Project

General

Profile

Activity

From 07/03/2017 to 08/01/2017

08/01/2017

10:32 PM Feature #7537: Include mellanox mlx4 and mlx5 ethernet driver
edit : It seems it's supported by the freebsd base : https://www.freebsd.org/releases/11.1R/hardware.html#ethernet
...
Alexandre Paradis
09:10 PM Bug #4494: axge bug - AX88179 chipset (network interface reseting)
FYI, still happening in v2.4 - but is on the FreeBSD HW compatibility list. Anything I can do to help debug?
Thanks!
Russell Morris
07:57 PM Revision a98daee3: Fix #7625: Auto select '128' as mask for IPv6
Renato Botelho
07:57 PM Revision 036b32b5: Fix #7625: Auto select '128' as mask for IPv6
Renato Botelho
04:03 PM Feature #7747 (New): Minor UI Tweak: Make hitting enter on the console (esp via SSH) should not log you out, but simply redraw the menu
When you don't have a password set on the console, the net effect is the same anyway. However, over SSH, this is ann... Dan Mahoney
03:40 PM Revision d08c1387: Fix VLAN Priority set pf syntax. Fixes #7744
Jim Pingle
03:13 PM Bug #7430: pfsense-utils.inc - where_is_ipaddr_configured() should account for loopback interface
It's a subject to be discussed but doesn't make sense to change where_is_ipaddr_configured() this way since it uses g... Renato Botelho
03:10 PM Bug #7625 (Feedback): When creating IPv6 firewall rule for single host, netmask improperly displays
Applied in changeset commit:036b32b57e88464d66e6e01e640178f68cf882ec. Renato Botelho
03:05 PM Feature #6293 (Duplicate): Include 'if_urndis.ko' kernel module for USB network tethering
Close it in favor of #7467 Renato Botelho
03:05 PM Feature #7467: Add iPhone/Android/Generic USB tethering support
Generalize the topic to be able to close older tickets Renato Botelho
03:02 PM Feature #7467: Add iPhone/Android/Generic USB tethering support
We need to make tests and it's too late for 2.4.0 Renato Botelho
02:59 PM pfSense Packages Bug #7578: Suricata -- Removing Hosts from Block Table via Alerts
It doesn't depend of a pfSense version and as soon as package is updated will be available for all supported versions Renato Botelho
01:10 PM Feature #7746: Proxy NDP
You can already use other types of VIPs to use additional addresses (IP Alias and CARP) just not for giant blocks of ... Jim Pingle
01:00 PM Feature #7746: Proxy NDP
I agree that it's horrible. But I still have a valid use case for such a feature because of *someone else's* preexis... Adam Thompson
12:36 PM Feature #7746 (Rejected): Proxy NDP
There isn't any such daemon. We've had it come up before and it's not possible at this time, possibly ever. It would ... Jim Pingle
12:22 PM Feature #7746: Proxy NDP
I can't find any evidence anywhere (including tcpdump) that "Proxy ARP" VIPs support NDP. I'm assuming they don't, s... Adam Thompson
12:21 PM Feature #7746 (Rejected): Proxy NDP
We have "Proxy ARP" VIPs, now we need "Proxy NDP" VIPs to allow pfSense to function with service providers such as OV... Adam Thompson
12:18 PM Bug #7745: 1:1 NAT is somehow broken for IPv6 (corner case??)
Hmm. It's 100% trivially reproducible for me. When it's 100% reproducible for me, most of the time it's 100% reprod... Adam Thompson
11:55 AM Bug #7745: 1:1 NAT is somehow broken for IPv6 (corner case??)
It shouldn't happen that way, but again, you have not yet identified a specific bug, only a symptom. We need a lot mo... Jim Pingle
11:51 AM Bug #7745: 1:1 NAT is somehow broken for IPv6 (corner case??)
If this need to be better documented on the public Wiki, I can make those changes myself. I can't update the officia... Adam Thompson
11:49 AM Bug #7745: 1:1 NAT is somehow broken for IPv6 (corner case??)
Perhaps I could have been clearer: the complaint here is that:
- creating a 1:1 NAT entry and then removing it someh...
Adam Thompson
11:36 AM Bug #7745 (Not a Bug): 1:1 NAT is somehow broken for IPv6 (corner case??)
I don't see a bug here. It works just like IPv4. IPv4 1:1 would also fail if you added a mapping for some other IP ad... Jim Pingle
11:30 AM Bug #7745: 1:1 NAT is somehow broken for IPv6 (corner case??)
Update: it only breaks when the WAN interface is in the same "subnet" (possibly /64, haven't confirmed the affected p... Adam Thompson
11:24 AM Bug #7745 (Not a Bug): 1:1 NAT is somehow broken for IPv6 (corner case??)
Steps to reproduce:
1. configure (e.g.) WAN interface as 2607:5300:79:501:167:114:147:49/56. Configure default gate...
Adam Thompson
10:50 AM Bug #7744 (Feedback): VLAN Priority options cause pf syntax error
Applied in changeset commit:d08c13875483a81b6393f0127abe719e5734dea4. Jim Pingle
10:40 AM Bug #7744 (Resolved): VLAN Priority options cause pf syntax error
In FreeBSD 11, the syntax for matching and setting VLAN Priorities changed. See https://reviews.freebsd.org/D6786
...
Jim Pingle

07/31/2017

08:32 PM Revision f4c3483a: rc.gateway_alarm, add syslog message that shows that a alarm was raised/cleared and what the parameters were
This helps clarify why sometimes services are restarted when reading through the syslogs.
(cherry picked from commit...
Pi Ba
08:32 PM Revision c71df82d: Merge pull request #3762 from PiBa-NL/20170624_gatewayalarm_log
Renato Botelho
08:32 PM Revision 2839bb13: Use correct wording for menu entry "Reset All States" in "System/Advanced Network"
(cherry picked from commit ee7bdbe69b873544b960c159386971af42cba52d) Fernsehkind
08:32 PM Revision c5ad7e26: Use correct wording for log output when IP address has changed and states are killed accordingly
(cherry picked from commit 8e7d47feda1c56715304a3a381fc9495698179fb) Fernsehkind
08:32 PM Revision 0ffce5fd: Add GUI entry for ip_change_kill_states in Network/Advanced (See #1629)
(cherry picked from commit 66a405929e61938c036005cca8fde0ba17554a27) Ralph Haussmann
08:32 PM Revision ba2500cf: Improve log output when ip_change_kill_states is set.
(cherry picked from commit a84da2286cc5353b5ce7161aa3d59ccd43ae3868) Ralph Haussmann
08:32 PM Revision f3d3a023: Merge pull request #3535 from fernsehkind/Redmine1629
Renato Botelho
08:01 PM Revision 9b18dc1b: Add pt_BR back to GUI since it's over 75% complete
Renato Botelho
07:41 PM Revision d33bdb27: Merge pull request #3774 from phil-davis/sort-if-names-RELENG_2_3
Renato Botelho
07:38 PM Revision ac789c95: ipsec, prevent simultaneous/repeated calling of vpn_ipsec_configure() by /etc/rc.newipsecdns
(cherry picked from commit 7c6f38e49a2005812e37fe5b365717edc0d5dd44) Pi Ba
07:38 PM Revision 23273a9b: Merge pull request #3773 from PiBa-NL/20170703-ipsec-sleep-lock
Renato Botelho
07:37 PM Revision 898d5161: Trafficshaper, show interface names for disabled interfaces, dont just show a kinda 'empty' spot..
(cherry picked from commit 725aee3f19ea01d48f14e65ac60e4189218b3834) Pi Ba
07:37 PM Revision 4b1d0e05: Merge pull request #3784 from PiBa-NL/20170713-shaper-show-disabled-interface-names
Renato Botelho
07:36 PM Revision 8f212c64: Correct typo's as per Jim's request
(cherry picked from commit 3e86fa9913091ded202854a931fa02320f7fa1a0) Martin Wasley
07:36 PM Revision 8420b944: Add Option to use static IPV6 over v4 parent ( PPPoE
A new option when setting a v6 static on the WAN to allow the connection to use the V4 interfaces i.e. PPPoE
(cherr...
Martin Wasley
07:36 PM Revision 40f2618c: Merge pull request #3761 from marjohn56/master
Renato Botelho
07:35 PM Revision 024a1db6: Merge pull request #3789 from stilez/patch-69
Renato Botelho
07:35 PM Revision 514233ee: typo
"Networked" not "network" - "Internet of Things" especially.
(cherry picked from commit d751dee379b37da868efa837df55...
Stilez y
07:35 PM Revision 23dcfc75: grammar fix
(cherry picked from commit 94ef78afa96f1870b453fab670754c01c6161665) Stilez y
07:35 PM Revision 83477771: format %1$s etc in help
(cherry picked from commit ef77e40e0c7b861cc268cd1f0e30600f573b807e) Stilez y
07:35 PM Revision 5c9bc798: Improve the HELP note about what will/won't work if TLD is set to ".local"
For example, some people won't use mDNS and won't know other things might break; also it's not clear that while ".loc... Stilez y
07:35 PM Revision 76efa197: Merge pull request #3787 from stilez/patch-68
Renato Botelho
07:34 PM Revision a32a2d04: Add support for IPv6 AUTO_LINKLOCAL flag on bridge interfaces
(cherry picked from commit b060e08c9dd701b56b5163321b5e9a79f90b1f23) Lorenz Schori
07:34 PM Revision 8d478177: Merge pull request #3788 from znerol/feature/master/bridge-ipv6-auto-linklocal
Renato Botelho
07:33 PM Revision 64876ec1: Use attribute rekey_enable as usual but optionally allow to set margintime if rekeying is not disabled
(cherry picked from commit 376e6f6719e6463913045b233ca90d69254057ff) hamnur
07:33 PM Revision a69de2f6: Fix indent of if-block
(cherry picked from commit 9d472f01c31f2b56a95631dcd4f49e4685f55ea6) hamnur
07:33 PM Revision 8f03bc04: Check if margintime is numeric and smaller than P1 lifetime
(cherry picked from commit af729f53f3c838f91dffb6368b656ddece527e05) hamnur
07:33 PM Revision f7c409fe: Hide margintime if rekeying is disabled
(cherry picked from commit e18ddb38449b6463fabf5782284b206a355dbad7) hamnur
07:33 PM Revision 04c2c662: Activate RADIUS accounting for mobile ipsec if it was selected on the auth server view
(cherry picked from commit 1e0442e0612ecd289aa979bc945be0d8ead35f41) hamnur
07:33 PM Revision 9ca72a77: Add strongswan rekeymargin attribute to vpn ipsec phase1 view
(cherry picked from commit 9542011684a26e0b1b959d9b56d5fcfc12023893) hamnur
07:33 PM Revision 39194387: Merge pull request #3770 from hamnur/master
Renato Botelho
07:32 PM Revision ccf8bd86: dhcp6c Advanced Config prefix interface
Currently, when using dhcp6c advanced configuration the prefix interface is WAN, this is not very useful!
The change...
Martin Wasley
07:32 PM Revision 16dec2f3: Merge pull request #3791 from marjohn56/PD-FIX
Renato Botelho
07:29 PM Revision 33048f25: Merge pull request #3585 from PiBa-NL/trafficgraphs-optimize
Renato Botelho
07:24 PM Revision 9d21b366: Merge pull request #3785 from stilez/patch-67
Renato Botelho
05:47 PM Bug #7743 (Not a Bug): Redmine does not allow slection of version 2.3.4_1 in "Affected version" field
Fixed (but not a bug) Jim Pingle
05:04 PM Bug #7743 (Not a Bug): Redmine does not allow slection of version 2.3.4_1 in "Affected version" field
My "Affected version" list goes 2.3, 2.3.3, 2.3.3_1, 2.3.4, 2.4, 2.4.x.
No 2.3.4_1 option is available, although I s...
Adam Thompson
05:00 PM Bug #7742: 1:1 NAT for IPv6 applies wrong subnet mask to "Single Host"
Also, when re-editing that 1:1 NAT rule, the GUI repeatedly resets the prefix length to "31". This, again, breaks al... Adam Thompson
04:55 PM Bug #7742: 1:1 NAT for IPv6 applies wrong subnet mask to "Single Host"
(I believe this is why I thought IPv6 NAT was broken in #7740. Not 100% sure. Made enough mistakes today I'm not su... Adam Thompson
04:54 PM Bug #7742 (Resolved): 1:1 NAT for IPv6 applies wrong subnet mask to "Single Host"
Adding an IPv6 1:1 NAT entry and choosing "Single Host" produces the resulting rule in /tmp/rules.debug:
binat on ...
Adam Thompson
04:45 PM Feature #7741 (Resolved): warn me when shooting myself in the foot with NPt
When one configures IPv6 NPt (network prefix translation) to use a public prefix that *does* overlap with the interfa... Adam Thompson
12:41 PM pfSense Packages Feature #7548 (Resolved): Add absolute offset stat to NTP monitoring display
Jim Pingle
12:02 PM pfSense Packages Feature #7548: Add absolute offset stat to NTP monitoring display
Tested, working (2.4.0.b.20170731.0959) John Pettitt
12:39 PM Bug #7740 (Not a Bug): 1:1 NAT field allows IPv6 addresses
It's allowed because it's valid. Granted it's not as useful and NPt does the same thing, essentially. If it were brok... Jim Pingle
12:08 PM Bug #7740 (Not a Bug): 1:1 NAT field allows IPv6 addresses
The 1:1 NAT setup screen allows IPv6 addresses to be entered, even though they do not function. No warnings are emit... Adam Thompson
12:06 PM Revision 40d2cc71: Update translation files
Renato Botelho
11:49 AM Revision 01115630: Regenerate pot
Renato Botelho
07:51 AM pfSense Packages Bug #7736 (Feedback): Crahs with Quagga OSPF and the latest 2.4 Beta
I just pushed a fix, give it a try when the package update shows next (0.6.20) Jim Pingle
03:46 AM Bug #7734: Using opton ia pd0 does not renew prefix and prefix get dropped
Sorry - was looking for it but forgot about /var/etc:... Daniel Helgenberger

07/30/2017

12:53 PM Feature #7739 (Rejected): If there is already a gateway, retrieve data from the one that already exists?
Having the same gateway on more than one interface is not a supported configuration. Jim Pingle
11:56 AM Feature #7739 (Rejected): If there is already a gateway, retrieve data from the one that already exists?
Hi,
I have multiple gateway with the same ip and then it can not show them at the same time, but I had to mix with...
Christoffer Öhman
12:14 PM Revision a0bd0a4f: important exclusion - update help text for packets dropped by NIC / offload
Say that non-promiscuous mode doesn't see packets dropped by NIC.
(promiscuous detection relies mainly on different r...
Stilez y
11:06 AM Revision 52229047: trafficgraphs, move common code to 1 file, and remove usage of 'localstorage' which shares unwanted changes to graph settings between widget and stats
Pi Ba
10:58 AM Revision d3fd2bbe: traffic-graphs, optimize retrieval of data every x seconds to reduce spikes in the graphs and load on pfSense
also cleanup some old code. Pi Ba
09:20 AM Feature #7738 (New): Highlight which IPSec (or other VPN) crypto modes are hardware-accelerated in the UI
I've found it VERY difficult to determine precisely which combinations of ciphers and MACs will be hardware-accelerat... Adam Thompson
08:39 AM Bug #7737 (New): radvd error message
Perhaps this is a configuration issue, or a bug introduced during the 2.4 update.
I am now receiving the following...
Juan Abonia
07:47 AM pfSense Packages Bug #7736 (Resolved): Crahs with Quagga OSPF and the latest 2.4 Beta
Crash report begins. Anonymous machine information:
amd64
11.0-RELEASE-p11
FreeBSD 11.0-RELEASE-p11 #193 d...
Andreas Strub

07/29/2017

02:42 AM Bug #7734: Using opton ia pd0 does not renew prefix and prefix get dropped
If you are still running 2.3 then it's not related at all, 7330 was a 2.4 issues and was fixed and is closed. The iss... Martin Wasley

07/28/2017

07:54 PM Revision dc5fdeea: notices, background delivery of growl messages and combined mail messages from a queue so that in case of failure the timeout period for connecting does not impact the functionality of the calling scripts themselves
1st message is delivered directly after it is queued.
2nd and following messages that are send within a 10 second win...
Pi Ba
07:47 PM Revision f8ac4324: Comment fixes
Steve Beaver
05:59 PM Revision 2f162658: Revise default widget settings to accommodate new support widget name
Steve Beaver
04:58 PM Revision 2304e7b4: Add renamed support widget
Steve Beaver
04:56 PM Revision 1528ee4e: dns, allow deleting last row for "Additional Names for this Host"
(cherry picked from commit f6cf3687d21c6ca6ba7a25605fafe249f866b439) Pi Ba
04:54 PM Revision 3f74acc7: Merge pull request #3783 from PiBa-NL/20170713-dns-delete-last-additional-name
Renato Botelho
02:20 PM Feature #3329: Allow creating "not" rules for IPsec Phase 2
Example implementation Markus Stockhausen
02:16 PM Feature #3329: Allow creating "not" rules for IPsec Phase 2
This feature wil be really helpful. Lets assume a office firewall connected to a HQ firewall. It serves sub multiple ... Markus Stockhausen
02:02 PM Bug #5826: Auto-exclude LAN address feature only works for the LAN interface
We have the same problem. For my reminder. Configuration is created by /etc/inc/vpn.inc in the following lines
i...
Markus Stockhausen
12:43 PM Feature #7549: Enable Python support in Unbound
To use python with unbound the module also needs to be enabled in the configuration file with:... Doug Twitchell
11:43 AM Bug #7735 (Not a Bug): Switching to wildcard cert fails until reboot
Steps to reproduce:
1. manually add the Globalsign CA
2. manually add the AlphaSSL intermediate CA
3. manually add...
Adam Thompson
09:32 AM Bug #7734: Using opton ia pd0 does not renew prefix and prefix get dropped
This might be related to #7330 Daniel Helgenberger
09:31 AM Bug #7734 (New): Using opton ia pd0 does not renew prefix and prefix get dropped
From my ISP i am getting a vl/rl of 14400 seconds
The prefix is not renewed and is dropped after 4hrs, see below.
...
Daniel Helgenberger
09:04 AM Todo #6606 (Assigned): Adapt captive portal to work without multi-instance ipfw
I'll check it Renato Botelho
09:02 AM Todo #6606: Adapt captive portal to work without multi-instance ipfw
I tried this morning and my devices which use to work are still being directed to the logon page. I have a few device... Brian Caouette
09:03 AM Bug #7733 (Resolved): User Manager deletes non-selected users
The User Manager seems to delete non-selected (wrong) users when using the 'red' delete button on the bottom of the U... Tom Wijnroks
07:05 AM Revision 58a185ae: dhcp6c Advanced Config prefix interface
Currently, when using dhcp6c advanced configuration the prefix interface is WAN, this is not very useful!
The change...
Martin Wasley
05:43 AM Bug #7732 (Not a Bug): Unable to connect remote system after upgrading to the latest version
This is a bug tracker, not a support system. Please post on the forum, reddit, mailing list, or another support chann... Jim Pingle
01:06 AM Bug #7732 (Not a Bug): Unable to connect remote system after upgrading to the latest version
Yesterday I was updated my pfsense to the latest version 2.3.4-RELEASE-p1 (amd64). After upgrading I am able to conne... Nagachandra Pavuluri

07/27/2017

05:42 PM Bug #6223: IPsec + OpenBGPD fails with "PF_KEY socket: No buffer space available"
Jim Pingle wrote:
> Only in that we're making progress on replacing OpenBGPD with FRR
Well that's exciting! I ass...
Michael OBrien
04:58 PM Revision 9968e384: Eliminate Gold menu item
Steve Beaver
04:58 PM Revision d85dc363: Rename support widget to "Netgate Services And Support"
Steve Beaver
04:18 PM Revision 3e86fa99: Correct typo's as per Jim's request
Martin Wasley
04:18 PM Revision b7331383: Add Option to use static IPV6 over v4 parent ( PPPoE
A new option when setting a v6 static on the WAN to allow the connection to use the V4 interfaces i.e. PPPoE Martin Wasley
12:12 PM pfSense Packages Bug #7729: pfBlockerNG orders NAT licked rules to the bottom of firewall rules
@BBcan177
Looks like it worked !
Pls make it default.
Yuri Weinstein
11:56 AM pfSense Packages Bug #7729: pfBlockerNG orders NAT licked rules to the bottom of firewall rules
@BBcan177
Thx for the clue.
What's the proper way to modify /usr/local/pkg/pfblockerng/pfblockerng.inc ?
I made c...
Yuri Weinstein
11:32 AM pfSense Packages Bug #7729: pfBlockerNG orders NAT licked rules to the bottom of firewall rules
Can you edit */usr/local/pkg/pfblockerng/pfblockerng.inc*
and replace the line (-) with the new line (+):
Line 4...
BBcan177 .
11:15 AM Bug #7731 (Duplicate): DynDNS fail to update after connection lose
Hi,
i experienced some problems with DynDNS update.
When the gateway is down (connection lost) and then come ba...
Alessandro Mannini
08:16 AM Bug #7730: 2.3.4_1 greX: loop detected when hit save on filter rules or interfaces
to clarify previous cluster sync comment:
If we make the change as described above on secondary the tunnel stays up ...
Richie M
07:16 AM Bug #7730 (New): 2.3.4_1 greX: loop detected when hit save on filter rules or interfaces
upgraded from 2.2.6
anytime we hit save in the GUI for interface or filter rules, even if no change was made, we sta...
Richie M

07/26/2017

11:44 PM pfSense Packages Bug #7729 (Resolved): pfBlockerNG orders NAT licked rules to the bottom of firewall rules
When I use pfBlockerNG and rules order as this https://snag.gy/yFQa5b.jpg after rules update my NAT linked non-pfBlo... Yuri Weinstein
10:25 PM Bug #7723 (Not a Bug): Cannot focus username or password input fields
Jim Pingle
06:45 PM Bug #7723: Cannot focus username or password input fields
I upgraded to 2.3.4p1 and can no longer reproduce. Thanks! Andornaut -
05:08 PM Revision 508a84ed: Enable REDIS option for suricata
Renato Botelho
05:08 PM Revision 6b473757: Enable REDIS option for suricata
Renato Botelho
05:08 PM Revision d1637ec2: Enable REDIS option for suricata
Renato Botelho
03:12 PM Bug #7728: 1:1 NAT: Destination IP Alias not displayed as web link
image of bad behaviour Markus Stockhausen
03:10 PM Bug #7728 (Resolved): 1:1 NAT: Destination IP Alias not displayed as web link
If you define a 1:1 NAT rule with a destination IP (source/destination match) this destination IP may be an alias. In... Markus Stockhausen
02:50 PM Revision 1fea5a2e: Fixed 7128
Steve Beaver
02:37 PM Bug #7629: FreeBSD PR affecting pfsense
Since JimP has confirmed 2.4.x will move to 11.1 then this bug is effectively resolved "after" that change occurs. Chris Collins
02:11 PM Revision 38af638a: Allow recheck on refresh if JSON not available
Steve Beaver
01:44 PM Revision e14c441b: Make rules that deal with IP+MAC pairs to be layer2 only
Renato Botelho
12:30 PM pfSense Packages Bug #7278 (Feedback): Suricata Service - Advanced Configuration Pass-Through not working
Merged, thanks! Renato Botelho
12:05 PM Feature #7593 (Rejected): Enable FreeBSD 11 pvclock module in 2.4 builds
pvclock is not a module, it's a standard piece of the kernel as you can see at original review at https://reviews.fre... Renato Botelho
11:48 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
the game in question is "For Honor", but im pretty sure it affects any game that uses peer to peer matchmaking. There... Anonymous
11:46 AM Feature #7727 (Resolved): uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
It's a bug with pfsense, at least in my eyes (nearly 15 years experience in IT and am a senior security engineer with... Anonymous
11:01 AM Bug #7474: Problems adding gateway from interface edit
Already in master by PR https://github.com/pfsense/pfsense/pull/3700
So it happens already in 2.4 - no need to push ...
Phillip Davis
08:54 AM Bug #7474: Problems adding gateway from interface edit
Push to 2.4.1 Renato Botelho
10:32 AM Bug #7128 (Resolved): system_advanced_network.php - fugly IPv6 over IPv4 input field alignment
Looks good now Jim Pingle
09:52 AM Bug #7128 (Feedback): system_advanced_network.php - fugly IPv6 over IPv4 input field alignment
Changed layout to use two separate fields + JS hide/show Anonymous
09:09 AM Feature #7549 (Resolved): Enable Python support in Unbound
Anything we need to do on the OS side is done already, the rest is up to the actual scripts to setup mounts/libraries... Jim Pingle
08:55 AM Bug #7268 (Feedback): System Info Widget "All" button does not work with "Disable the automatic dashboard auto-update check"
Merged Renato Botelho
08:54 AM pfSense Packages Feature #7548 (Feedback): Add absolute offset stat to NTP monitoring display
Merged, thanks! Renato Botelho
08:49 AM Todo #6606 (Feedback): Adapt captive portal to work without multi-instance ipfw
Work is now complete Renato Botelho
07:16 AM Bug #7724 (Rejected): Captive portal not blocking unauthorized MAC addresses
This is not a general problem that can be reproduced here, and there is not enough detail in your report to speculate... Jim Pingle
07:09 AM Bug #6400: assign_interfaces.php issues with large numbers of interfaces
See also: #7726 Jim Pingle
07:08 AM Bug #7726 (Duplicate): Many VLANS and php-fpm 100%CPU Hangs web gui
Duplicate of #6400 Jim Pingle
05:43 AM Bug #7726 (Duplicate): Many VLANS and php-fpm 100%CPU Hangs web gui
This problem was reported some time ago already:
https://forum.pfsense.org/index.php?topic=102607.0
https://forum...
Markus Kötter
03:14 AM Feature #1219: Ship DTRACE enabled kernels in the images
+1
I would not even bother if dtrace kernel was an extra image for pfsense 2.4.
Markus Kötter
12:05 AM Bug #7725 (Resolved): Support for iwm
FreeBSD 11-Current added support for the Intel Dual Band Wireless AC 3160/7260/7265 IEEE 802.11ac network adapters (h... Jamie Nadeau

07/25/2017

11:39 PM Bug #7724 (Rejected): Captive portal not blocking unauthorized MAC addresses
We are using pfSense
Serial: 57625aa6-71ba-11e7-8e29-0800275891eb
Netgate Device ID: f3ad8559b22bd5e94b4d
From...
Gaurav Parashar
09:03 PM Revision 239b15fb: Add some info to HELP text (no code change otherwise)
NTP background isn't going to be widely known. So provide a bit of info so that it's done properly if someone cares.
...
Stilez y
06:55 PM Revision f6e6ff31: Restore calls to pfSense_ipfw_table_zerocnt(), it's fixed now
Renato Botelho
05:10 PM Revision f4c867e0: Remove unused parameters
Renato Botelho
05:08 PM Revision 5f6825bb: Do not associate IP and MAC on down table
Renato Botelho
05:04 PM Revision 75395abf: Fix syntax
Renato Botelho
04:56 PM Revision fa6ae0ea: Remove leftover debug
Renato Botelho
04:47 PM Revision 3c4fcd5b: Ressurrect nomacfilter option on CP now IPFW supports combined tables with IP and MAC address
Renato Botelho
02:53 PM Revision b060e08c: Add support for IPv6 AUTO_LINKLOCAL flag on bridge interfaces
Lorenz Schori
02:49 PM Revision d751dee3: typo
"Networked" not "network" - "Internet of Things" especially. Stilez y
02:48 PM Revision 94ef78af: grammar fix
Stilez y
02:37 PM Revision ef77e40e: format %1$s etc in help
Stilez y
02:33 PM Revision b45746a3: Improve the HELP note about what will/won't work if TLD is set to ".local"
For example, some people won't use mDNS and won't know other things might break; also it's not clear that while ".loc... Stilez y
02:18 PM Bug #6223: IPsec + OpenBGPD fails with "PF_KEY socket: No buffer space available"
Only in that we're making progress on replacing OpenBGPD with FRR, which hopefully will not suffer from the same issu... Jim Pingle
02:14 PM Bug #6223: IPsec + OpenBGPD fails with "PF_KEY socket: No buffer space available"
Any progress on this? josue escalante
12:21 PM Bug #7723 (Feedback): Cannot focus username or password input fields
No problems here on Chrome with Android 7.1.2 and Chrome 59.0.3071.125 (Tablet) or Android 7.0 (Droid Turbot 2), in p... Jim Pingle
11:51 AM Bug #7723 (Not a Bug): Cannot focus username or password input fields
The username and password input fields cannot be focused when using Chrome on Android.
h2. Steps to reproduce
1...
Andornaut -
12:04 PM Revision b40b4a3e: Re-introduce Captive Portal statistics
Renato Botelho
10:07 AM Bug #4218: Bridge does not have AUTO_LINKLOCAL flag
PR: https://github.com/pfsense/pfsense/pull/3788 (simple checkbox, does not detect whether or not ipv6 is configured ... znerol znerol
06:43 AM Bug #4218: Bridge does not have AUTO_LINKLOCAL flag
I think this feature could be implemented as follows:
* Provide a new advanced configuration option on the bridge ...
znerol znerol
09:46 AM Bug #7500: Upgrade From 2.3.3_p1 to 2.4 Fails (libssl.so.8 not found)
See also: #7722 Jim Pingle
09:46 AM Bug #7722 (Duplicate): PHP Startup: Unable to load dynamic library '/usr/local/lib/php/20131226/ssh2.so' - Shared object "libssl.so.7" not found, required by "libssh2.so.1" in Unknown on line 0
Duplicate of #7500 Jim Pingle
09:33 AM Bug #7722 (Duplicate): PHP Startup: Unable to load dynamic library '/usr/local/lib/php/20131226/ssh2.so' - Shared object "libssl.so.7" not found, required by "libssh2.so.1" in Unknown on line 0
Upgraded through WebGUI 2.3.4 to 2.4.0-BETA (amd64) everything seems to go smooth except I receive this error...
C...
Geoffrey Bricker
06:02 AM Bug #7721 (Closed): NTPd stops using external peers if listening on one interface only in a muliwan setup
In a multiwan setup, when selecting only one listening interface (eg. LAN), NTPd does not select external peers as th... Daniel Helgenberger

07/24/2017

09:32 PM Feature #7720 (New): Add general watchdog kernel modules (like ichwd) and watchdogd support in the GUI.
Per this topic, enabling watchdogd seems to be harder than it should be: https://forum.pfsense.org/index.php?topic=10... Dan Mahoney
03:56 PM Bug #7719 (Resolved): Dynamic DNS updates not working on interface failover
I realized that dynamic DNS hostnames are not being updated on interface failover. When manually marking a gateway as... Jorge Albarenque
11:12 AM Revision eb0a2a94: Update translation files
Renato Botelho
11:04 AM Revision 46b206d7: Regenerate pot
Renato Botelho
10:05 AM Feature #7718 (New): Hostname for Custom DynDNS Updater.
Hi,
right now I'm using a custom DynDNS service for VPN connectivity. The problem is that you can't set the hostna...
Oliver Loch
09:34 AM pfSense Packages Bug #7191 (Resolved): squid package EN-US grammar errors
Jim Pingle
09:29 AM pfSense Packages Bug #7191: squid package EN-US grammar errors
Also fixed in 0.4.37 so I am sure this bug can be closed now. Vincent Bentley
09:18 AM pfSense Packages Bug #7674: Issue Downloading Snort Alert Log Download
Ryan Eckenrode wrote:
> I have found that I am no longer able to download the Alert Logs from the snort_alerts.php p...
Vincent Bentley
03:32 AM Bug #4310: Limiters + HA results in hangs on secondary
Jose Duarte wrote:
> For those still with problems you can use limiters in HA with any version w/out kernel panic bu...
Lars Jorgensen

07/22/2017

07:26 AM Feature #7717 (Closed): DNS Resolver update to Unbound-1.6.4 to get RPZ / fastrpz support
We'll pick it up automatically once it hits the proper ports branches used by 2.3.x and 2.4.x. Jim Pingle
06:26 AM Feature #7717 (Closed): DNS Resolver update to Unbound-1.6.4 to get RPZ / fastrpz support
We would like to be able to use Reverse Policy Zones (RPZ) using the "fastrpz" patch which Unbound has included into ... Rolf Sommerhalder

07/21/2017

07:08 PM pfSense Packages Bug #7716 (Resolved): Suricata - Barnyard2 webui configuration updates result in base64-encoded value written to the config for the password
Any changes to the Suricata barnyard configuration page requires that you update the password as well, otherwise the ... Renaud Holcombe
11:47 AM Bug #7715: Update from 2.3.4 to -p1 mangled many config entries including users, patches, other config
ok
Stilez y
11:42 AM Bug #7715 (Rejected): Update from 2.3.4 to -p1 mangled many config entries including users, patches, other config
Please discuss a problem such as this on the forum or mailing list rather than jumping right to assuming it's a bug a... Jim Pingle
11:35 AM Bug #7715: Update from 2.3.4 to -p1 mangled many config entries including users, patches, other config
Logs Stilez y
11:35 AM Bug #7715 (Rejected): Update from 2.3.4 to -p1 mangled many config entries including users, patches, other config
I updated my test router 2.3.4 to 2.3.4-p1 and a load of config got wiped out in the process, including users reset a... Stilez y
09:49 AM Bug #7714 (Confirmed): NTP Widget Time Display
Note: The time itself is correctly fetched from the firewall, but is being adjusted to the wrong time _zone_ when dis... Jim Pingle
09:45 AM Bug #7714 (Resolved): NTP Widget Time Display
NTP Widget on 2.3.4-RELEASE-p1 is showing a time other than the received NTP time. Timezone is set to Etc/UTC as per ... Ben Montour
09:33 AM Feature #7245: NTP widget shows client time instead of server time
Start a new bug report for that. It may be using the local time _zone_ incorrectly but it is not using the local cloc... Jim Pingle
09:31 AM Feature #7245: NTP widget shows client time instead of server time
Jim Pingle wrote:
> The fix was in 2.3.4 and any release after that.
>
> It is not pulling local time. I just con...
Ben Montour
09:29 AM Feature #7245: NTP widget shows client time instead of server time
The fix was in 2.3.4 and any release after that.
It is not pulling local time. I just confirmed it by loading the ...
Jim Pingle
09:19 AM Feature #7245: NTP widget shows client time instead of server time
This appears to still be pulling local time in 2.3.4-RELEASE-p1.
Was this fix part of 2.3.4 or am I misreading somet...
Ben Montour
06:31 AM Bug #7713 (Rejected): APU2C4 + TRAFFIC SHAPER CBQ = KERNEL PANIC
Please discuss the problem on the forum before opening a bug report.
It is highly unlikely that we will make speci...
Jim Pingle
04:37 AM Bug #7713: APU2C4 + TRAFFIC SHAPER CBQ = KERNEL PANIC
The issue occur with a simple install with at least 1 vlan (vlan number2).
Without VLAN the issue doesn't occur.
...
Julien REVERT
03:17 AM Bug #7713 (Rejected): APU2C4 + TRAFFIC SHAPER CBQ = KERNEL PANIC
Hardware APU2C4
Pfsense 2.3.4_1
Coreboot 4.0.7
As soon as you activated traffic shaper with CBQ, there is a kern...
Julien REVERT
04:19 AM Bug #4310: Limiters + HA results in hangs on secondary
For those still with problems you can use limiters in HA with any version w/out kernel panic but for that you need ad... Jose Duarte

07/20/2017

10:59 PM Feature #4606 (Duplicate): PKI : CA signing external CSR
Superseded by #7383 Jim Pingle
06:42 PM Feature #7712: Support NPt with Dynamic WAN Interfaces
Jim Pingle wrote:
> Duplicate of #4881
Oops. My apologies, my search was incomplete.
Galen POSPISIL
06:31 PM Feature #7712 (Duplicate): Support NPt with Dynamic WAN Interfaces
Duplicate of #4881 Jim Pingle
05:39 PM Feature #7712 (Duplicate): Support NPt with Dynamic WAN Interfaces
Currently, using Multi-WAN with IPv6 requires a static IPv6 address on all WAN connections. Mass market cable and DS... Galen POSPISIL
05:41 PM Revision a911c65a: Support widget visible by default
Steve Beaver
05:34 PM Revision b96b6d3b: Add customer support widget
Steve Beaver
05:04 PM Revision 629be5fd: Do not re-create core pkg repo when running with -r
Renato Botelho
05:04 PM Revision 47683c94: Do not re-create core pkg repo when running with -r
Renato Botelho
05:04 PM Revision 31fd94b3: Do not re-create core pkg repo when running with -r
Renato Botelho
09:53 AM Bug #7711: Traffic Shapper = Kernel Panic
Ok, I will do more testing and keep you inform.
Thanks.
Julien REVERT
09:52 AM Bug #7711: Traffic Shapper = Kernel Panic
Like most other x86/x86-64 hardware, while it may work, we do not specifically test on that platform to ensure compat... Jim Pingle
09:40 AM Bug #7711: Traffic Shapper = Kernel Panic
Ok but APUC4 is a compatible pfsense hardware no? Julien REVERT
09:39 AM Bug #7711 (Rejected): Traffic Shapper = Kernel Panic
Please discuss the problem on the forum before opening a bug report.
It's entirely possible that even if it isn't ...
Jim Pingle
09:34 AM Bug #7711: Traffic Shapper = Kernel Panic
The stability of the APU2C4 was perfect for 5 months before traffic shapper testing...
Same issue with 3 other APU...
Julien REVERT
09:33 AM Bug #7711 (Rejected): Traffic Shapper = Kernel Panic
Hardware APU2C4 with SSD 16Gb
As soon as I configure traffic shapper (wizard or not), my pfsense is completely stu...
Julien REVERT
04:23 AM Bug #7709: raspberry pi or anything that can emulate ethernet gadget over usb mac id not read
i had filed a bug request on bugzilla on freebsd site and the devs there provided a patch to test but i have no clue ... Bipin Chandra

07/19/2017

02:05 PM Revision e266811c: Update the base package exclude files list.
Luiz Souza
01:54 PM Revision 57ee53b6: Build frr for testing
Jim Pingle
08:36 AM Bug #7326 (Resolved): Unbound fails to start during rc.wanipchange when using large enough dns lists
I still haven't been able to replicate the original problem here, but unbound appears to be restarting OK on WAN fail... Jim Pingle
08:07 AM Bug #7693 (Resolved): Brute force protection does not kill states, so additional login attemps may be possible in some cases
Works. States get killed, client cannot make new connections. Jim Pingle
07:50 AM Bug #7709: raspberry pi or anything that can emulate ethernet gadget over usb mac id not read
well the mac spoofing works in gui but the base mac id keeps changing so pfsense doesnt query for the new mac id when... Bipin Chandra
07:07 AM Bug #7709: raspberry pi or anything that can emulate ethernet gadget over usb mac id not read
That would be the same as setting a MAC address to spoof on the interface configuration in the GUI. If that doesn't w... Jim Pingle
06:48 AM Bug #7709: raspberry pi or anything that can emulate ethernet gadget over usb mac id not read
there is a way mentioned here https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=174464
no idea if this can be implem...
Bipin Chandra
07:41 AM Todo #7708 (Resolved): bsdinstall does not have a "Recover config.xml" option like the previous installer
Works! Jim Pingle

07/18/2017

09:47 PM Bug #7697: NAT port forward rule using "WAN address" doesn't work as expected if router does not acquire a WAN address on startup
I'll try to test it out in the next couple of weeks hopefully. Thanks for the fix. Andy Wang
04:03 PM Revision 396a2796: Fix license
Jim Pingle
03:35 PM Revision e5aeaeb6: Add installer script to optionally recover config.xml off an existing drive. Implements #7708
Jim Pingle
01:49 PM Bug #7710 (Resolved): IGMP Proxy
IGMP Proxy failed on SG-1000, its been working O.K and for some reason the recent updates have caused it to fail agai... Jeremy Lewis
11:34 AM Bug #7709 (Needs Patch): raspberry pi or anything that can emulate ethernet gadget over usb mac id not read
If it's a FreeBSD bug, which it appears to be, report it upstream to FreeBSD. Once they fix it, the change will trick... Jim Pingle
11:23 AM Bug #7709 (Needs Patch): raspberry pi or anything that can emulate ethernet gadget over usb mac id not read
based on the discussion here
https://forum.pfsense.org/index.php?topic=133695.0
it seems like a freebsd issue whe...
Bipin Chandra
10:50 AM Todo #7708 (Feedback): bsdinstall does not have a "Recover config.xml" option like the previous installer
Applied in changeset commit:e5aeaeb6a8b46c9532119285630f4e42d0e79b24. Jim Pingle
10:12 AM Todo #7708 (Resolved): bsdinstall does not have a "Recover config.xml" option like the previous installer
The new bsdinstall installer does not have an option to recover an existing config.xml from a previous installation.
...
Jim Pingle
09:56 AM Feature #7707 (Resolved): Captive Portal - Radius Time out configuration field
Captive Portal Radius Server connection function has a hardcoded timeout value of '3' there are instances where it i... Kanthamohan Jeyaraman

07/17/2017

12:48 PM Revision ee8e4e73: Prevent iOS auto-capitalization on username field
Steve Beaver
12:14 PM Revision 376e6f67: Use attribute rekey_enable as usual but optionally allow to set margintime if rekeying is not disabled
hamnur
11:59 AM Revision c21d913d: Change login page links to absolute paths
Steve Beaver
10:30 AM pfSense Packages Feature #7706 (Resolved): Add option to write certificate to the filesystem after renew
In some cases it would be handy to have the certificate data written out to the filesystem so that action scripts cou... Jim Pingle
05:24 AM Revision f72f2fac: add "very"
Stilez y
05:22 AM Revision 49bb19eb: slight further text/format improvement
Stilez y
05:11 AM Revision b0fc769a: Improve help text for promiscuous mode
"promiscuous mode" is often quoted but not always understood. Also its possible drawbacks (other than compatibility w... Stilez y

07/16/2017

10:04 AM Feature #7705 (Resolved): Support dynamic interface address for 1:1 NAT
Currently, in the 1:1 NAT UI, the "External subnet IP" field cannot be populated with options such as "WAN address" o... Riccardo Paolo Bestetti
09:42 AM Feature #7704 (Resolved): Destination port range "Any" in Port Forward UI doesn't work
If you set "Any" as the Destination port range for a Port Forward TCP or UDP entry, upon saving the new rule you get ... Riccardo Paolo Bestetti

07/15/2017

03:44 PM Bug #7702: Unattended Reboot Failing
OK, NP - thought it was best to capture ... I admit, not sure of the link between the forum and redmine. Sorry!
FY...
Russell Morris
03:38 PM Bug #7702 (Not a Bug): Unattended Reboot Failing
This is not happening on any systems here. Please do not open bug reports until the problems have been properly evalu... Jim Pingle
03:12 PM Bug #7702 (Not a Bug): Unattended Reboot Failing
Hi,
I have been seeing this in recent v2.4 builds, thinking it's something that should be fixed. When I reboot (or...
Russell Morris
03:39 PM Bug #7703 (Not a Bug): HW Acceleration in OpenVPN
This is a topic for a forum discussion, not a bug report. This is not a discussion or question/answer support platform. Jim Pingle
03:33 PM Bug #7703 (Not a Bug): HW Acceleration in OpenVPN
Hi,
This may be me, but just in case - likely good to log it, in case it's not.
Trying to use HW acceleration i...
Russell Morris
02:13 PM Bug #4695: TAP (OpenVPN) Traffic Blocked
OK, thanks! Wasn't sure if that state was equal to closed or not. Sorry for the extra "traffic". Russell Morris
02:10 PM Bug #4695: TAP (OpenVPN) Traffic Blocked
It's already closed: "Not a bug".
Thanks.
Jim Thompson
02:01 PM Bug #4695: TAP (OpenVPN) Traffic Blocked
Agreed, resolved - close this out (I don't know how, sorry!). Russell Morris
02:11 PM Bug #7701 (Rejected): Shell Command (daemon) Stops Other Services
Hi,
It may just be me (sorry if it is!), but similar to this thread ... I'm finding that some custom shell command...
Russell Morris
02:08 PM Bug #7700 (Closed): Port Forwarding Failing - with Alias
Hi,
As captured in this thread - it seems that recently Port Forwarding / NAT is broken, when using aliases (works...
Russell Morris
02:00 PM Bug #4696: OpenVPN Status / Client List
Working correctly in v2.4.0, so this one should be closed - I'd close it, not sure how ... :(.
Thanks!
Russell Morris
01:58 PM pfSense Packages Feature #7699 (New): OpenVPN Client Export - Default Gateway
Hi,
Just a thought, but - it would be nice to be able to set this option in Client Export, not just in the server ...
Russell Morris
07:41 AM Bug #7698 (Duplicate): Umlauts are no longer displayed properly
This has already been fixed, the 2.3.4-p1 release is about to come out and includes this correction.
https://doc.pfs...
Jim Pingle
06:13 AM Bug #7698 (Duplicate): Umlauts are no longer displayed properly
In the newest Version on the DHCP Status Page (/status_dhcp_leases.php) Umlauts in the Description Field are no longe... Flole Systems

07/14/2017

07:36 PM Revision 3c05905d: Bump PRODUCT_REVISION to 2.3.4-p1
Renato Botelho
06:48 PM Revision db3b3afb: Use an alternate method to stop unbound and fix #7326
(cherry picked from commit 782453b4dbb77e5bc97a43f56b95a006c5434d65)
(cherry picked from commit 67fea036201f5af338338...
Jim Pingle
06:47 PM Revision 67fea036: Use an alternate method to stop unbound and fix #7326
(cherry picked from commit 782453b4dbb77e5bc97a43f56b95a006c5434d65) Jim Pingle
06:46 PM Revision 782453b4: Use an alternate method to stop unbound and fix #7326
Jim Pingle
05:40 PM Bug #7692: andwidthd date on daily report incorrect.
I have created a report with bandwidthd here:
https://sourceforge.net/p/bandwidthd/bugs/50/
Anonymous
03:29 PM Bug #7692: andwidthd date on daily report incorrect.
I don't have it installed on either of my SG-1000s right now. It's possible there is an ARM-specific bug that affects... Jim Pingle
02:58 PM Bug #7692: andwidthd date on daily report incorrect.
It is not the browser cache, the date seems to change on every graph generation, and the software was installed just ... Anonymous
07:10 AM Bug #7692 (Not a Bug): andwidthd date on daily report incorrect.
Most likely something is cached in your browser. Try ctrl+F5 or shift+click reload. It is fine on all of my systems w... Jim Pingle
07:04 AM Bug #7692 (Not a Bug): andwidthd date on daily report incorrect.
Bandwidthd shows incorrect date (changing between graphs) in daily report.
See attachment for screenshot.
Env...
Anonymous
04:28 PM Bug #7697: NAT port forward rule using "WAN address" doesn't work as expected if router does not acquire a WAN address on startup
The pull-request was pulled yesterday. https://github.com/pfsense/pfsense/commit/40c09b6dadb04928dc9a279969193b620ff1... Pi Ba
03:58 PM Bug #7697 (Resolved): NAT port forward rule using "WAN address" doesn't work as expected if router does not acquire a WAN address on startup
This forum post:
https://forum.pfsense.org/index.php?topic=127585.msg733528#msg733528
Describes what I'm seeing:
<...
Andy Wang
03:25 PM Bug #4479: Firewall rules won't match GRE interface after applying IPSEC transport encryption on GRE tunnel
I don't see any target version on this bug. Is this being worked on? Any chances this could be fixed for 2.4? Jorge Albarenque
03:23 PM Todo #7689 (Resolved): bsdinstall does not automatically copy config.xml from USB drive like the previous installer
Looks good, multiple confirmations that it works. Jim Pingle
03:18 PM pfSense Packages Bug #7696 (Resolved): Telegraf Package Saving Incorrect Password
The contents of the password field are not being passed properly to the telegraf.conf file. The password is being en... Galen POSPISIL
02:59 PM Bug #6529: dhcp6c fails to start with track6 on a bridge interface
I am adding a sighting. My logs are as follows:
@Jul 12 06:23:21 pfSense dhcp6c[17300]: /var/etc/dhcp6c_wan.conf:13 ...
Mathew Keith
02:00 PM Bug #7326 (Feedback): Unbound fails to start during rc.wanipchange when using large enough dns lists
Applied in changeset commit:782453b4dbb77e5bc97a43f56b95a006c5434d65. Jim Pingle
01:57 PM Revision 7505efe7: If a client address is in the webConfiguratorlockout table, do not allow them to access the GUI. Print an error and kill their states. Ticket #7693
Extra check to be sure that an existing open state cannot bypass lockout controls.
(cherry picked from commit cc9b0f...
Jim Pingle
01:57 PM Revision f0da1eda: If a client address is in the webConfiguratorlockout table, do not allow them to access the GUI. Print an error and kill their states. Ticket #7693
Extra check to be sure that an existing open state cannot bypass lockout controls.
(cherry picked from commit cc9b0f...
Jim Pingle
01:55 PM Revision cc9b0f76: If a client address is in the webConfiguratorlockout table, do not allow them to access the GUI. Print an error and kill their states. Ticket #7693
Extra check to be sure that an existing open state cannot bypass lockout controls. Jim Pingle
01:54 PM Bug #7693 (Feedback): Brute force protection does not kill states, so additional login attemps may be possible in some cases
Moving the sshlockout portion to #7695 Jim Pingle
10:29 AM Bug #7693: Brute force protection does not kill states, so additional login attemps may be possible in some cases
GUI portion is done. It also kills states if someone tries to access the GUI while in the table, so if it isn't feasi... Jim Pingle
07:46 AM Bug #7693 (Resolved): Brute force protection does not kill states, so additional login attemps may be possible in some cases
The way that browsers and ssh clients work, it may be possible to exceed brute force protection limits enforced by ss... Jim Pingle
10:44 AM Revision 9d472f01: Fix indent of if-block
hamnur
10:36 AM Revision 7683e057: Merge branch 'master' of https://github.com/hamnur/pfsense into HEAD
hamnur
10:29 AM Revision af729f53: Check if margintime is numeric and smaller than P1 lifetime
hamnur
09:58 AM Revision e18ddb38: Hide margintime if rekeying is disabled
hamnur
12:17 AM Revision 47914246: Fix typo
(cherry picked from commit 2c3b9ac554cc3940962e7f9b1799857583c394ab)
(cherry picked from commit 930914fd813130b0d1bd8...
Jim Pingle
12:17 AM Revision 930914fd: Fix typo
(cherry picked from commit 2c3b9ac554cc3940962e7f9b1799857583c394ab) Jim Pingle
12:17 AM Revision 2c3b9ac5: Fix typo
Jim Pingle

07/13/2017

07:52 PM Revision 725aee3f: Trafficshaper, show interface names for disabled interfaces, dont just show a kinda 'empty' spot..
Pi Ba
07:49 PM Revision f6cf3687: dns, allow deleting last row for "Additional Names for this Host"
Pi Ba
07:06 PM Revision 1fdecbe6: cron, fix job removal by index splice and write valid schedules for ramdrive backups
(cherry picked from commit ce3371fe969733c92cd91fe31d2acb69fc877986) Pi Ba
07:05 PM Revision aeb0e915: cron, dont write_config() when nothing changed.
Pi Ba
06:59 PM Revision ea7b8b00: Merge pull request #3771 from PiBa-NL/20170701-cron-fix
Renato Botelho
06:58 PM Revision bef8ce51: bootup, change message to "Checking config backups consistency..." to tell whats taking time, as there is usually little to cleanup involved
(cherry picked from commit c2530487978f68c46c663fee9c9049479f267925) Pi Ba
06:58 PM Revision d991f97b: Merge pull request #3772 from PiBa-NL/20170703-boot-config-check-message
Renato Botelho
06:58 PM Revision 04cd314b: nat, portforwards should not make up a new destination information when a configured dhcp interface does not currently have an address.
fixes: https://forum.pfsense.org/index.php?topic=127585.msg733528#msg733528
(cherry picked from commit 5a8a8bbea33ec2...
Pi Ba
06:56 PM Revision 40c09b6d: Merge pull request #3782 from PiBa-NL/20170712-nat-configure-skip-no-dest
Renato Botelho
06:09 PM pfSense Packages Feature #7691 (New): Allow for custom icap services for squid
We would like to integrate additional icap services into the pfsense squid configuration, but there is no way add the... Orion Poplawski
05:58 PM Revision 324bbc3f: Restructure how unbound zone data is written to fix processing of "redirect" zone entries. Fixes #7690
Also corrects some other misc issues for formatting of zone data.
While here, add an option, not exposed in the GUI, ...
Jim Pingle
05:58 PM Revision 021332fa: Restructure how unbound zone data is written to fix processing of "redirect" zone entries. Fixes #7690
Also corrects some other misc issues for formatting of zone data.
While here, add an option, not exposed in the GUI, ...
Jim Pingle
04:37 PM Revision 4541f84d: Restructure how unbound zone data is written to fix processing of "redirect" zone entries. Fixes #7690
Also corrects some other misc issues for formatting of zone data.
While here, add an option, not exposed in the GUI, ...
Jim Pingle
02:58 PM Bug #4031: Notifications mail bomb in some gateway failure circumstances
This could help quite a bit imho :) https://github.com/pfsense/pfsense/pull/3768 Pi Ba
01:32 PM Bug #7690 (Resolved): System Domain Local Zone Type option Redirect is broken
Works Renato Botelho
01:10 PM Bug #7690 (Feedback): System Domain Local Zone Type option Redirect is broken
Applied in changeset commit:021332fa29f0c08bff833ce1c7ddcb9ac9a769b1. Jim Pingle
11:50 AM Bug #7690 (Confirmed): System Domain Local Zone Type option Redirect is broken
Still needs the fix ported to 2.3.x, it did not cherry-pick cleanly. Jim Pingle
11:50 AM Bug #7690 (Feedback): System Domain Local Zone Type option Redirect is broken
Applied in changeset commit:4541f84d12c86775022b0e49d527d6f4f9a6911f. Jim Pingle
11:50 AM Bug #6318: IPsec dashboard widget causes GUI failure
I think this bug's priority should be raised since it also breaks openvpn functionality. Marcio Merlone
07:14 AM Bug #5319: Error message "No config named" in charon daemon
This bug is also present in 2.3.4, I have to kill the charon process every 2-3 days to keep the problem from appearing. Robert Olofsson

07/12/2017

08:16 PM Revision 5a8a8bbe: nat, portforwards should not make up a new destination information when a configured dhcp interface does not currently have an address.
fixes: https://forum.pfsense.org/index.php?topic=127585.msg733528#msg733528 Pi Ba
02:46 PM Bug #7690 (Resolved): System Domain Local Zone Type option Redirect is broken
If user chose option 'Redirect' on 'System Domain Local Zone Type' in services_unbound.php unbound doesn't start with... Renato Botelho
01:19 PM Todo #7689 (Feedback): bsdinstall does not automatically copy config.xml from USB drive like the previous installer
Change committed to freebsd-src repo, should show up in snapshots soon. Jim Pingle
01:14 PM Todo #7689 (Closed): bsdinstall does not automatically copy config.xml from USB drive like the previous installer
Feature is described here:
https://doc.pfsense.org/index.php/Automatically_Restore_During_Install
Basically: Loca...
Jim Pingle
12:46 PM Bug #7615: User / Group Privileges for the "Status: Monitoring" page.
Ok. It appears that when the package "Status_Traffic_Totals" is installed it replaces "Status: Monitoring" in the use... Landon Wubbels
07:53 AM pfSense Packages Feature #7189: Letsencrypt acme sync in HA environment
Relevant Commits:
2.4:
https://github.com/pfsense/FreeBSD-ports/commit/119d687658b46a0310a481c22f5a435e5de9625f
...
Jim Pingle
07:51 AM pfSense Packages Feature #7189 (Resolved): Letsencrypt acme sync in HA environment
Works on both 2.4 and 2.3.x now. Jim Pingle

07/11/2017

04:52 PM Bug #7604: Bug #6594 is not resolved: Waiting for Internet connection to update pkg metadata and finish package reinstallation
A quick workaround:
Interrupt update process with ctrl+c and enter to a shell. Then:
vi /usr/local/etc/pkg/repos/...
Guillem Parera
03:59 PM pfSense Packages Feature #7189 (Feedback): Letsencrypt acme sync in HA environment
Pushed a fix for 2.3.x versions now. Jim Pingle
03:29 PM pfSense Packages Feature #7189 (Assigned): Letsencrypt acme sync in HA environment
Well, it works on 2.4, needs some adjustments for 2.3.x yet. Jim Pingle
03:11 PM pfSense Packages Feature #7189 (Feedback): Letsencrypt acme sync in HA environment
I just pushed a new feature to the ACME package, it can now send service restart commands via XMLRPC using the system... Jim Pingle
12:50 PM Bug #7146: install_cron_job() causes inexplicable issues when saving package configuration
I went through and tried a few of the packages and some did need the write, others did not. I didn't test the whole l... Jim Pingle
12:11 PM Feature #7688 (Rejected): AutoConfigBackup - Info Icon - username only
It would be beneficial to include a hover icon (info tip) on the AutoConfigBackup setup page that informs users to us... Clinton Cory
07:45 AM Bug #7675 (Resolved): Remove MSS clamping exclusions on pppoe, l2tp, pptp
Thanks for testing!
Jim Pingle
07:43 AM Bug #7675: Remove MSS clamping exclusions on pppoe, l2tp, pptp
I have updated to the last few snapshots and I have not had any issues with the MSS clamping being set on the PPPOE c... Anonymous
07:11 AM Bug #7687 (Not a Bug): File permissions to open for /var/etc/mpd_wan.conf
It's also in /conf/config.xml where it can be read by anyone on the box.
At the moment, it's all a part of how the...
Jim Pingle
05:11 AM Bug #7687 (Not a Bug): File permissions to open for /var/etc/mpd_wan.conf
Considering this file has the clear text password to the ISP account it needs to have something less than world reada... Andrew Spurrier

07/10/2017

04:15 PM Revision 02068d31: Improve the way the auth server list is generated and account for a key being removed from the array when deleting. Fixes #7682
(cherry picked from commit fa628b1a15a1c03343caa2735e09de291ae4e382) Jim Pingle
04:15 PM Revision fa628b1a: Improve the way the auth server list is generated and account for a key being removed from the array when deleting. Fixes #7682
Jim Pingle
04:12 PM Revision 4e4cac0d: Improve the way the auth server list is generated and account for a key being removed from the array when deleting. Fixes #7682
Jim Pingle
03:34 PM Bug #7682 (Resolved): system_authservers delete UI bugs
Works. Jim Pingle
11:30 AM Bug #7682 (Feedback): system_authservers delete UI bugs
Applied in changeset commit:4e4cac0dd53afcf26aa2b523dc16916730d92133. Jim Pingle
08:35 AM Bug #7682: system_authservers delete UI bugs
The fix seems to work but it could be better/simpler, see my comments on PR 3780. Jim Pingle
03:24 PM Bug #7685 (Resolved): OpenVPN Auth Digest Algorithm list contains entries that are functionally identical and thus redundant
Fixed.
Only actual digest algorithms show now, and not their aliases. Configurations that referenced an alias are ...
Jim Pingle
09:40 AM Bug #7685 (Feedback): OpenVPN Auth Digest Algorithm list contains entries that are functionally identical and thus redundant
I pushed a fix for this in commit:f49ef559060ec8cad5c7a3a548d509cf08b5549b but forgot to put this ticket number on th... Jim Pingle
08:52 AM Bug #7685: OpenVPN Auth Digest Algorithm list contains entries that are functionally identical and thus redundant
This also appears to be confirmed by @openssl list-message-digest-algorithms@, which lists which names/aliases map to... Jim Pingle
07:37 AM Bug #7685 (Resolved): OpenVPN Auth Digest Algorithm list contains entries that are functionally identical and thus redundant
The way "openvpn --show-digests" works it ends up listing several algorithms that are functionally equivalent but som... Jim Pingle
02:36 PM Revision f49ef559: Fix OpenVPN Auth Digest Algorithm selection so it does not use duplicate/alias names in the list, and fix existing entries on upgrade so they use the actual digest name and not an alias.
Jim Pingle
09:44 AM pfSense Packages Bug #7681: OpenVPN client export utility - Exporting Android inline configuration can include incorrect client auth method in .ovpn file
Thank you Jim! Makes sense. David Nuzik
07:37 AM pfSense Packages Bug #7681: OpenVPN client export utility - Exporting Android inline configuration can include incorrect client auth method in .ovpn file
I made a different issue entry for the actual underlying problem here: https://redmine.pfsense.org/issues/7685 Jim Pingle
07:36 AM pfSense Packages Bug #7681 (Not a Bug): OpenVPN client export utility - Exporting Android inline configuration can include incorrect client auth method in .ovpn file
It does appear that they are the same, but different versions of OpenSSL or different libraries that are OpenSSL-like... Jim Pingle
08:29 AM pfSense Packages Feature #7686: Add option in HAProxy to configure SSL defaults based on the Mozilla SSL Configuration Generator
oops, misspelled configure in the subject line Corey Boyle
08:27 AM pfSense Packages Feature #7686 (New): Add option in HAProxy to configure SSL defaults based on the Mozilla SSL Configuration Generator
Would be nice to have "Modern | Intermediate | Old" options in the configuration of HAProxy for SSL cipher suites, ba... Corey Boyle
06:25 AM Bug #6559: OpenVPN 'mode server' directive missing
If it's remote access, you need to give it a tunnel network. It is not valid for remote access without a tunnel netwo... Jim Pingle
06:04 AM Bug #6559: OpenVPN 'mode server' directive missing
Jim Pingle wrote:
> or you have to setup bridging, etc.
>
> It is only doing what it is told (or not told, as the...
Geoff Jones

07/09/2017

08:05 PM Bug #7684: Web Configurator - IP address is cutoff in the Gateways widget
The gateway x.y.104.1 is the IP address of the router that is upstream from the pfSense WAN.
Dynamic DNS should set ...
Phillip Davis
08:04 PM Bug #7684: Web Configurator - IP address is cutoff in the Gateways widget
Jim Pingle wrote:

> They are not the same thing.
Oops. Where is the "embarassed" emoji when I need it?
Michael Woffenden
07:59 PM Bug #7684 (Rejected): Web Configurator - IP address is cutoff in the Gateways widget
One of those is your upstream ISP gateway (gateways widget)
The other is your firewall's own IP address (Dynamic D...
Jim Pingle
07:56 PM Bug #7684 (Rejected): Web Configurator - IP address is cutoff in the Gateways widget
I currently have an IP address that is XX.XX.XXX.XXX and in the Gateways widget the last 2 digits on the right are mi... Michael Woffenden
02:39 PM Revision 19be2fc2: Reduce complexity of checking whether system should be rebooted after RAM Disk option change.
Also fix the issue when RAM Disk option is changed, but there is an input error and thus on subsequent form submittin... Nazar Mokrynskyi

07/08/2017

10:50 PM pfSense Packages Feature #7683 (New): Splunk Universal Forwarder Package
It would be nice to have a Splunk Universal Forwarder package so we can send logs and other monitor capable files e.g... Dennis Chow
10:01 PM Bug #7682: system_authservers delete UI bugs
master: https://github.com/pfsense/pfsense/pull/3780
RELENG_2_3:https://github.com/pfsense/pfsense/pull/3778
RELENG...
Phillip Davis
09:46 PM Bug #7682 (Resolved): system_authservers delete UI bugs
1) In system_authservers, have a list of at least 3 extra auth servers defined, and Local Database will be at the end... Phillip Davis
07:40 PM pfSense Packages Bug #7681 (Not a Bug): OpenVPN client export utility - Exporting Android inline configuration can include incorrect client auth method in .ovpn file
Intro:
Hello this is my first bug entry. I hope I have done a good job reporting the specifics of what I believe to ...
David Nuzik

07/07/2017

09:07 PM Revision 2504e3f1: Fix CA reference so serial increases properly. Remove variable for feature that didn't work out. Ticket #7527
Jim Pingle
03:46 PM Bug #7206 (Resolved): Authentication Method Used in Bug 6751 Removed by Amazon
PR was merged months ago, no recent complaints. Should be OK.
https://github.com/pfsense/pfsense/pull/3608
Jim Pingle
03:45 PM Bug #7213: Hyper-V install, no disk found
That's something that will need to be addressed by FreeBSD. If it's fixed in 11-STABLE, perhaps our next release afte... Jim Pingle
03:20 PM Bug #4696 (Not a Bug): OpenVPN Status / Client List
No additional confirmation or responses in several years/versions, and it wasn't clear it was ever a problem to begin... Jim Pingle
03:18 PM Bug #7446 (Resolved): RFC2136 Dynamic DNS needs local directive so updates are sourced correctly
Jim Pingle
03:14 PM pfSense Packages Bug #7263 (Resolved): FreeRADIUS - complete lack of input validation
Seems to be good. Jim Pingle
03:13 PM Bug #6967 (Resolved): DH Groups 22, 23, 24 missing from Phase 2 selection GUI
Jim Pingle
03:12 PM Bug #7295 (Resolved): RFC2136 not updating at boot time
It's working here as well, no problems with RFC2136 at boot on 2.4. Jim Pingle
03:11 PM Bug #6758 (Resolved): 2 x Crash with "PHP Fatal error: Call to undefined function pfSense_interface_listget() in /etc/inc/interfaces.inc on line 80"
The PHP extensions setup has been completely changed since this report, it's not valid any longer. Jim Pingle
03:11 PM Bug #6629 (Resolved): Can't update to "update" update (e.g. 2.3.1_5)
Lots of upgrade issues have been fixed since this report. Most anything left is either cosmetic, caused by network co... Jim Pingle
03:09 PM Bug #6559 (Not a Bug): OpenVPN 'mode server' directive missing
No response or confirmation from anyone else seeing the issue on recent versions.
As stated before, it isn't that ...
Jim Pingle
03:07 PM Bug #4237 (Closed): Error "macro IPsec not defined" once after firmware upgrade
No recent reports on supported versions, unless this can be reproduced on 2.4 it appears to be solved. Jim Pingle
03:04 PM Bug #5741 (Closed): IPs from Random Aliases Lists Are Added to Routes Table
No response or confirmation from anyone else seeing the issue on recent versions. Jim Pingle
03:03 PM Bug #4113 (Resolved): multiple instances of /var/db/rrd/updaterrd.sh
No response or confirmation from anyone else seeing the issue on recent versions. Jim Pingle
02:39 PM pfSense Packages Bug #7237 (Resolved): ACME - first table row on certs tab does not autoexpand the fields
This has been fixed for a while now Jim Pingle
02:29 PM Bug #7667 (Resolved): Calls to unbound-control are missing configuration path so they fail
Jim Pingle
02:29 PM Bug #7649 (Resolved): pkg_edit.php - The last row cannot be deleted with ntopng.xml
Jim Pingle
01:43 PM Bug #7326: Unbound fails to start during rc.wanipchange when using large enough dns lists
Here is a patch to try, for those who had problems with the previous commit. Jim Pingle
01:28 PM Bug #7326: Unbound fails to start during rc.wanipchange when using large enough dns lists
BBcan177 . wrote:
> I would recommend the following command (And also for the other Unbound start/reload etc...)
> ...
Jim Pingle
01:11 PM Bug #7677 (Resolved): Cert manager not creating server cert
Fixed Jim Pingle
01:10 PM Feature #7527 (Resolved): Sign CSRs - subjectAlternateNames
Works Jim Pingle
10:51 AM Bug #7680: Wrong IP address being entered against pfSense host name on a multi-interface system in /etc/hosts
Jim Pingle wrote:
> There isn't any viable method to override that and adding one would be a lot of work for little ...
tqwqllrm tqwqllrm
10:27 AM Bug #7680 (Needs Patch): Wrong IP address being entered against pfSense host name on a multi-interface system in /etc/hosts
There isn't any viable method to override that and adding one would be a lot of work for little benefit. If someone w... Jim Pingle
10:23 AM Bug #7680 (Needs Patch): Wrong IP address being entered against pfSense host name on a multi-interface system in /etc/hosts
I'm running pfSense 2.3.4 and it has multiple interfaces. It chooses one of its IP address and enters it in /etc/hos... tqwqllrm tqwqllrm
09:56 AM Feature #6038: Add ability to configure which interface is chosen for defining hostname IP in /etc/hosts
Nicki Messerschmidt wrote:
> I stumbled over this problem also. In my case I have several LAN interfaces and the wro...
tqwqllrm tqwqllrm
07:14 AM Bug #7679: Dynamic DNS don't select GW, only default gateway from kernel
It's ok!
Thank you =)
Nielsen Oliveira
07:07 AM Bug #7679 (Rejected): Dynamic DNS don't select GW, only default gateway from kernel
Please post on the forum for assistance with your Dynamic DNS problem. I, and many others, use Dynamic DNS with multi... Jim Pingle
06:55 AM Bug #7679 (Rejected): Dynamic DNS don't select GW, only default gateway from kernel
Acredito que seja um bug, pois testei várias formas e realmente ele só assume o GW do kernel, quando utilizo tanto o ... Nielsen Oliveira
06:14 AM Bug #7678 (Duplicate): Bad HTML-encoding on the status_dhcp_leases.php page
This has already been fixed in 2.3.4-p1 (which is not yet released) and snapshot images.
https://doc.pfsense.org/i...
Jim Pingle
12:38 AM Bug #7678 (Duplicate): Bad HTML-encoding on the status_dhcp_leases.php page
It seems that the 2.3.4 release reintroduced an old bug, see #6079. The description column currently shows HTML entit... Chris Vanclercq

07/06/2017

06:27 PM Revision 5764c363: Stop using pecl-ssh2
Renato Botelho
06:27 PM Revision 7da9f1e5: Stop using pecl-ssh2
Renato Botelho
06:23 PM Revision b91d55c3: Deprecate pfSense freeradius2 package in favor of freeradius3
Renato Botelho
06:23 PM Revision 6761daa4: Deprecate pfSense freeradius2 package in favor of freeradius3
Renato Botelho
05:47 PM Revision 7db12011: Add another possible CSR Armor string when validating. Ticket #7383
Jim Pingle
05:30 PM Revision 0c82b8c2: Restructure how certificate types and SANs are handled in the cert manager when making a Cert/CSR/Signing, so each section can properly use the controls without duplicating. It is now possible to add SANs and EKUs to certificates when signing using the certificate manager. Fixes #7527 and also Fixes #7677
NOTE: Attributes such as SANs and KU/EKU cannot be copied from a CSR when signing due to a deficiency in OpenSSL's x5... Jim Pingle
04:57 PM Bug #7326: Unbound fails to start during rc.wanipchange when using large enough dns lists
Instead of using this stop command
mwexec("echo '/usr/local/sbin/unbound-control stop' | /usr/bin/su -m unboun...
BBcan177 .
07:33 AM Bug #7326 (Assigned): Unbound fails to start during rc.wanipchange when using large enough dns lists
Jim Pingle
07:30 AM Bug #7326 (Feedback): Unbound fails to start during rc.wanipchange when using large enough dns lists
Applied in changeset commit:6e094e04f7d9634c7151bd9aa68ad93c71584d80. Jim Pingle
07:22 AM Bug #7326 (Assigned): Unbound fails to start during rc.wanipchange when using large enough dns lists
Several complaints of unbound not starting/stopping correctly after that last patch was added, so I backed it out for... Jim Pingle
02:10 PM Feature #1801 (Rejected): Intermediate SSL certs box
Just import intermediates into the CAs tab directly. See #2800 Jim Pingle
02:07 PM pfSense Packages Bug #4756 (Not a Bug): OpenVPN Client Export fails when using "real" certificate
It works fine if you import the chain, see #2800, which would include the case of a public CA (which should still nev... Jim Pingle
02:04 PM Bug #5317 (Not a Bug): CSR signed certificates shows issuer as external
Import the CA cert (cert only), any intermediate CA certs, and the signed cert. It will pick up the issuer correctly ... Jim Pingle
02:00 PM pfSense Packages Bug #7170 (Resolved): FreeRADIUS built-in certificate manager defaults to MD5 (!!!), no support for SHA2
This has all been removed from FreeRADIUS. Cert handling in FreeRADIUS is 100% done in the Cert Manager now on 2.3.4 ... Jim Pingle
01:48 PM Feature #7666 (Resolved): Adding SAN DNS:username to User Certificates that are created via User Manager the same way as it is done via Cert. Manager
Works fine now. Jim Pingle
01:34 PM Feature #7527: Sign CSRs - subjectAlternateNames
wow. Great. I'll try this out first thing tomorrow morning. Thank you very much :-) Philip Hofstetter
12:40 PM Feature #7527 (Feedback): Sign CSRs - subjectAlternateNames
Applied in changeset commit:0c82b8c2a77bba6b2b3ab42a880c0e478ebc70f6. Jim Pingle
12:35 PM Feature #7527 (Assigned): Sign CSRs - subjectAlternateNames
Jim Pingle
12:51 PM Feature #7383: system_certmanager.php?act=new: Add new select option to sign a CSR
Also, as of commit:0c82b8c2a77bba6b2b3ab42a880c0e478ebc70f6 I have changed how this operates slightly, there were a c... Jim Pingle
12:50 PM Feature #7383: system_certmanager.php?act=new: Add new select option to sign a CSR
Larry Westfall wrote:
> Below is the request:
> -----BEGIN NEW CERTIFICATE REQUEST-----
That's the problem, it h...
Jim Pingle
12:40 PM Bug #7677 (Feedback): Cert manager not creating server cert
Applied in changeset commit:0c82b8c2a77bba6b2b3ab42a880c0e478ebc70f6. Jim Pingle
08:31 AM Bug #7677 (Assigned): Cert manager not creating server cert
I'm in the middle of some certificate work. It should have been in an OK state when I left it yesterday but it's poss... Jim Pingle
08:24 AM Bug #7677 (Resolved): Cert manager not creating server cert
Current snap
2.4.0-BETA (amd64)
built on Thu Jul 06 07:22:07 CDT 2017
FreeBSD 11.0-RELEASE-p10
Cert Manager not...
JohnPoz _
12:27 PM Revision eb3435be: Removed MSS clamping exclusions
Robbert Rijkse
12:27 PM Revision b2e4bb17: Removed MSS clamping exclusions
(cherry picked from commit 53c26adecad735f7a015466dbbcba3f22655a902) Robbert Rijkse
12:27 PM Revision 2f55e551: Removed MSS clamping exclusions
(cherry picked from commit 53c26adecad735f7a015466dbbcba3f22655a902) Robbert Rijkse
12:21 PM Revision 53e138c0: Several complaints of unbound problems after commiting, so back this out. Revert "Change the way unbound is stopped when the process is being restarted, to give the old process enough time to exit cleanly. Fixes #7326"
This reverts commit 863804a917987ea10993433c84399b5711c3c352. Jim Pingle
12:21 PM Revision c59b2bc3: Several complaints of unbound problems after commiting, so back this out. Revert "Change the way unbound is stopped when the process is being restarted, to give the old process enough time to exit cleanly. Fixes #7326"
This reverts commit 0577d9df462063bb3d26f0805c1e06fbdb359157. Jim Pingle
12:20 PM Revision 6e094e04: Several complaints of unbound problems after commiting, so back this out. Revert "Change the way unbound is stopped when the process is being restarted, to give the old process enough time to exit cleanly. Fixes #7326"
This reverts commit 38d110824c87ff60c6289c0432d55009586ceee4. Jim Pingle
08:22 AM Bug #7676 (Rejected): L2TP Settings not retained
Please discuss this on the forum for help diagnosing your issue. That is not a general problem, and more information ... Jim Pingle
08:13 AM Bug #7676 (Rejected): L2TP Settings not retained
Trying to configure L2TP VPN Server for a small company, we were able to login through L2TP but when checking again o... Henry Jesus Jr. Lastimosa
07:28 AM Bug #7675 (Feedback): Remove MSS clamping exclusions on pppoe, l2tp, pptp
PR Merged Jim Pingle

07/05/2017

08:41 PM Revision 282b6c66: Add the ability to set certificate type and SAN attributes in a CSR. Ticket #7527
TODO: They are not carried over after signing in the GUI Jim Pingle
07:12 PM Bug #6099: igmpproxy does not recognize upstream interface
Diogo Quintela wrote:
> Rai Wol wrote:
> > Can someone confirm its working in 2.4?
> >
> > Doesn't stop after 3...
J L
07:07 PM Revision a3507259: Fix missing line from openssl.cnf
(cherry picked from commit c369871083ee6a5be958129df5457c8e952aa9e2) Jim Pingle
07:06 PM Revision c3698710: Fix missing line from openssl.cnf
Jim Pingle
07:03 PM Revision 5c985ed2: Fix missing line from openssl.cnf
Jim Pingle
06:12 PM Bug #7675: Remove MSS clamping exclusions on pppoe, l2tp, pptp
Pull request created to fix this:
https://github.com/pfsense/pfsense/pull/3777
Anonymous
05:43 PM Bug #7675 (Resolved): Remove MSS clamping exclusions on pppoe, l2tp, pptp
As per https://forum.pfsense.org/index.php?topic=132918.0
Creating an issue to track removing the exclusions setup...
Anonymous
05:53 PM Revision 276f8ce0: Do not ship .po files on images
Renato Botelho
05:49 PM Revision ba47d6fd: Update translation files
Renato Botelho
05:49 PM Revision 1d8a0e66: Regenerate pot
Renato Botelho
05:30 PM Revision b767fe6c: Add the username as the first SAN when making a user certificate from the user manager creation screen. Fixes #7666
Jim Pingle
05:30 PM Revision 2e1809dd: Fix some additional cases for CN->SAN handling, and move some code to a function to avoid duplication for other pending uses. Ticket #7666
Jim Pingle
04:56 PM Revision 2485e772: Include User Agent information when update bogons list
Renato Botelho
04:56 PM Revision 12e31e87: Include User Agent information when update bogons list
Renato Botelho
04:56 PM Revision 7fbb45be: Include User Agent information when update bogons list
Renato Botelho
04:27 PM Revision 6cc74faa: Remove extra spaces from User Agent
Renato Botelho
04:27 PM Revision 0d3d86c8: Remove extra spaces from User Agent
Renato Botelho
04:27 PM Revision ba7d82b0: Remove extra spaces from User Agent
Renato Botelho
04:22 PM Revision 41744bf9: Send uniqueid instead of UUID on user-agent
Renato Botelho
04:22 PM Revision ea8abb80: Declare user_agent variable in the function it's used
Renato Botelho
04:22 PM Revision e927083e: Move uniqueid read to a function system_get_uniqueid()
Renato Botelho
04:22 PM Revision 48600bc6: Send uniqueid instead of UUID on user-agent
Renato Botelho
04:22 PM Revision 7928e419: Declare user_agent variable in the function it's used
Renato Botelho
04:21 PM Revision 2bf67a6f: Send uniqueid instead of UUID on user-agent
Renato Botelho
04:05 PM Revision d49ad309: Declare user_agent variable in the function it's used
Renato Botelho
04:00 PM Revision cb61e2d8: Move uniqueid read to a function system_get_uniqueid()
Renato Botelho
03:59 PM Revision 2f8793b7: Move uniqueid read to a function system_get_uniqueid()
Renato Botelho
02:55 PM pfSense Packages Bug #7674 (Resolved): Issue Downloading Snort Alert Log Download
I have found that I am no longer able to download the Alert Logs from the snort_alerts.php page. I have attempted di... Ryan Eckenrode
12:40 PM Feature #7666 (Feedback): Adding SAN DNS:username to User Certificates that are created via User Manager the same way as it is done via Cert. Manager
Applied in changeset commit:b767fe6cdf7977916d2f245ea529f84f7e0d1f30. Jim Pingle
11:02 AM Bug #7673 (Not a Bug): multi wan 0.0.0.0
Hi,
Once it detects that there is the same ip address multiple times whenever you save something, the web server l...
Christoffer Öhman

07/04/2017

02:40 PM Bug #7672 (Rejected): Enabling DNS Resolver returns erorr
Please discuss the problem on the forum to diagnose your problem and identify any potential bugs. If there is a repea... Jim Pingle
01:33 PM Bug #7672 (Rejected): Enabling DNS Resolver returns erorr
Hi
I am getting this error when I try to enable DNS Resolver. I haven't been using the DNS Resolver before because...
Tino Zidore
02:57 AM Revision 3666d731: Add user option to sort interface names RELENG_2_3
Signed-off-by: Phil Davis <phil@jankaritech.com> Phil Davis

07/03/2017

10:24 PM Revision 7c6f38e4: ipsec, prevent simultaneous/repeated calling of vpn_ipsec_configure() by /etc/rc.newipsecdns
Pi Ba
10:04 PM Feature #6753: Interfaces list order not consistent
It works in master 2.4, but it never got backported to RELENG_2_3 or RELENG_2_3_4.
This was the PR in master: https:...
Phillip Davis
12:04 PM Feature #6753: Interfaces list order not consistent
Thank you guys for taking this into account. It works well, much better to use now!
May I ask for one last thing? Th...
robi robi
08:15 PM Revision c2530487: bootup, change message to "Checking config backups consistency..." to tell whats taking time, as there is usually little to cleanup involved
Pi Ba
11:19 AM Feature #7671: Gateway Monitoring Via Custom Script or Telnet.
many ISPs in India also do a similar thing and etisalat in UAE do a similar thing, if the bill isnt paid by the 15th ... Bipin Chandra
11:08 AM Feature #7671 (New): Gateway Monitoring Via Custom Script or Telnet.
It would be very helpful to have the ability to monitor gateways via a custom script or telnet. ISPs are beginning to... Bridgetowermedia IT
 

Also available in: Atom