if address is reserved, it's useful to know the status.)
Add ping t...
Daryl Morse
02:29 PM pfSense Packages Feature #6651: Loopback interfaces
+1 for this request. The ability is there as Chris mentioned, but IPs can only be bound to lo0. Additionally, an opti... Anonymous

03/31/2017

01:01 PM Bug #7439 (Closed): IKE_SA (IKEv2) does not rekey on break before make startegy, just issues IKE_DELETE and connection is closed
h1. 2.4.0-BETA-amd64-20170228-0411
Both MSW 10 and macOS 10.12 does not rekey IKE_SA on _break-before-make_ starte...
Reinis Adovics
11:02 AM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
I'm also experiencing this bug with 2.3.3-RELEASE (amd64) using Unbound and no BIND. LAN (renamed "LAN1") serves regu... Hannes van Vuuren
07:51 AM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
With Unbound and the newest release of pfSense ATM (2.3.3-RELEASE-p1 (amd64)) it isn't working for one of four interf... xander bron
08:14 AM pfSense Packages Bug #7437: Mail Report package 3.1 removed support for STARTTLS
Is it possible delete or replace attachment here?
Seems like I can edit message, but not delete or replace attached ...
Dmitry Gromov
07:52 AM pfSense Packages Bug #7437: Mail Report package 3.1 removed support for STARTTLS
Of course, I tested it - see attached screenshot, in this case notifications cease to works as well as reports.
On...
Dmitry Gromov
05:56 AM pfSense Packages Bug #7437: Mail Report package 3.1 removed support for STARTTLS
I'm telling you what to tick so that you have the mail reports working with STARTTLS without any changes needed in th... Kill Bill

03/30/2017

09:53 AM pfSense Packages Bug #7437: Mail Report package 3.1 removed support for STARTTLS
Hi!
It looks like you do not understand the difference between SMTPS and STARTTLS.
If I check "Enable SMTP over...
Dmitry Gromov
06:46 AM pfSense Packages Bug #7437: Mail Report package 3.1 removed support for STARTTLS
It works just fine on 2.3.3 when you tick the checkbox that you stubbornly refuse to tick for god knows what reason. ... Kill Bill
06:04 AM pfSense Packages Bug #7437: Mail Report package 3.1 removed support for STARTTLS
I am glad it works for you in 2.4, but last I checked 2.3.3-RELEASE-p1 is the current release and it does NOT work th... Dmitry Gromov
03:10 AM pfSense Packages Bug #7437: Mail Report package 3.1 removed support for STARTTLS
I must be speaking Chinese. Tick the "Enable SMTP over SSL/TLS" and it will work. Simple. (The "Enable STARTTLS" thin... Kill Bill

03/29/2017

07:14 PM pfSense Packages Bug #7437: Mail Report package 3.1 removed support for STARTTLS
Are we looking at different codebases?
There are two checkboxes on /usr/local/www/system_advanced_notifications.ph...
Dmitry Gromov
06:35 PM pfSense Packages Bug #7437: Mail Report package 3.1 removed support for STARTTLS
Dmitry Gromov wrote:
> And that is _exactly_ what version 3.1 does - it disables handling of STARTTLS if STARTTLS ch...
Kill Bill
06:13 PM pfSense Packages Bug #7437: Mail Report package 3.1 removed support for STARTTLS
Hi!
Well, that is kind of strange way to treat the issue, let's not jump to conclusions that fast.
I had a bit ...
Dmitry Gromov
07:37 AM pfSense Packages Bug #7437 (Rejected): Mail Report package 3.1 removed support for STARTTLS
It was changed because phpmailer changed. It detects STARTTLS support automatically. If it can't, then the server isn... Jim Pingle
04:49 AM pfSense Packages Bug #7437: Mail Report package 3.1 removed support for STARTTLS
It was not removed, it's supposed to be used automatically when you tick SSL and the mailserver is advertising STARTT... Kill Bill
01:17 AM pfSense Packages Bug #7437 (Rejected): Mail Report package 3.1 removed support for STARTTLS
I had pfSense configured to send mail reports via FastMail on port 587 with STARTTLS.
All worked great until recent ...
Dmitry Gromov
03:38 PM pfSense Packages Bug #7438: Squid 0.4.36_2 Remote Cache Parent not working
Test this: https://github.com/doktornotor/FreeBSD-ports/commit/d2d68063934e1474571e4ef3e0dfb713835b9b22.patch Kill Bill
02:16 PM pfSense Packages Bug #7438 (Closed): Squid 0.4.36_2 Remote Cache Parent not working
We had transparent mode proxy working with a Remote Cache parent working on 0.4.36
When we upgraded to 0.4.36_2 it...
Robert Siegman
08:00 AM Bug #7425: dhclient not sending option 77
I have issued a PR on this: pfsense/FreeBSD-src - Option 77 Additions to dhclient #8 Martin Wasley
07:06 AM Bug #7345 (Feedback): nanobsd upgrades still fail bacause of lacking resolv.conf
PR has been merged, thanks! Renato Botelho

03/28/2017

08:13 PM Bug #7412: rtsold will not run on VLAN interfaces
Ok, understood. Thanks for the explanation, I appreciate it. I'll lay low for a season and see how it goes. mike cross
08:11 PM Bug #7412: rtsold will not run on VLAN interfaces
No, there is no default gateway because rtsold won't run. DHCPv6 on its own does not handle gateways. It's the same r... Jim Pingle
08:10 PM Bug #7412: rtsold will not run on VLAN interfaces
Jim Pingle wrote:
> A VLAN interface for a WAN will not pull an IPv6 address via DHCPv6 with a default configuration...
mike cross
08:06 PM Bug #7436 (Duplicate): SG-1000 not installing default gateway on VLAN WAN interface
Duplicate of #7412 Jim Pingle
08:04 PM Bug #7436 (Duplicate): SG-1000 not installing default gateway on VLAN WAN interface
I have an SG-1000 with 2.4.0.b.20170328.1156 installed. Comcast residential IPv6, DHCPv6 on the WAN interface gets a... mike cross
08:13 AM Bug #7435 (Feedback): Cannot edit IP address in a host override
Looks good. I managed to reproduce this late yesterday but left myself a note to check on it this morning again with ... Jim Pingle
05:26 AM Bug #7435: Cannot edit IP address in a host override
PR with more stuff and a slightly different way to fix:
https://github.com/pfsense/pfsense/pull/3679
And this bug...
Phillip Davis
03:07 AM Bug #7435: Cannot edit IP address in a host override
PR https://github.com/pfsense/pfsense/pull/3678 Phillip Davis
07:31 AM Bug #7428 (Resolved): Rule with empty port alias causes error loading rules
Thanks! Jim Pingle

03/27/2017

11:28 PM Bug #7435 (Resolved): Cannot edit IP address in a host override
Forum: https://forum.pfsense.org/index.php?topic=127835.0
In either of DNS Forwarder or Resolver:
a) Add some hos...
Phillip Davis
10:45 PM Bug #7428: Rule with empty port alias causes error loading rules
Tested on latest 2.4-BETA and 2.3.4-DEVELOPMENT and this is fixed. Using an empty port alias in a rule causes the rul... Phillip Davis
08:35 PM Bug #7428: Rule with empty port alias causes error loading rules
PRs merged:
https://github.com/pfsense/pfsense/pull/3670 - code needed for fix
https://github.com/pfsense/pfsense/p...
Phillip Davis
08:29 AM Bug #7428: Rule with empty port alias causes error loading rules
The fix looks OK to me and the PR fixes the problem, I just want to get at least one more person here to look it over... Jim Pingle
12:20 PM Bug #7434 (Feedback): Traffic shaper wizard: SMB choice uses invalid destination port range
Applied in changeset commit:02c3646f36f84bfe1a65c54c38a05e100e8abd44. Jim Pingle
12:12 PM Bug #7434: Traffic shaper wizard: SMB choice uses invalid destination port range
I pushed a fix, but now I'm wondering if we might want some upgrade code to fix the existing broken rules. Since it w... Jim Pingle
12:05 PM Bug #7434 (Resolved): Traffic shaper wizard: SMB choice uses invalid destination port range
The ports for SMB used by the traffic shaper are defined in /etc/inc/wizardapp.inc, and they are defined incorrectly.... Jim Pingle
09:45 AM Bug #7326: Unbound fails to start during rc.wanipchange when using large enough dns lists
Can the devs chime in on this issue please?
Are there other functions in the code that also need to be patched to ...
BBcan177 .
09:27 AM pfSense Packages Bug #7431: BIND (9.11-2) Log shortcut needs to be updated.
Updated to correct Repo (Hpefully) https://github.com/pfsense/FreeBSD-ports/pull/335 Marc Riley
07:37 AM Bug #6957: CARP arp reply with wrong src mac
This also seems to have a negative effect on switches the pfSense gateway is not directly connected to. I.e. pfSense ... Anonymous
07:28 AM Bug #7415: favicon is not correctly implemented
As my humble contribution to the work of this team, i added all other formats in the existing favicon.ico file. Enjoy. Leon Straathof
07:19 AM Bug #6991 (Resolved): IPv6 traffic hitting a rule with policy routing and NPt fails/disappears
Looks OK. Traffic hitting rules that failed before the first fix works OK still. Jim Pingle
07:11 AM Bug #7421: Unresolvable port alias is omitted from rule rather than generating an error
I'll close this out and check out the other ticket/PR shortly. Thanks! Jim Pingle
07:06 AM Bug #7433: led and sw bouton do not work in APU2
See the other ticket, this one is a duplicate. Jim Pingle
06:50 AM Bug #7433: led and sw bouton do not work in APU2
hello JIM, Thank you but how I add this fix in pfsense 2.3.3 nanoBSD Anthony hesnaux
06:35 AM Bug #7433 (Duplicate): led and sw bouton do not work in APU2
Jim Pingle
05:39 AM Bug #7433: led and sw bouton do not work in APU2
You already filed this as #7432
Anthony hesnaux wrote:
> Can you help me
Not here. Use https://forum.pfsense.o...
Kill Bill
04:19 AM Bug #7433 (Duplicate): led and sw bouton do not work in APU2
Hello ALL,
I test to install pfsense(2.3.X) in APU2
but I find a problem with led in front and switch reset bouton....
Anthony hesnaux
06:36 AM Feature #7432 (Needs Patch): Add drivers for led and sw bouton APU2
When FreeBSD adds the drivers, we will get them naturally from upstream. Jim Pingle
01:24 AM Feature #7432 (Needs Patch): Add drivers for led and sw bouton APU2
Hello ALl,
I test to install pfsense(2.3.X) in APU2
but I find a problem with led in front and switch reset bouton....
Anthony hesnaux
01:31 AM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
I am having this same exact issue. Has there been any traction on this? Lynn Dixon

03/26/2017

12:01 PM pfSense Packages Bug #7431: BIND (9.11-2) Log shortcut needs to be updated.
You have submitted this against completely wrong abandoned repo. Any fixes need to go to https://github.com/pfsense/F... Kill Bill
11:04 AM pfSense Packages Bug #7431 (Resolved): BIND (9.11-2) Log shortcut needs to be updated.
The Shortcut to the BIND Logs (on page /pkg_edit.php?xml=bind.xml) currently points to /diag_logs_resolver.php
...
Marc Riley
07:28 AM Bug #7430 (New): pfsense-utils.inc - where_is_ipaddr_configured() should account for loopback interface
At least with @$check_localip = true@, this function should IMNSHO return the lo0 interface when you pass @127.0.0.1@... Kill Bill
06:01 AM Bug #7429: DHCP service error greater than 10 on shared network
This has nothing to do with 10 leases or licensing. Your problem is "Interface igb0 matches multiple shared networks"... Kill Bill
05:44 AM Bug #7429 (Rejected): DHCP service error greater than 10 on shared network
Getting this message:
rc.bootup: The command '/usr/local/sbin/dhcpd -user dhcpd -group _dhcp -chroot /var/dhcpd -cf ...
Brandon Gerber
04:08 AM Bug #7421: Unresolvable port alias is omitted from rule rather than generating an error
Changed code works also, and better - it allows port ranges through :)
While testing, I also entered an empty alia...
Phillip Davis
03:30 AM Bug #7428: Rule with empty port alias causes error loading rules
PR https://github.com/pfsense/pfsense/pull/3670 Phillip Davis
03:20 AM Bug #7428 (Resolved): Rule with empty port alias causes error loading rules
1) Create a port alias, but do not enter any ports in it (leave it empty)
2) Add a rule that uses that port alias
3...
Phillip Davis

03/25/2017

11:41 PM Bug #7303: ipv6 connectivity lost on pfSense reboot
i can confirm this problem on 2.4 tired to bring up 3rd tunnel and couldn't but did find this happing too Michael Kellogg
05:44 PM Bug #7427 (Rejected): Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 127846801 bytes) in /usr/local/www/crash_reporter.php on line 142
^ What they said. Discuss on the forum, if there is a bug we can open a more specific ticket with detail. Jim Pingle
09:18 AM Bug #7427: Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 127846801 bytes) in /usr/local/www/crash_reporter.php on line 142
Post on the forum for help. Then later if there is some bug or good change to make to the software it can be opened a... Phillip Davis
06:57 AM Bug #7427: Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 127846801 bytes) in /usr/local/www/crash_reporter.php on line 142
Brother Jonathan wrote:
> The system is currently working fine but it's still bugging me.
It's hardly working fin...
Kill Bill
02:11 AM Bug #7427 (Rejected): Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 127846801 bytes) in /usr/local/www/crash_reporter.php on line 142
Good Day
Im new on the pfsense
Everything is work fine until i see this error.
The system is currently working ...
Brother Jonathan

03/24/2017

09:33 PM Feature #5851: Add copy action to OpenVPN client / server
+1 Jeremy Nelson
04:52 PM Bug #6991 (Feedback): IPv6 traffic hitting a rule with policy routing and NPt fails/disappears
Our initial fix was reverted in favour of the upstream fix. This need to be tested again. Luiz Souza
04:49 PM Bug #7426 (Resolved): UDP packet drops
When doing an iperf test outside of pfsense there is a strange packet loss at the start of the test.
UDP packets d...
Chris Macmahon
01:03 PM Bug #7421: Unresolvable port alias is omitted from rule rather than generating an error
There was a problem with this code and validating port ranges. I pushed another fix that should cover that case as well. Jim Pingle
07:11 AM Bug #7421 (Resolved): Unresolvable port alias is omitted from rule rather than generating an error
Great, thanks for testing! Jim Pingle
10:50 AM Bug #7424 (Feedback): status_carp.php: Reset Demotion Status button does not appear when the demotion value is negative
Applied in changeset commit:52a3580a200c9f37f33c2985852e68fc65f3266a. Jim Pingle
10:22 AM Bug #7424 (Resolved): status_carp.php: Reset Demotion Status button does not appear when the demotion value is negative
In some cases, through manual user intervention, the value of net.inet.carp.demotion can be negative. The GUI shows a... Jim Pingle
10:41 AM Bug #7425 (Resolved): dhclient not sending option 77
Not sure it's a bug, more of something missing. As reported on the forum 2.4 dhclient does not send option 77. This p... Martin Wasley
09:46 AM Bug #7174 (Duplicate): OpenVPN Server and Client not detecting Hardware Cryto
The only issue here is actually a duplicate of #5976 - closing. Jim Pingle
09:32 AM Feature #7383 (Closed): system_certmanager.php?act=new: Add new select option to sign a CSR
Anonymous
09:28 AM Feature #7383: system_certmanager.php?act=new: Add new select option to sign a CSR
Build 2.4.0.b.20170323.1221
I was able to create a signing request and sign it via the UI.
The CSR remained in ...
James Snell
08:46 AM Feature #4606: PKI : CA signing external CSR
i see now, there might be another problem.
currently pfsense cannot handle certificates w/o a private key - so the...
Tech Synedra
08:42 AM Bug #7423: Special characters in a password cause problems
The Captive Portal login page is the default an it is not customized. Davide Cottignoli
08:35 AM Bug #7423 (Not a Bug): Special characters in a password cause problems
Possible related to bug #6688:
When £ (pound) character is used in a password from an Active Directory account and a...
Davide Cottignoli
08:17 AM Bug #7422: Typo in OpenVPN NCP description
Current version 2.4.0.b.20170323.1013

No 'z' in text. http://imgur.com/vCa9QWo
John Murphy
07:10 AM Bug #7422 (Feedback): Typo in OpenVPN NCP description
PR Merged Jim Pingle
07:58 AM Feature #2358: NAT64 support
UPVOTE!!!
We are switching several of our subnets from dual-stack to pure IPv6 and NAT64/DNS64 is not optional for u...
Dmitri Toubelis
12:27 AM Feature #7182: Break up System Widget on the Dashboard
Remaining "todo": Traffic Graphs widget code needs to be changed so that it will work with multiple Traffic Graphs wi... Phillip Davis
12:25 AM Feature #7182: Break up System Widget on the Dashboard
RELENG_2_3_3 and RELENG_2_3 have a consistent implementation of being able to filter the content displayed in various... Phillip Davis

03/23/2017

11:36 PM Bug #7422: Typo in OpenVPN NCP description
My bad, so I will fix, see PR https://github.com/pfsense/pfsense/pull/3669 Phillip Davis
07:46 PM Bug #7422: Typo in OpenVPN NCP description
https://github.com/pfsense/pfsense Kill Bill
06:22 PM Bug #7422 (Resolved): Typo in OpenVPN NCP description
Under Enable NCP, when you click on blue info sign you get:
"When both peers support NCP and have it enabled, NCP...
Ivor Kreso
11:29 PM Bug #6367: Long delays with LDAP enabled w/local users during boot at "Synchronizing user settings..."
I hate to comment on an old issue but I couldn't find one for the "proper fix" as mentioned above. Today my LDAP serv... Ilya Kogan
11:10 PM Bug #7421: Unresolvable port alias is omitted from rule rather than generating an error
Test:
a) Add an alias and a rule that uses it
b) Backup config
c) Edit config, delete the alias but leave the rule...
Phillip Davis
01:30 PM Bug #7421 (Feedback): Unresolvable port alias is omitted from rule rather than generating an error
Applied in changeset commit:224e1648174e4a27b7f091fe348a81c74bacf23e. Jim Pingle
01:20 PM Bug #7421 (Resolved): Unresolvable port alias is omitted from rule rather than generating an error
GUI validation prevents this from happening, but if a port alias is missing from the firewall configuration, a rule u... Jim Pingle
04:31 PM Bug #4310: Limiters + HA results in hangs on secondary
We are not noticing our secondary (which is also a VM) hang. However, our one limited rule traffic ends overnight, s... Steve Y
04:51 AM Bug #7420 (Closed): ipsec status freezing
I upgraded a SG-8860 yesterday from 2.3.2_1 to 2.3.3_1 after I applied the bios upgrade.
Unfortunately, now the IP...
Brice Figureau
01:21 AM Bug #7382: DNS Forwarder does not resolve DNS names on first boot
I can confirm the same behavior. My problem is with Domain Overrides, but I'm assuming the problem is the same.
T...
Jeremy Nelson

03/22/2017

04:20 PM Bug #7419 (Duplicate): CloudFlare DDNS Not working for wildcard updates
It is not possible to update the record for a wildcard domain using Cloudflare DDNS, even if the wildcard checkbox is... Galen POSPISIL
04:07 PM Feature #7418: Dynamic dns should be sorted interface name
well looks like interfaces were fixed across gui I have a bunch of gateway groups due to 3 isps added at different ti... Michael Kellogg
12:00 PM Feature #7418: Dynamic dns should be sorted interface name
No matter how we choose to sort them someone else will probably want them sorted differently. Making the tables thems... Jim Pingle
11:53 AM Feature #7418: Dynamic dns should be sorted interface name
System/Routing/Gateway Groups
should be sorted by group name alphabetically also
Michael Kellogg
11:47 AM Feature #7418 (New): Dynamic dns should be sorted interface name
Dynamic dns should be sorted interface name Michael Kellogg
01:21 PM Feature #2358: NAT64 support

I would like to see this important functionality
EDUARDO CERQUEIRA DA SILVA
01:04 PM Feature #7193: NTP process PGRMF
I'm sorry, I think I was unclear. In my original config I had selected GGA in the “NMEA Sentences” menu, plus ticked ... Pär Wedin
12:33 PM Todo #7385: Sanitize PHP includes
I redid the write_config() stuff as a separate PR. If someone provides some ETA for "next QA run", I'll redo the incl... Kill Bill
11:07 AM Feature #7407: Ability to preserve currently allocated IP address when adding static entries from Status -> DHCP Leases
The warning is for continuing to argue/discuss the issue here on redmine. This is not a discussion platform. I've sai... Jim Pingle
11:03 AM Feature #7407: Ability to preserve currently allocated IP address when adding static entries from Status -> DHCP Leases
Jim Pingle wrote:
> Consider this a second warning.
A *WARNING*? For what?
With above attitude, thank you for o...
ml 35
10:47 AM Feature #7407: Ability to preserve currently allocated IP address when adding static entries from Status -> DHCP Leases
Discuss it on the forum. Consider this a second warning. Jim Pingle
10:41 AM Feature #7407: Ability to preserve currently allocated IP address when adding static entries from Status -> DHCP Leases
Jim Pingle wrote:
> [...] unless the ISC DHCP daemon behavior is fixed.
Then are you suggesting that the manual f...
ml 35
10:32 AM Feature #7407: Ability to preserve currently allocated IP address when adding static entries from Status -> DHCP Leases
Yes, we know all of that. None of that helps the situation. It doesn't contradict anything, and if you read closer yo... Jim Pingle
10:29 AM Feature #7407: Ability to preserve currently allocated IP address when adding static entries from Status -> DHCP Leases
Jim Pingle wrote:
> Static mappings express a preference for address assignment and do not prevent other devices fro...
ml 35
10:27 AM Feature #7407: Ability to preserve currently allocated IP address when adding static entries from Status -> DHCP Leases
If I understand right, wiki claims that ISC DHCP will happily lease a fixed-address definition to anyone in case that... ml 35
08:48 AM Feature #7407: Ability to preserve currently allocated IP address when adding static entries from Status -> DHCP Leases
We are not that product. The DHCP daemon we use, the ISC DHCP Daemon does not support reservations. Static mappings e... Jim Pingle
08:42 AM Feature #7407: Ability to preserve currently allocated IP address when adding static entries from Status -> DHCP Leases
Jim Pingle wrote:
> You can't static map addresses inside the pool, so this would just confuse users.
There is at...
ml 35
10:41 AM Bug #4287: Wrong display for ppp in Interfaces page
I can't test the patch actually because since then I have changed my 3G usb key to an other huawei one, and there is ... Jo S
07:11 AM Bug #4287 (Feedback): Wrong display for ppp in Interfaces page
Jim Pingle
10:34 AM Feature #7392: Please allow syncing authorized_keys into config.xml
Kill Bill wrote:
> What's exactly difficult about CTRL+C, CTRL+V?
it takes more time and it's not just a CTRL-C C...
ml 35
07:12 AM Feature #6841 (Feedback): reduce numeric precision in Gateways Widget
Jim Pingle
03:25 AM Feature #6841: reduce numeric precision in Gateways Widget
Merged. Kill Bill
07:12 AM pfSense Packages Bug #7417 (Rejected): Avahi ipv6(disabled) port 5353(local link ipv6) firewall log spam until avahi is stopped for a few secs and then restarted
Please discuss and diagnose the problem on the forum before opening a bug report with the precise details and specifi... Jim Pingle
02:40 AM pfSense Packages Bug #7417: Avahi ipv6(disabled) port 5353(local link ipv6) firewall log spam until avahi is stopped for a few secs and then restarted
This is a bug tracker, use forums for discussions and mystery stories please. Kill Bill
07:10 AM Bug #6890 (Feedback): PPP service name error
Jim Pingle
07:09 AM Bug #7399 (Feedback): getserviceproviders.php - lack of sanity checking in foreach()
Jim Pingle

03/21/2017

11:57 PM pfSense Packages Bug #7417: Avahi ipv6(disabled) port 5353(local link ipv6) firewall log spam until avahi is stopped for a few secs and then restarted
Just a small edit: I just noticed that the spam started again. My guess is its some device on my lan, I will turn off... rub man
11:02 PM pfSense Packages Bug #7417 (Rejected): Avahi ipv6(disabled) port 5353(local link ipv6) firewall log spam until avahi is stopped for a few secs and then restarted
Hi,
I have ipv6 disabled and have not changed anything major changed on my network that has ipv6 enabled. But when ...
rub man
10:56 AM Bug #4287: Wrong display for ppp in Interfaces page
Merged. Kill Bill
10:56 AM Bug #6890: PPP service name error
Merged. Kill Bill
10:55 AM Bug #7399: getserviceproviders.php - lack of sanity checking in foreach()
Merged. Kill Bill
10:44 AM Bug #4479: Firewall rules won't match GRE interface after applying IPSEC transport encryption on GRE tunnel
This affects both GRE over IPSEC transport and IPSEC tunnel mode carrying a GRE
All traffic exiting the GRE tunnel...
Brett Howard
09:13 AM Feature #7416 (Needs Patch): DHCPv4 client does not support ``supersede`` statement for option 54
Changes to FreeBSD should first be submitted upstream to FreeBSD. Jim Pingle
08:55 AM Feature #7416 (Closed): DHCPv4 client does not support ``supersede`` statement for option 54
The German cable internet provider Unitymedia uses DHCP relays which only answer to broadcasts. Dhclient renews WAN l... Fabian Kurtz
08:58 AM Bug #7402: Inconsistent use of htmlentities validation checks
https://github.com/pfsense/pfsense/commit/11800cffd5bd0731596324cd4d26f829bf198174 allows users to put stuff like "&"... Phillip Davis
08:42 AM Bug #7415 (Resolved): favicon is not correctly implemented
favicon is implemented as a favicon.ico in the root of the webserver. This is one of the 2 possible methodes and favo... Leon Straathof

03/20/2017

10:10 PM Feature #7318: Dashboard widget filters - provide a "None" option
Above PRs 3652 and 3653 have been merged to master. Phillip Davis
02:30 PM pfSense Packages Feature #7414 (New): snort needs automated refresh on ip change
if pppoe ip changes snort needs refreshed to deal with that ip change would be nice if it happened automatically Michael Kellogg
02:09 PM pfSense Packages Todo #7411: LADVD Devices not wide enough
Andy Kniveton wrote:
> The output is when run from a shell is fine , but the output is cut off via the web gui in th...
Andy Kniveton
06:07 AM pfSense Packages Todo #7411 (New): LADVD Devices not wide enough
The output is when run from a shell is fine , but the output is cut off via the web gui in the top section :-
+GUI...
Andy Kniveton
01:31 PM Bug #7413 (Resolved): status_dhcpv6_leases.php: Some DHCPv6 leases are not displayed in the GUI
On status_dhcpv6_leases.php, only about half the leases in my /var/dhcpd/var/db/dhcpd6.leases file are displayed in t... Jim Pingle
12:25 PM Bug #7412 (Resolved): rtsold will not run on VLAN interfaces
A VLAN interface for a WAN will not pull an IPv6 address via DHCPv6 with a default configuration.
In a default con...
Jim Pingle
11:40 AM Bug #7372 (Feedback): Cannot filter ICMP Type SKIP
Applied in changeset commit:bea1884125fdd9d8ef58afd97f53516b61adaf29. Phillip Davis
06:36 AM Feature #7410: IPSEC multiple dynamic IP remote clients
If it's possible, it will take some time/thought about how best to handle. Jim Pingle
01:41 AM Feature #7410 (Closed): IPSEC multiple dynamic IP remote clients
We are actually running version 2.3.2 using mainly pfsense as a IPSEC VPN server for multiple remote locations.
Remo...
Sebastien WILD
03:30 AM Bug #4723: Can't forward UDP fragmented packets with scrubbing enabled.
Luiz Otavio O Souza wrote:
> Richard, which pfSense version are you running ?
Latest 2.3.3_1
Richard Gate

03/19/2017

10:46 PM Bug #7402: Inconsistent use of htmlentities validation checks
How about the use of filter_var: http://php.net/manual/en/filter.filters.php
filter_var($value, FILTER_SANIT...
BBcan177 .
10:41 PM Bug #7116: a floating 'match' rule on LAN does not put traffic from a broswer on a clientpc into a shaper queue
I think my bug is related too.
https://redmine.pfsense.org/issues/7409
Kristopher Kolpin
09:23 PM Bug #7409: Packets originating from the firewall itself do not enter the proper queue.
I just posted on the forum now but I believe the rule I am using is sound. I know just because I said I've been usin... Kristopher Kolpin
09:10 PM Bug #7409 (Rejected): Packets originating from the firewall itself do not enter the proper queue.
Please post on the forum for discussion. Shaping happens when a packet exits an interface, odds are your floating rul... Jim Pingle
08:58 PM Bug #7409 (Rejected): Packets originating from the firewall itself do not enter the proper queue.
I have a 25/10 DSL connection and for well over a year I've been able to setup queues successfully for regular intern... Kristopher Kolpin
08:16 PM Feature #7406: Ability to clear all dhcp leases at once
ml 35 wrote:
> Under Status - DHCP Leases I can clear all leases one by one.
> It would be useful if I had a button...
Daryl Morse
10:46 AM pfSense Packages Bug #7310: Packages pre-deinstall script removes temporary files used by pkg
This is not a Snort bug. Beyond already linked #7229, there's another example of pkg being braindead junk here: https... Kill Bill
04:45 AM Feature #7122: Add filters to various dashboard widgets
Phillip Davis wrote:
> With the delay in reviewing/merging community-contributed PRs, I have split PR 3602 up into t...
Kill Bill
04:23 AM Feature #7122: Add filters to various dashboard widgets
With the delay in reviewing/merging community-contributed PRs, I have split PR 3602 up into the various parts that ar... Phillip Davis
03:58 AM Feature #7318: Dashboard widget filters - provide a "None" option
Revised code in:
https://github.com/pfsense/pfsense/pull/3652 Handle widgets having no items selected for display
h...
Phillip Davis

03/18/2017

10:29 PM Feature #7193: NTP process PGRMF
I also have a Garmin 18x LVC and I've been trying to replicate your setup but I'm not really sure why you needed a fu... Jack Booth
02:55 PM pfSense Packages Bug #7170: FreeRADIUS built-in certificate manager defaults to MD5 (!!!), no support for SHA2
https://github.com/pfsense/FreeBSD-ports/pull/334
Should be pretty much complete now.
Kill Bill

03/17/2017

05:48 PM Bug #7380: WAN DHCP Gateway Outside of Subnet Causing Route Issues
Thanks Jim. Apologies for not linking the diff the first time around.
I've signed the CLA and submitted a pull re...
Doran Smestad
03:23 PM Feature #7408 (Duplicate): IGMPPROXY quickleave
Jim Pingle
03:10 PM Feature #7408: IGMPPROXY quickleave
Duplicate of #3862 Kill Bill
03:02 PM Feature #7408 (Duplicate): IGMPPROXY quickleave
Dear pfsense-team,
Can you add the possibility to activate or deactive the quickleave option of the igmpproxy?
ht...
Thomas Levi
02:27 PM Feature #7383 (Feedback): system_certmanager.php?act=new: Add new select option to sign a CSR
Anonymous
01:08 PM Bug #4723: Can't forward UDP fragmented packets with scrubbing enabled.
Richard Gate wrote:
> Hi, I've hit this problem with UDP packets for RADIUS authentication when using a pfSense IPSe...
Luiz Souza
11:46 AM Bug #4723: Can't forward UDP fragmented packets with scrubbing enabled.
Hi, I've hit this problem with UDP packets for RADIUS authentication when using a pfSense IPSec tunnel from an AP doi... Richard Gate
09:12 AM pfSense Packages Bug #7403: Captive Portal + freeradius2 + MySQL problems with German Umlaut
https://redmine.pfsense.org/issues/4497 John Wayne
09:08 AM pfSense Packages Bug #7403: Captive Portal + freeradius2 + MySQL problems with German Umlaut
http://lists.freeradius.org/pipermail/freeradius-users/2005-November/004818.html John Wayne
08:36 AM pfSense Packages Bug #7403: Captive Portal + freeradius2 + MySQL problems with German Umlaut
In the log files it seems all correct:
Mar 17 13:41:05 radiusd 74676 Login incorrect: [guest/müller] (from clie...
John Wayne
05:02 AM pfSense Packages Bug #7403 (New): Captive Portal + freeradius2 + MySQL problems with German Umlaut
We have a setup using a Captive Portal and freeradius2 package + MySQL as database for authentication.
The freerad...
John Wayne
07:40 AM Bug #7396 (Resolved): Stopping and then starting again the load balancer clears out system tables (Bogons, sshlockout, aliases...)
Great, thanks for testing! Jim Pingle
07:35 AM Bug #7396: Stopping and then starting again the load balancer clears out system tables (Bogons, sshlockout, aliases...)
Jim Pingle wrote:
> OK, try the later change here on the ticket now ( commit:31b1f1e1 )
This is all good now ! Th...
Julien Petit
06:59 AM Bug #7396: Stopping and then starting again the load balancer clears out system tables (Bogons, sshlockout, aliases...)
OK, try the later change here on the ticket now ( commit:31b1f1e1 ) Jim Pingle
07:15 AM Feature #7407 (Rejected): Ability to preserve currently allocated IP address when adding static entries from Status -> DHCP Leases
You can't static map addresses inside the pool, so this would just confuse users. Jim Pingle
07:14 AM Feature #7407 (Rejected): Ability to preserve currently allocated IP address when adding static entries from Status -> DHCP Leases
I go to "Status -> DHCP Leases"
I click the "+" sign to "Add static mapping" under the "Actions" column
The page ...
ml 35
06:04 AM Feature #7406 (Resolved): Ability to clear all dhcp leases at once
Under Status - DHCP Leases I can clear all leases one by one.
It would be useful if I had a button to also clear all...
ml 35
05:57 AM Feature #7405 (New): Ability to add dhcp host reservations from "Diagnostics -> ARP table"
It can be very useful when you introduce pfsense into a lan where there are lots of static ip addresses.
This way ...
ml 35
05:23 AM Feature #7392: Please allow syncing authorized_keys into config.xml
What's exactly difficult about CTRL+C, CTRL+V? Kill Bill
04:42 AM Feature #7392: Please allow syncing authorized_keys into config.xml
ok, can you instead at least add an option to not clear the authorized_keys at reboot? it is really difficult to have... ml 35
05:22 AM pfSense Packages Bug #7404 (Not a Bug): OpenVPN Client Export with custom DynDNS not working
When using the OpenVPN Client Export Utility with a custom DynDNS the Host name resolution combobox-value is empty.
...
John Wayne
04:14 AM Bug #7116: a floating 'match' rule on LAN does not put traffic from a broswer on a clientpc into a shaper queue
Forgot to say: Indeed, *Pass* rule will place packets into related queue but it will break traffic. Dmitriy K
12:56 AM Bug #7402 (New): Inconsistent use of htmlentities validation checks
Forum: https://forum.pfsense.org/index.php?topic=127350.0
Various pages have a loop through the input parameters (...
Phillip Davis
12:23 AM Feature #4632: Support for Multipath TCP (MPTCP)
when it's in FreeBSD. Jim Thompson

03/16/2017

10:23 PM Feature #4632: Support for Multipath TCP (MPTCP)
Not sure where this is in development but this could really help me
so quick googling
http://blog.multipath-tcp....
Michael Kellogg
03:48 PM Bug #7396: Stopping and then starting again the load balancer clears out system tables (Bogons, sshlockout, aliases...)
Note that with your patch, tables are not deleted like before. Only our alias table "Trusted" is emptied. Without you... Julien Petit
03:44 PM Bug #7396: Stopping and then starting again the load balancer clears out system tables (Bogons, sshlockout, aliases...)
I couldn't reproduce that but it gave me another idea of where to look for problems. I'll have another fix pushed her... Jim Pingle
03:29 PM Bug #7396: Stopping and then starting again the load balancer clears out system tables (Bogons, sshlockout, aliases...)
Jim Pingle wrote:
> Nothing else should be required but the changes made in the patch.
>
> I can reproduce the pr...
Julien Petit
02:10 PM Bug #7396: Stopping and then starting again the load balancer clears out system tables (Bogons, sshlockout, aliases...)
Nothing else should be required but the changes made in the patch.
I can reproduce the problem without that fix ap...
Jim Pingle
01:54 PM Bug #7396: Stopping and then starting again the load balancer clears out system tables (Bogons, sshlockout, aliases...)
Jim Pingle wrote:
> That is not the usual way to operate relayd, however. Normally you would not need to stop/start ...
Julien Petit
01:20 PM Bug #7401 (Feedback): custom_php_deinstall_command isn't being run during pkg post-deinstall because info.xml has already been removed by that step.
Applied in changeset commit:59fada5c1fb57f2896caae895c70dd10ef5d02da. Jim Pingle
10:58 AM Bug #7401 (Resolved): custom_php_deinstall_command isn't being run during pkg post-deinstall because info.xml has already been removed by that step.
A bit of a chicken/egg problem here:
The custom_php_deinstall_command function from a package is supposed to be ru...
Jim Pingle
11:45 AM Bug #5993 (Feedback): dhcp6c not started until an RA received
Jim Pingle
11:43 AM Bug #5993: dhcp6c not started until an RA received
This issue can be closed. It was fixed in 2.3.3 and 2.4. Daryl Morse
10:59 AM pfSense Packages Bug #7319 (Rejected): Tinc uninstall leaves an entry in the firewall rules tab.
The code in the package is OK. Real problem is here: #7401 Jim Pingle
10:22 AM Bug #7400 (Assigned): Traffic Graphs show bad data on 2.3.3_1
Jared Dillard
07:28 AM Bug #7400 (Assigned): Traffic Graphs show bad data on 2.3.3_1
Hi!
i updated pfsense to version 2.3.3_1
Now, the traffic graph are showing wrong data. On Status/Traffic Graph...
Luis Garcia
10:20 AM Bug #7378 (Feedback): pfctl: ix0: driver does not support altq
Fix committed to RELENG_2_4, RELENG_2_3 and RELENG_2_3_3: https://github.com/pfsense/FreeBSD-src/commit/f2504b01d55b5... Luiz Souza
09:18 AM Bug #4479: Firewall rules won't match GRE interface after applying IPSEC transport encryption on GRE tunnel
Confirmed still not working on 2.4 Phil Lavin
09:14 AM Bug #7145 (Feedback): rc.newwanipv6 running in all cases, even for a renew
Jim Pingle
09:13 AM Bug #7145: rc.newwanipv6 running in all cases, even for a renew
This is fixed in 2.4. DHCP6C client modified to give REASONS and only call the update script when needed. Martin Wasley
04:17 AM Bug #7145: rc.newwanipv6 running in all cases, even for a renew
Having issues with this in 2.3.3
Every 30 minutes, my IPv6 address is refreshed, causing rc.newwanipv6 to fire on al...
Øyvind Hvidsten
09:12 AM Todo #6944 (Closed): dhcp6c releasing allocation
Jim Pingle
09:12 AM Bug #7185 (Feedback): DHCP6c SIGTERM, SIGKILL
Jim Pingle
09:10 AM Bug #7185: DHCP6c SIGTERM, SIGKILL
Close this Issue. DHCP6C has been fixed. Martin Wasley
09:11 AM pfSense Packages Bug #7390 (Feedback): SquidGuard
Fix pushed. Will show up shortly in pfSense-pkg-squidGuard version 1.16.1. Jim Pingle
08:54 AM Bug #7330 (Resolved): IPv6 Prefix is deleted on PPPoe reset, but not reapplied.
Fixed by PR Jim Pingle
03:41 AM Bug #7330: IPv6 Prefix is deleted on PPPoe reset, but not reapplied.
Fixed - Close this one. Martin Wasley
08:06 AM pfSense Packages Bug #6763: Squid ClamAv wrong redirect URL
Solution:
when I installed pfSense with all packages I use, I gave it a domain name.
After some while, I changed th...
Roma Golbraich
07:33 AM pfSense Packages Bug #7263 (Feedback): FreeRADIUS - complete lack of input validation
Jim Pingle
04:09 AM pfSense Packages Bug #7263: FreeRADIUS - complete lack of input validation
Merged. Kill Bill
06:46 AM Bug #7399: getserviceproviders.php - lack of sanity checking in foreach()
https://github.com/pfsense/pfsense/pull/3649 Kill Bill
06:45 AM Bug #7399 (Resolved): getserviceproviders.php - lack of sanity checking in foreach()
To reproduce:
- Go to Interfaces - Assign - PPPs - Add
- Choose PPP as Like Type
- Select country like Åland Isl...
Kill Bill
06:31 AM Feature #7122: Add filters to various dashboard widgets
Once the PR has been reviewed (and hopefully merged) the new checkbox format (like other widgets) will be available. ... Phillip Davis
05:13 AM Feature #7122: Add filters to various dashboard widgets
James Snell wrote:
> Build 2.4.0.b.20170314.2306 showing a multi-select box for interfaces, was expecting checkboxes...
Kill Bill
04:54 AM Feature #7122: Add filters to various dashboard widgets
Build 2.4.0.b.20170314.2306 showing a multi-select box for interfaces, was expecting checkboxes.
Cropped screensho...
James Snell
06:02 AM Bug #6890: PPP service name error
Yeah, the input validation makes zero sense, there's no user input there in the first place.
https://github.com/pf...
Kill Bill
05:29 AM Bug #6890: PPP service name error
Sorry for third answer, just found the service name check
/usr/local/www/interfaces_ppps_edit.php
Line 276
if ...
Daniel Weeber
05:27 AM Bug #6890: PPP service name error
Problem is in /usr/local/share/mobile-broadband-provider-info/serviceproviders.xml
Line 3150 contains (),-
<name>...
Daniel Weeber
05:05 AM Bug #6890: PPP service name error
Having the same problem. cannot add any ppp connection because it's saying "The service name contains invalid charact... Daniel Weeber
02:13 AM Bug #7326: Unbound fails to start during rc.wanipchange when using large enough dns lists
I pushed a commit for this (not a PR yet because I think there's more to be done) but in case anyone wants to use thi... → luckman212
01:15 AM Bug #7116: a floating 'match' rule on LAN does not put traffic from a broswer on a clientpc into a shaper queue
I confirm this bug. In pfSense 2.4 no matter what you with *Match* floating rules do all traffic is being pushed into... Dmitriy K

03/15/2017

11:49 PM Bug #7116: a floating 'match' rule on LAN does not put traffic from a broswer on a clientpc into a shaper queue
I too am seeing this bug. Fresh setup of traffic shaping using the wizard simply didn't work. All traffic was being p... Jakub Osika
06:07 PM pfSense Packages Bug #7391: 0.4.36_1 localnet ACL missing
Kill Bill wrote:
> And FYI regarding the OpenVPN: https://redmine.pfsense.org/issues/4331 (IOW, it will never be aut...
tqwqllrm tqwqllrm
03:30 PM pfSense Packages Bug #7391: 0.4.36_1 localnet ACL missing
And FYI regarding the OpenVPN: https://redmine.pfsense.org/issues/4331 (IOW, it will never be auto-added to localnet ... Kill Bill
09:39 AM pfSense Packages Bug #7391: 0.4.36_1 localnet ACL missing
No, it's not, noone touched the relevant code for years.
https://github.com/pfsense/FreeBSD-ports/blame/devel/www...
Kill Bill
09:35 AM pfSense Packages Bug #7391: 0.4.36_1 localnet ACL missing
Kill Bill wrote:
> Look, you need either non-empty local interface, or fill in Allowed Subnets on the ACLs tab. Plea...
tqwqllrm tqwqllrm
09:28 AM pfSense Packages Bug #7391: 0.4.36_1 localnet ACL missing
Look, you need either non-empty local interface, or fill in Allowed Subnets on the ACLs tab. Please, use forums for d... Kill Bill
09:25 AM pfSense Packages Bug #7391: 0.4.36_1 localnet ACL missing
Kill Bill wrote:
> Kindly tick "Allow local network(s) on interface(s)" if you want such ACL.
This is already tic...
tqwqllrm tqwqllrm
09:23 AM pfSense Packages Bug #7391: 0.4.36_1 localnet ACL missing
Additional information: The pfSense box is running OpenVPN so this may be a problem with this version of squid not be... tqwqllrm tqwqllrm
09:23 AM pfSense Packages Bug #7391: 0.4.36_1 localnet ACL missing
Kindly tick "Allow local network(s) on interface(s)" if you want such ACL. Kill Bill
08:00 AM pfSense Packages Bug #7391 (Not a Bug): 0.4.36_1 localnet ACL missing
Version 0.4.36_1 of Squid on pfSense 2.3.3 does not provide the "localnet" acl anymore in /usr/local/etc/squid/squid.... tqwqllrm tqwqllrm
06:04 PM Feature #7398 (Assigned): Show average value of bandwidth in/out on Dashboard trafic graph
Jared Dillard
05:33 PM Feature #7398 (Assigned): Show average value of bandwidth in/out on Dashboard trafic graph
Show like the image in attach.
Elias Pereira
05:01 PM Bug #6993: OpenVPN status error during CARP state transition
James Webb wrote:
> Running two devices in HA and have stacked one IP Alias onto the CARP IP. If I bind a OpenVPN se...
Mario Lener
03:45 PM pfSense Packages Bug #7390 (Confirmed): SquidGuard
Jim Pingle
06:44 AM pfSense Packages Bug #7390 (Resolved): SquidGuard
When a @'@ caracter is inserted in a comment, the "filter config" button in "Log" tab no longer works.
Javascript ca...
Aurélien BONANNI
03:17 PM Bug #7397 (Resolved): Backport factory.sh changes to 2.3
Copy recently added factory.sh functionality to 2.3 Anonymous
02:10 PM Bug #7396 (Feedback): Stopping and then starting again the load balancer clears out system tables (Bogons, sshlockout, aliases...)
Applied in changeset commit:803ca43a02863d2086f4affd8c1048c598475bf9. Jim Pingle
02:03 PM Bug #7396: Stopping and then starting again the load balancer clears out system tables (Bogons, sshlockout, aliases...)
To me, I have a fix pushed. Jim Pingle
01:54 PM Bug #7396 (Confirmed): Stopping and then starting again the load balancer clears out system tables (Bogons, sshlockout, aliases...)
Also affects 2.4.x.
That is not the usual way to operate relayd, however. Normally you would not need to stop/star...
Jim Pingle
01:32 PM Bug #7396 (Resolved): Stopping and then starting again the load balancer clears out system tables (Bogons, sshlockout, aliases...)
Hi there :)
This is reproducible on a brand new 2.3.3 or 2.3.3_1 pfsense 64 bits with following simple load balanc...
Julien Petit
02:05 PM Bug #7393: Problem with static route when you have Two WAN with same Gateway
You can have multiple WANs with different gateways, yes.
You cannot have multiple WANs with the same gateway. If i...
Jim Pingle
02:02 PM Bug #7393: Problem with static route when you have Two WAN with same Gateway
Jim Pingle wrote:
> Yes. And it works by chance, not by design. It's not a configuration we support.
No it works ...
Anthony hesnaux
01:51 PM Bug #7393: Problem with static route when you have Two WAN with same Gateway
Yes. And it works by chance, not by design. It's not a configuration we support. Jim Pingle
01:46 PM Bug #7393: Problem with static route when you have Two WAN with same Gateway
Error Jim Pingle,my Both WAN are PPPoE link in IPVPN MPLS but there are a same gateway
I have 1 link PPPoE (ADS...
Anthony hesnaux
12:25 PM Bug #7393: Problem with static route when you have Two WAN with same Gateway
It happens to work, that doesn't make it any more valid than if it were two non-PPPoE lines on the same network, just... Jim Pingle
12:23 PM Bug #7393: Problem with static route when you have Two WAN with same Gateway
wait I thought multi pppoe worked via your own comments and tests I just ordered a second pppoe ?
https://redmine....
Michael Kellogg
11:54 AM Bug #7393: Problem with static route when you have Two WAN with same Gateway
Having two interfaces on the same network is not a feature we support, and it is not a valid configuration. The probl... Jim Pingle
11:32 AM Bug #7393: Problem with static route when you have Two WAN with same Gateway
Hello Jim Pingle,
it's not a system-level limitation because when I add static route in CLi : /root: route add 192.1...
Anthony hesnaux
10:36 AM Bug #7393 (Rejected): Problem with static route when you have Two WAN with same Gateway
Having two WANs with the same gateway is not a viable configuration. It's an operating system-level limitation, nothi... Jim Pingle
10:33 AM Bug #7393 (Rejected): Problem with static route when you have Two WAN with same Gateway
hello all,
We find a problem on pfsense Nanobsd 2.3.2
Hardware : Motherboard ALIX
we have 2 Wan interface with M...
Anthony hesnaux
01:06 PM Feature #4372: dnscrypt support
+1 ml 35
12:54 PM Feature #6519: SSD TRIM option via GUI
Jim Pingle wrote:
> No, it is not. The option cannot be changed while the disk is mounted.
Could you add in the ...
ml 35
11:04 AM pfSense Packages Bug #7170: FreeRADIUS built-in certificate manager defaults to MD5 (!!!), no support for SHA2
Thanks, can start killing some code now. :) Kill Bill
10:38 AM pfSense Packages Bug #7170: FreeRADIUS built-in certificate manager defaults to MD5 (!!!), no support for SHA2
FYI- I merged that PR, should be good to continue. Jim Pingle
10:44 AM Feature #7395 (Duplicate): IPv6: Display prefix assigned by ISP
*PROBLEM STATEMENT*
When using DHCPv6 PD on the WAN interface, there is no easy way to see what prefix the ISP assig...
Tim Cappalli
10:36 AM Bug #7394 (Resolved): firewall_aliases_edit.php: Renaming an alias after input errors fails to update references
When renaming an alias the firewall normally checks for references in firewall/nat rules and updates the alias name w... Jim Pingle
10:28 AM Feature #2358: NAT64 support
UPVOTE!
I'd also like to voice my support for this integration
Scott Rosenberg
10:27 AM Feature #2358: NAT64 support
Joel Whitehouse wrote:
> Would like to see support for NAT64/DNS64 in pfsense. Deployment of DNS64 outside of the g...
Scott Rosenberg
10:08 AM Feature #7392 (Rejected): Please allow syncing authorized_keys into config.xml
While I could maybe see a script made to import keys there is no way this would be automated in the way you describe.... Jim Pingle
10:05 AM Feature #7392 (Rejected): Please allow syncing authorized_keys into config.xml
For me it is a bit inconvenient to copy and paste ssh keys into UI.
I am usually doing this using ssh-copy-id whic...
ml 35
09:30 AM Bug #7316 (Feedback): Fail Boostrap format port in
Applied in changeset commit:57dd76d15c66e5cd60839fe4b376153778de8904. Phillip Davis
09:29 AM Feature #7383: system_certmanager.php?act=new: Add new select option to sign a CSR
A fix for the Openssl library error is on the way.
Select Method->Sign a Certificate Signing Request
Use the "C...
Anonymous
08:54 AM Feature #7383 (Assigned): system_certmanager.php?act=new: Add new select option to sign a CSR
I also get "openssl library returns: error:0906D06C:PEM routines:PEM_read_bio:no start line" when attempting to sign ... Jim Pingle
08:52 AM Feature #7383: system_certmanager.php?act=new: Add new select option to sign a CSR
Current Base System 2.4.0.b.20170315.0313
Option not available. What am I missing? Isn't this a later snapshot? ...
John Murphy
08:27 AM Feature #7383: system_certmanager.php?act=new: Add new select option to sign a CSR
Build 2.4.0.b.20170314.2306
The option "Sign a Certificate Signing Request" is now present.
Created a signing r...
James Snell
06:10 AM Bug #7389 (In Progress): Limiter does not work with transparent proxy
Good morning the limiter returned to present problems, identical to the other bug already reported and resolved and r... Nelson Junior
06:05 AM Bug #7345: nanobsd upgrades still fail bacause of lacking resolv.conf
Great, thank you very much Brett! Andrew Hotlab
05:17 AM pfSense Packages Bug #7388: Suricata does not property recognize MTU for PPPOE interfaces
See this: https://redmine.openinfosecfoundation.org/issues/1556#note-2 Kill Bill
04:01 AM Todo #7385: Sanitize PHP includes
Up to pfSense devs. If you prefer, I can do a single PR for all the write_config() stuff, however that shouldn't rot ... Kill Bill

03/14/2017

09:49 PM Todo #7385: Sanitize PHP includes
@Kill Bill - there are write_config(gettext()) things mixed together with include_once() changes in these PRs.
Would...
Phillip Davis
09:25 PM Todo #7385: Sanitize PHP includes
Thanks for this. Given that JimP and others have a recollection that there is a reason for the seemingly odd includes... Anonymous
05:13 PM Todo #7385: Sanitize PHP includes
Hmmm well, I obviously left the filter.inc in places where stuff like @filter_configure()@ is being used (talking abo... Kill Bill
03:27 PM Todo #7385: Sanitize PHP includes
I seem to recall shaper.inc being in unexpected places because running a filter reload action fails without it. But t... Jim Pingle
03:21 PM Todo #7385: Sanitize PHP includes
Assigned to Steve Beaver, but this looks like it could be a hairball. Jim Thompson
04:00 AM Todo #7385: Sanitize PHP includes
Adding some related PRs here:
- https://github.com/pfsense/pfsense/pull/3624
- https://github.com/pfsense/pfsense...
Kill Bill
03:39 AM Todo #7385 (New): Sanitize PHP includes
Includes are massively wrong across the entire pfSense code.
Sort of a reminder. Please, review functions used in ...
Kill Bill
09:22 PM Bug #7345: nanobsd upgrades still fail bacause of lacking resolv.conf
I also ran into this issue, which broke my ability to update my NanoBSD 2.3.2_1 box to 2.3.3_1. The box in question ... Brett Keller
09:11 PM pfSense Packages Bug #7388 (New): Suricata does not property recognize MTU for PPPOE interfaces
Due to path MTU discovery (via ICMPv6) issues with some IPv6 TCP traffic I have to manually set MSS to 1452 in the WA... Kristopher Kolpin
06:01 PM Bug #7326: Unbound fails to start during rc.wanipchange when using large enough dns lists
I left the log message just for testing... Shouldn't be included in final code...
The function is_process_running...
BBcan177 .
05:35 PM Bug #7326: Unbound fails to start during rc.wanipchange when using large enough dns lists
Could probably use @is_process_running()@ from util.inc instead of the @exec()@. That debug stuff should certainly be... Kill Bill
05:23 PM Bug #7326: Unbound fails to start during rc.wanipchange when using large enough dns lists
Its a 30x loop in 1 sec increments and breaks on Unbound being fully shutdown.
for ($i=1; $i <= 30; $i++) {
BBcan177 .
05:21 PM Bug #7326: Unbound fails to start during rc.wanipchange when using large enough dns lists
note on my system it needs a lot more than one second to shutdown, probably around 10 seconds due to the over 1 milli... Chris Collins
01:49 PM Bug #7326: Unbound fails to start during rc.wanipchange when using large enough dns lists
The issue with the way pfSense stops Unbound, is that the Unbound service takes longer to shut down when there are ma... BBcan177 .
04:01 PM Feature #7383: system_certmanager.php?act=new: Add new select option to sign a CSR
Use a build from after the time the change was made. Your build was made at 0021 hrs, the new code was added at 1300 ... Anonymous
03:59 PM Feature #7383: system_certmanager.php?act=new: Add new select option to sign a CSR
Current Base System 2.4.0.b.20170314.0021
Option not displayed in Cert. Manager GUI. Checked CAs, Certificates, a...
John Murphy
02:16 PM Feature #7383 (Feedback): system_certmanager.php?act=new: Add new select option to sign a CSR
Functionality has been added as requested
https://github.com/pfsense/pfsense/commit/2052d3e2ae3acf5564a460dad91966...
Anonymous
03:36 PM Feature #7321: DynDNS - Add DreamHost DNS support
Whoops... I completely missed that the second red flag "CLA Missing" was a reversal.
Jim Thompson
02:28 PM Feature #7321: DynDNS - Add DreamHost DNS support
The Pull Request should show that I have already completed the CLA. Is there a separate one that I need to complete? Frank Gruman
02:01 PM Feature #7321: DynDNS - Add DreamHost DNS support
will need a signed CLA prior to integration. Jim Thompson
03:34 PM Bug #7232: haproxy_pool_edit.php -- sprintf() too few arguments
Seems like these changes should be reverted?
In webgui im seeing:...
Pi Ba
02:25 PM Bug #4479: Firewall rules won't match GRE interface after applying IPSEC transport encryption on GRE tunnel
Has anyone managed to test on 2.4 yet? Experiencing this issue in 2.3 latest. Phil Lavin
02:19 PM Bug #7288 (Needs Patch): The field 'Distinguished name Organization' contains invalid characters
Looks like it may be possible to use UTF-8 but it would require significant work to ensure everything functions prope... Jim Pingle
02:02 PM pfSense Packages Bug #7319: Tinc uninstall leaves an entry in the firewall rules tab.
Assigned to Pingle for tracking. Jim Thompson
01:39 PM Bug #7380: WAN DHCP Gateway Outside of Subnet Causing Route Issues

Assigned to Renato for evaluation.
Actual diff is here:
https://github.com/doransmestad/pfsense/commit/d79a46...
Jim Thompson
12:50 PM Bug #7387 (New): New Traffic Graph in dashboard resets inverted view to normal view
New Traffic Graph in Dashboard resets inverted view to overlapping view when switching tabs between Status-Monitoring... Carsten Lohrmann
09:30 AM Bug #7386 (Resolved): IPv6 not disabled in mpd.conf w/ IPv6 GUI option set to 'disabled'
continuing from:
https://forum.pfsense.org/index.php?topic=126849.0
When my ISP (Fairpoint) apparently added some...
Bill McGonigle

03/13/2017

02:22 PM Bug #7384 (Resolved): DHCPv6 doesn't merge IPv6 prefix with the input submitted in DNS servers field when using Track Interface IPv6 configuration parameter for the LAN interface.
When using Track Interface as a IPv6 Configuration Type in the LAN interface, the DHCPv6 server doesn't merge the IA_... Hannu Tirkkonen
11:34 AM pfSense Packages Bug #7170: FreeRADIUS built-in certificate manager defaults to MD5 (!!!), no support for SHA2
OK, I'll figure something out and do a PR. Need https://github.com/pfsense/FreeBSD-ports/pull/308 merged first before... Kill Bill
08:20 AM pfSense Packages Bug #7170: FreeRADIUS built-in certificate manager defaults to MD5 (!!!), no support for SHA2
I agree, it could/should be killed for 2.4.
Not that far out, probably a few weeks.
Jim Pingle
05:35 AM pfSense Packages Bug #7170: FreeRADIUS built-in certificate manager defaults to MD5 (!!!), no support for SHA2
Guys, any ETA for 2.4 release (not date, but weeks/months, that sort of thing)? Would be a good opportunity to get ri... Kill Bill
08:51 AM Feature #7383 (Closed): system_certmanager.php?act=new: Add new select option to sign a CSR
Certificate Manager -> Certificates -> Add New: There would be a new select option 'Sign a Certificate Signing Reques... Anonymous
06:26 AM Feature #7381: Option to disable alias popups in rules
Well yes, it's already limited to 10K entries (they are all displayed if you have the patience to scroll down...)
...
Kill Bill
06:20 AM Feature #7381: Option to disable alias popups in rules
In the 2.2.x days we only let the popup display 30 or so entries which seems saner than making an option. A huge alia... Jim Pingle
03:32 AM Feature #7381: Option to disable alias popups in rules
It seems a reasonable thing to me (for those running on crud hardware at either server or client end) and is easy to ... Phillip Davis
03:19 AM Feature #7381: Option to disable alias popups in rules
Huh, what kind of horrible HW/browser are you using? Takes about a second on a 10 years old laptop with an alias havi... Kill Bill
06:03 AM Bug #7203: pkg_mgr_installed.php - visually separate the legend
RELENG_2_3 backport - https://github.com/pfsense/pfsense/pull/3644 Kill Bill
04:11 AM Bug #7382 (Closed): DNS Forwarder does not resolve DNS names on first boot
"DNS Forwarder (dnsmasq)" service is running at first boot but i am get an error : "dhcpleases Could not deliver sign... Özgür Keleş

03/12/2017

08:41 PM Feature #7381 (Resolved): Option to disable alias popups in rules
An option to disable the popup of the aliases in the rules section would be very handy, hovering over a 20k+ list by ... Ken Sim
03:15 PM Bug #7379: Virtual IPs/Proxy ARP: Not defined pid file on starting choparp.
Yeah, it'd help to determine what's the actual bug before attempting to fix it.
P.S. Please, use GitHub for patche...
Kill Bill
03:05 PM Bug #7379: Virtual IPs/Proxy ARP: Not defined pid file on starting choparp.
New Bug after applying the patch:
There are several PoxyARP VIPs. Open one of them to edit and change the type to an...
aLexander Panfilov
12:44 PM Bug #7379 (Resolved): Virtual IPs/Proxy ARP: Not defined pid file on starting choparp.
Not defined pid file on starting choparp. The pfSense may not kill the program to reconfiguration.
@--- interfaces...
aLexander Panfilov
01:47 PM Bug #7380 (Resolved): WAN DHCP Gateway Outside of Subnet Causing Route Issues
When deploying PFSense in OVH's public cloud, they assign a IPv4 address via DHCP in a /32 subnet. Naturally, with s... Doran Smestad
01:30 PM Bug #6344: Firewall rules being deleted when separators are added
I'm no longer seeing this behavior. This issue can be closed. Zetto Null
01:23 PM Bug #7249: firewall_rules.php & firewall_nat.php: Replaces underscores with spaces in aliase names
NOYB NOYB wrote:
> So what is the actual issue that replacing the underscore with space in the displaying of the rul...
Zetto Null
06:03 AM Bug #6732: interfaces_ppps_edit.php: L2TP and PPTP WAN-type interface editing has broken input validation
Can you give some detail of what you are entering. I can't (easily) reproduce it, so maybe there is some unusual/spec... Phillip Davis
05:42 AM Bug #6732: interfaces_ppps_edit.php: L2TP and PPTP WAN-type interface editing has broken input validation
It seems that it only works partially.
I just tried to paly around with the @interfaces_ppps_edit.php@-Settings on v...
Thomas Rieschl
03:27 AM Bug #7330: IPv6 Prefix is deleted on PPPoe reset, but not reapplied.
It's my thread :)
And yeah, PR https://github.com/pfsense/pfsense/pull/3515 will resolve this one...
Thanks again!
Greg M
03:13 AM Bug #7330: IPv6 Prefix is deleted on PPPoe reset, but not reapplied.
Michael Zieher wrote:
> Greg M wrote:
> > Hi!
> >
> > Very similar issue I think it`s connected: https://forum.p...
Martin Wasley

03/11/2017

03:14 PM Bug #5999: IPv6 IP Alias prevents Track Interface from working with DHCPv6 and RA
Fixing this would help with the problems discussed in this forum post: https://forum.pfsense.org/index.php?topic=1269... Doug Twitchell
02:50 PM Bug #6233: Bootloop with Alix after 2.3 upgrade
Norm Sevilla wrote:
> I can confirm the issue on my setup as well, a Negate m1n1wall with pfSense 2.3.3_1 and a Hifn...
Norm Sevilla
12:38 PM Bug #6233: Bootloop with Alix after 2.3 upgrade
I can confirm the issue on my setup as well, a Negate m1n1wall with pfSense 2.3.3_1 and a Hifn 7955 crypto accelerato... Norm Sevilla
02:12 PM Bug #6138 (Resolved): Long hostnames overlap the "time" title in the Monitoring graphs
Thanks, Malcolm. I'll mark this resolved. Jared Dillard
08:56 AM Bug #6138: Long hostnames overlap the "time" title in the Monitoring graphs
I've got a reasonably long fqdn hostname (32 characters) and it looks OK now and doesn't overlap. Malcolm Hussain-Gambles
12:59 PM Bug #7378 (Resolved): pfctl: ix0: driver does not support altq
Motherboard: Supermicro X10SDV-4C-TLN2F
using the onboard NIC: 2 RJ45 10GBase-T ports
2.3.3-RELEASE-p1 (amd64)
Fr...
Omer Iqbal
11:30 AM Feature #3697: New backup/restore area: Certificates
Ah yeah, blindly replacing a config section is indeed absolutely no problem... Who cares that the GUI, VPNs and other... Kill Bill
11:14 AM Feature #3697: New backup/restore area: Certificates
OPNsense implemented it and it works like a charm. Few days ago I was prepping a replacement box and I though I would... Dmitriy K
10:58 AM Feature #3697: New backup/restore area: Certificates
Dmitriy K wrote:
> It would be nice if we could backup / restore all certificates only.
I don't think so. Imagine...
Kill Bill
07:16 AM Bug #7334 (Assigned): SG-1000 Update failure
The progress bar issue is another matter. We are waiting for a fix from upstream. Anonymous
01:59 AM pfSense Packages Feature #7377 (Resolved): ACME Certificate DNS-Digitalocean Verification Method
It would be great to have a DNS verification method for DigitalOcean DNS API that is now natively in GitHub for acme.... the wer

03/10/2017

11:51 PM Bug #7334: SG-1000 Update failure
Renato Botelho wrote:
> Fixed on pfSense-upgrade 0.18
I'm still seeing 'failures' part way through the script. S...
Greg Siemon
07:03 PM pfSense Packages Feature #7376 (Closed): ACME Package - Please add support Namecheap DNS service
Please add DNS support in the ACME Package for the Namecheap DNS service provider.
Namecheap API documentation
h...
User Name
06:13 PM Bug #7375 (Assigned): User with restricted privileges can still delete all monitoring/graphing data
Jared Dillard
05:47 PM Bug #7375 (Resolved): User with restricted privileges can still delete all monitoring/graphing data
I attempted to create a "graph-viewing-only" user account that I could hand out to non-admin users so that they could... Brett Keller
11:59 AM Bug #6186: race conditions in service startup
I've run into this issue as well on my pfSense machines that have ovpn client interfaces set as the outgoing interfac... John Cairns
09:46 AM pfSense Packages Bug #7374: Barnyard2 package has incomplete install when installed as Suricata depedency
You can take it whereever you want. There's no reference to Snort in the config [1], and no useful information here.
...
Kill Bill
09:43 AM pfSense Packages Bug #7374: Barnyard2 package has incomplete install when installed as Suricata depedency
I'll take it up with Netgate support if this is the attitude I get here.
Easy to be a dick when you don't use your r...
Randy Terbush
09:42 AM pfSense Packages Bug #7374: Barnyard2 package has incomplete install when installed as Suricata depedency
I'll track this and contact Bill Meeks.
"Kill Bill", please find a way to interact with a more professional tone....
Jim Thompson
09:33 AM pfSense Packages Bug #7374: Barnyard2 package has incomplete install when installed as Suricata depedency
Like, read what? There is zero information here to determine anything and it has nothing to do with the PBI junk on <... Kill Bill
09:16 AM pfSense Packages Bug #7374: Barnyard2 package has incomplete install when installed as Suricata depedency
Maybe you can take a little different attitude and take time to read what I wrote since I took the time to search the... Randy Terbush
08:50 AM pfSense Packages Bug #7374: Barnyard2 package has incomplete install when installed as Suricata depedency
Randy Terbush wrote:
> This seems to be possible duplicate of #3756
No, absolutely not, plus completely unclear ...
Kill Bill
08:12 AM pfSense Packages Bug #7374 (Closed): Barnyard2 package has incomplete install when installed as Suricata depedency
This seems to be possible duplicate of #3756 which was marked resolved 2 years ago, but still appears to be an issue.... Randy Terbush
07:59 AM Bug #7330: IPv6 Prefix is deleted on PPPoe reset, but not reapplied.
Hi!
I honestly believe that this one deservers a little higher priority than normal...
Greg M
06:45 AM Feature #4606: PKI : CA signing external CSR
+1 for that rather basic feature!
it should be easy to implement, there is already a similar package, that handles...
Tech Synedra

03/09/2017

08:40 PM Bug #4287: Wrong display for ppp in Interfaces page
https://github.com/pfsense/pfsense/pull/3639
Cannot see what else could be done here. If it's not reported, it's n...
Kill Bill
06:19 PM Bug #4669: QinQ virtual interfaces available for assignment where they shouldn't be
Timo Nieminen wrote:
> The patch 1. is missing on 2.3.2-RELEASE-p1. Booting system with QinQ interfaces assigned wil...
Kill Bill
01:32 PM Bug #7373 (New): Firewall schedules GUI needs to be redone from scratch
That thing is seriously horrible, the calendar is confusing like hell plus mostly useless - never heard of anyone sch... Kill Bill
11:34 AM Bug #7372: Cannot filter ICMP Type SKIP
An easier way to keep it would be to use the type number (39) instead of the name. The rule loads fine with 39 instea... Jim Pingle
03:14 AM Bug #7372: Cannot filter ICMP Type SKIP
If you want to block all "dodgy" ICMP types, then you should probably block ICMP type numbers that do not have a defi... Phillip Davis
02:50 AM Bug #7372: Cannot filter ICMP Type SKIP
Phillip Davis wrote:
> SKIP (type 39) has been deprecated:
> Is there a reason you (or anyone) need to particularly...
Kill Bill
 

Also available in: Atom