Project

General

Profile

Activity

From 11/20/2017 to 12/19/2017

12/19/2017

09:51 PM Bug #8222: When trying to add another OPT interface, it's replacing the last existing one
Using
2.4.3-DEVELOPMENT (amd64)
built on Tue Dec 19 18:22:48 CST 2017
FreeBSD 11.1-RELEASE-p6
I can say ...
Alexandre Paradis
09:51 PM Bug #8223: Cannot delete vlan, I get redirected to an empty page
Using
2.4.3-DEVELOPMENT (amd64)
built on Tue Dec 19 18:22:48 CST 2017
FreeBSD 11.1-RELEASE-p6
I can say ...
Alexandre Paradis
05:56 PM Bug #8206 (Resolved): Hosted Openappid rules - syntax error
Jim Pingle
05:07 PM Bug #8206: Hosted Openappid rules - syntax error
Renato Botelho wrote:
> Should be fixed now
Sorry for the delayed confirmation but, as I'm sure you know by now, ...
Lance Fogle
11:17 AM Bug #6447: Interface allows dynamic gateway to be deleted
this is rather confusing - i stumbled above some "_dhcp" postfixed gateway entry and was not able to get rid of it - ... Roland Kletzing
05:49 AM Bug #8226 (Resolved): Pass-through MAC automatic additions adds duplicate
When a user has multiple browser tabs open before logging into the captive portal. Each 'll show the captive portal l... Sander Naudts
04:14 AM Feature #8168: strongswan dhcp option
Lars Pedersen wrote:
> Would be nice to have the dhcp plugin for strongswan in pfsense. This feature could be useful...
Lars Pedersen

12/18/2017

05:28 PM Revision 11f89751: allow for timezones with half hour increments i.e. asia/kolkata
Stephen Jones
05:23 PM Revision 5946477f: Fixed #8129 Updated to show timezones that have half hour increments i.e. asia/kolkata
Stephen Jones
01:55 PM Revision e34c96a3: Revert "Merge pull request #3868 from loonylion/master"
Caused issues reported in https://redmine.pfsense.org/issues/8223
This reverts commit 74c55258b21ada7a542965c2470fbaa...
Steve Beaver
01:39 PM Revision 32edd5dd: Optimze ICMP description processing
Steve Beaver
01:31 PM Revision 609ef335: Fixes #8219
Escape single quotes when they arise from ICMP description translations Steve Beaver
11:30 AM Bug #8129 (Feedback): NTP Status -> Server time value incorrect for timezone Asia/Kolkata
Applied in changeset commit:5946477f65f0f7a20504833ac156419875ac2b2b. Anonymous
11:20 AM Bug #8165: Fragmented at source IPv6 packets (UDP + ICMP Ping) are not forwarded / v2.4.2 AMD64
Just realised the packet capture example was truncated by one character. Here's what it should look like:
16:56:5...
Mike Nichols
10:52 AM Bug #8222: When trying to add another OPT interface, it's replacing the last existing one
I have revered the OPT naming code to vanilla pfSense; if this bug still occurs it's caused by something else. Peter Schofield
08:00 AM Bug #8222 (Feedback): When trying to add another OPT interface, it's replacing the last existing one
This was likely a problem introduced during a recent pull request merge: https://github.com/pfsense/pfsense/pull/3868... Jim Pingle
10:52 AM Bug #8223: Cannot delete vlan, I get redirected to an empty page
This should now be fixed; I corrected the broken reference. Peter Schofield
08:07 AM Bug #8223 (Feedback): Cannot delete vlan, I get redirected to an empty page
Jim Pingle
07:56 AM Bug #8223: Cannot delete vlan, I get redirected to an empty page
PR reverted. Anonymous
07:49 AM Bug #8223: Cannot delete vlan, I get redirected to an empty page
Yes. let's back out that PR. Anonymous
07:09 AM Bug #8223 (New): Cannot delete vlan, I get redirected to an empty page
That page doesn't exist, but there is a reference to it: https://github.com/pfsense/pfsense/blob/master/src/usr/local... Jim Pingle
06:52 AM Bug #8223 (Closed): Cannot delete vlan, I get redirected to an empty page
Unable to reproduce
There is no interfaces_vlan_new_prof.php page in pfSense
Suggest you discuss on the forum.
Anonymous
10:09 AM Feature #7281: OpenVPN: Add support for IPv6 dynamic prefix selection
I'm actually using a ULA range for the IPv6 Tunnel Network, so that doesn't need to change, but the IPv6 Local networ... Corey Boyle
09:04 AM Feature #7281: OpenVPN: Add support for IPv6 dynamic prefix selection
I would love to see this as well. Corey Boyle
09:53 AM Bug #8003: IPsec weirdness with 2.4.1
I am also having similar problems on 2.4.2.
One end shows connected, the other end shows disconnected. And - the pfS...
Mitch Claborn
09:49 AM Bug #7420: ipsec status freezing
I am also having this problem with 2.4.2.
Command line doesn't help either:
swanctl --list-sas
connecting to ...
Mitch Claborn
09:47 AM Bug #8225 (Not a Bug): wrong gateway/monitor address for OpenVPN IPv6 gateway?
After configuring a remote access OVPN server, with IPv6 address for the tunnel network and the local network, the au... Corey Boyle
07:40 AM Bug #8219: No gateway groups on french language
Applied in changeset commit:609ef33537e10e6faef38bbbeb16e477384a4503. Anonymous
07:32 AM Bug #8219 (Feedback): No gateway groups on french language
Corrected by escaping single quote characters when they arise in ICMP descriptions. Anonymous

12/17/2017

09:55 PM pfSense Packages Feature #8224: Add "OU" field to FreeRADIUS page
Javier Ramirez wrote:
> FreeRADIUS will attempt to *compare* this cert (with an OU) to the details provided in FreeR...
Javier Ramirez
09:51 PM pfSense Packages Feature #8224 (New): Add "OU" field to FreeRADIUS page
It's possible to have FreeRADIUS validate the server/client cert against the CA. However, there's no place in the GUI... Javier Ramirez
10:11 AM Bug #8221 (Not a Bug): config xml downloads with incorrect creation date on macOS 10.13.
Definitely not anything in pfSense. There is nothing on the firewall that sets a date/time for the backup except for ... Jim Pingle
04:39 AM Bug #8221: config xml downloads with incorrect creation date on macOS 10.13.
I think this is actually a problem with the Synology NAS where I store my router XML files. Looks like they have a b... Ashley Harvey
12:29 AM Bug #8221 (Not a Bug): config xml downloads with incorrect creation date on macOS 10.13.
I haven't tested this thoroughly, but when downloading my config files, the date stamp is in the filename and is corr... Ashley Harvey
02:02 AM Bug #8223 (Resolved): Cannot delete vlan, I get redirected to an empty page
The page I get redirected is : https://192.168.5.2/interfaces_vlan_new_prof.php
404 Not Found
nginx
Using ...
Alexandre Paradis
01:59 AM Bug #8222 (Resolved): When trying to add another OPT interface, it's replacing the last existing one
Using
2.4.3-DEVELOPMENT (amd64)
built on Fri Dec 15 09:33:08 CST 2017
FreeBSD 11.1-RELEASE-p6
I cannot ...
Alexandre Paradis
12:44 AM Revision c56471a7: Fixes #7413: Some DHCPv6 leases are not displayed in the GUI
. Better handling/parsing of ISC dhcpv6 leases file and removal of unnecessary properties.
. Experimental Pools/failo...
Anders Lind

12/16/2017

09:46 PM Bug #8220 (Resolved): UI does not allow multiple MAC for same DHCP address
The UI does not allow multiple MAC addresses to be assigned the same DHCP address, even when using different hostname... Doug Fultz
07:41 PM Bug #7413: status_dhcpv6_leases.php: Some DHCPv6 leases are not displayed in the GUI
I have added a PR here: https://github.com/pfsense/pfsense/pull/3892
and updated https://forum.pfsense.org/index.php...
Anders Lind
05:41 PM Bug #8219 (Resolved): No gateway groups on french language
When in the french language is displayed there is no gateway group options on firewall interface rules. Chris Macmahon
11:11 AM Bug #8217: Traffic Graph widget can not handle more than 4 interfaces
Ok, it was a bug in the javascript file traffic-graphs.js line #332
I just had to hide the widget (-) .. reload t...
Mubarak Alrashidi
10:04 AM Bug #8217 (Resolved): Traffic Graph widget can not handle more than 4 interfaces
If there is more than 4 (four) interfaces, the Traffic Graph widget won't show the statistics graph. Mubarak Alrashidi
10:12 AM Bug #8218 (Duplicate): Changing an interface name will break the manual created gateway-group
If a gateway-group is created. then change the name of an interface which is a member of that gateway-group. will bre... Mubarak Alrashidi
07:54 AM pfSense Packages Feature #8216 (New): Add prometheus output for telegraf
Please consider adding prometheus output as output choice for telegraf Nicolas Marot
07:39 AM Bug #8215: rcvif is NULL in ip6_forward - possible regression in 2.4
I'd like to build a replacement kernel with the change so we can get our VPN working again. Is there a specific guide... Lih Wei Chia
07:37 AM Bug #8215 (Closed): rcvif is NULL in ip6_forward - possible regression in 2.4
[Bug re-created after previous one was accidentally closed by staff]
Hi, I'm facing random crashes after upgrading...
Lih Wei Chia
04:31 AM pfSense Packages Bug #8214 (Resolved): HOME_NET includes all locally attached Networks
When selecting a passlist to define the HOME_NET the HOME_NET always contains the locally attached networks of all in... Julian Wecke

12/15/2017

11:42 PM Revision e5c4b4fc: Fix input field help texts
Joeri Capens
07:04 PM Revision 9ad6899e: make inputs a bit wider for fahrenheit
Michael Newton
06:23 PM Revision e5d14da2: address comments
Michael Newton
06:21 PM Revision 7620b362: fix copy/paste error
Michael Newton
06:11 PM Revision 8b09ec18: update label on unit change
also ensure unit labels can be internationalized, and fix some whitespace Michael Newton
05:55 PM Revision bc63503b: Moving this code to PHP for i18n
Michael Newton
05:42 PM Revision cb7bef9d: don't change thresholds to F until after passing to Javascript
Michael Newton
04:28 PM pfSense Packages Bug #8213 (New): acl src file not populated from alias
Trying to use an alias as frontend ACL source IP filter. Alias (7 hosts) resolves correctly in pfSense, HAProxy conf... Jerry Fath
03:32 PM Revision abe217af: Merge pull request #3890 from JoeriCapens/master
Steve Beaver
03:24 PM Feature #7671: Gateway Monitoring Via Custom Script or Telnet.
Alright script is done, its pretty basic, See attached. Took Brendon's advice and used the Mark gateway as down optio... Bridgetowermedia IT
01:51 PM pfSense Packages Bug #8212 (Not a Bug): Ipsec overwiew
Please post on the forum, mailing list, or reddit to discuss your problem. It is unlikley you have a bug based on the... Jim Pingle
01:47 PM pfSense Packages Bug #8212 (Not a Bug): Ipsec overwiew
Hi
At some point I had some IpSec VPNs configured and I deleted them because they were no longer needed, those VPN...
Vincent Romero
10:49 AM pfSense Packages Feature #8211 (Resolved): ACME cron job <- log activity
Please log ACME's cron activity in the system log (normal and error outputs) so we know that there's any issue with i... robi robi
09:40 AM Bug #6319 (Feedback): DHCP6 DDNS tsig key missing from dhcpv6.conf for reverse zone
Applied in changeset commit:0e13a3a63b28a0b8dc4b86543adaf0506ab1d17c. Joeri Capens
04:55 AM Bug #8206 (Feedback): Hosted Openappid rules - syntax error
Should be fixed now Renato Botelho
12:43 AM Bug #8206: Hosted Openappid rules - syntax error
Renato knows. Jim Thompson
01:16 AM Bug #8061: LAN WAN Interfaces missing in Traffichshaper
I am also confirming this issue on 2.3.5 and now 2.3.5_p1.
We have 22 affected units and they are all using the ig...
Josh Chilcott

12/14/2017

09:58 PM pfSense Packages Feature #8210 (Rejected): DHCP servers do not automatically advertise interface IP as DNS server with BIND enabled
That would require coding support for the BIND package in the base system, which isn't going to happen. If you want t... Jim Pingle
09:32 PM pfSense Packages Feature #8210 (Rejected): DHCP servers do not automatically advertise interface IP as DNS server with BIND enabled
The text on the DNS Servers field of the DHCP server configuration pages reads "Leave blank to use the system default... Chaos215 Bar2
08:35 PM Revision 78347c9b: Add a missing return when no NIC is found.
Luiz Souza
07:27 PM Revision 87d2f8cd: Abort the initial interface setup when no interfaces are found.
Luiz Souza
11:57 AM pfSense Packages Bug #8209 (Closed): Suricat Inline netmap bad packet errors
Using PFsense 2.4.2 and Suricata 4.0.1_1 I using Inline mode, I see errors like this appearing in the system log rath... Stan Masterson
08:27 AM Bug #6223 (Closed): IPsec + OpenBGPD fails with "PF_KEY socket: No buffer space available"
It's still broken with FreeBSD 11.x and OpenBGPD and it's unclear if that combination will be fixed upstream.
If y...
Jim Pingle

12/13/2017

09:55 PM Bug #8208 (Resolved): Restoring a config in 2.4.2 with 2.3.X Security/Errata Only repo selected breaks PHP
After attempting to repair repos for a failed upgrade, config was exported from 2.3.4-P1 and imported to a fresh inst... Paighton Bisconer
09:23 PM Bug #8056: Bridge + CARP crashes/freezes pfSense
Happens on both e1000 drivers and virtio drivers.
Harry Coin
09:22 PM Bug #8056: Bridge + CARP crashes/freezes pfSense
This is observed on pfsense running in a QEMU/KVM host running Ubuntu/"artful". Harry Coin
01:43 PM Bug #8056: Bridge + CARP crashes/freezes pfSense
PF deadlocks once every 3 hours or so. There's a process holding a lock (carp lock, bridge lock)? which then I thin... Harry Coin
01:40 PM Bug #8056: Bridge + CARP crashes/freezes pfSense
Confirmed. For detail, see this.
https://redmine.pfsense.org/issues/8145
Harry Coin
08:29 PM Revision 207abc3e: spelling!
Michael Newton
01:43 PM Revision 352612a2: Use correct repo path for i386
Renato Botelho
01:41 PM Revision ec308151: Use correct repo path for i386
Renato Botelho
10:47 AM Bug #8207 (New): 2.4 cannot boot as a Xen VM with more than 7 NICs
2.4 does not seem to be able to boot when running as a VM under Xen when the guest is assigned more than 7 NICs. Boo... Michael Reardon
06:28 AM Revision 3f3641a4: "Save" user selection for DUID type
It proved confusing for users who entered a DUID as a certain type to
see the resulting DUID file displayed as a "Raw...
kang tastic
04:00 AM Revision 7955bcce: Remove endianness checking
all pfSense builds are little-endian kang tastic

12/12/2017

10:43 PM Revision 34d4ffe9: update convenience functions
Michael Newton
10:42 PM Revision b807b8cc: update threshold values dynamically
otherwise problems occur with saving wrong values when switching between C/F Michael Newton
09:38 PM Revision 5d73b032: more accurate progress bar display
we only use Fahrenheit for display, don't change the values! Michael Newton
09:02 PM Revision 7578d907: show ºF on updates via javascript
Michael Newton
08:19 PM Revision 1532881e: initial display of temperature in ºF
still need to update javascript Michael Newton
07:41 PM Revision 8405ebed: account for thresholds and bar width in ºF
global variables are really really ugly, this should be wrapped in an anonymous function Michael Newton
07:30 PM Revision 9b6b13e6: Fix build_snapshots.sh -n
Renato Botelho
07:30 PM Revision 0f4ed832: Fix build_snapshots.sh -n
Renato Botelho
07:24 PM Revision 188d7f19: display/enter thresholds in ºF as well
Michael Newton
06:58 PM Revision 090a9f12: fix copy/paste error
Michael Newton
06:53 PM Revision 7e1b79e6: provide temperature in Fahrenheit
Also resolve some indent issues, restrict live updates to temperature value only (not unit text) Michael Newton
06:38 PM Revision b8810db7: checkbox for option to display Fahrenheit
Michael Newton
05:41 PM Bug #8206: Hosted Openappid rules - syntax error
This was originally posted in the forum at https://forum.pfsense.org/index.php?topic=141319.0 Lance Fogle
05:39 PM Bug #8206 (Resolved): Hosted Openappid rules - syntax error
There is currently no community knowledge of who the "volunteer maintainer" is for the file hosted at http://files.pf... Lance Fogle
03:48 PM Feature #8205: Allow display of temperature in Fahrenheit
https://github.com/pfsense/pfsense/pull/3891 Michael Newton
01:54 PM Feature #8205 (Resolved): Allow display of temperature in Fahrenheit
For the dashboard temperature sensor widget, Americans should be able to use their strange units.
Working on a pul...
Michael Newton
03:12 PM Revision bea1ef64: Add new CONTRIBUTING file and Pull Request template
Jim Pingle
10:20 AM Bug #8204 (Not a Bug): unbound returning funny ip instead of nothing
It would appear that either you have forwarding mode on and your upstream server returns its own address instead of N... Jim Pingle
10:19 AM Bug #8204: unbound returning funny ip instead of nothing
please close the ticket. Problem ist DNS of Provider. Tom Mü-Ko
10:18 AM Bug #8204: unbound returning funny ip instead of nothing
close Tom Mü-Ko
10:06 AM Bug #8204 (Not a Bug): unbound returning funny ip instead of nothing
where I ask unbount on pfSense for an IP, i.e. 1.1.1.1 it returns 62.138.239.45, 62.138.238.45:... Tom Mü-Ko
07:30 AM Bug #8201: 502 gateway issues Increase FPM process availability in high ram systems
PR: https://github.com/pfsense/pfsense/pull/3881 Jim Pingle
02:51 AM Bug #8201 (Duplicate): 502 gateway issues Increase FPM process availability in high ram systems
To reduce chance of nginx gateway error when interacting with FPM backend, this patch does the following, starts up e... Martin Wasley
07:28 AM Bug #8200: Set VLAN priority on on dhcp6c packets
Referencing by number won't automatically create a link between Github and Redmine, you'll have to use the entire URL... Jim Pingle
02:47 AM Bug #8200: Set VLAN priority on on dhcp6c packets
PR #3862 Martin Wasley
02:41 AM Bug #8200 (Resolved): Set VLAN priority on on dhcp6c packets
dhcp6c packets are not being tagged with VLAN priority.
Pull request issued:
PR 3862
Martin Wasley
07:22 AM Feature #8191: IPv6 - Support for configuring multiple DUID types
PR: https://github.com/pfsense/pfsense/pull/3889 Jim Pingle
05:10 AM pfSense Packages Feature #8203 (Resolved): pfSense-pkg-suricata: extended eve output selectable headers
If the extended eve output is selected suircate gets configured to log all possible http headers. This might be too m... Julian Wecke
03:45 AM Revision fffb9eed: Code cleanup
Add a check to Copy DUID button on system_advanced_network.php kang tastic
03:09 AM Feature #8202 (Resolved): Captive portal: add support for setting traffic quotas
Pull request #3453 on github https://github.com/pfsense/pfsense/pull/3453
Add support for traffic quotas to captiv...
Caio Plumbeo
02:11 AM pfSense Packages Bug #8194: BIND fails to respond after interface goes down
* "Any configuration changes…" Chaos215 Bar2
01:44 AM pfSense Packages Bug #8194 (Closed): BIND fails to respond after interface goes down
2.4.2-RELEASE with BIND 9.11_9 on SG-4860
Steps to reproduce:
1) Install pfSense 2.4.2-RELEASE and the BIND packa...
Chaos215 Bar2
02:05 AM pfSense Packages Feature #8199 (New): Support reordering and/or sort alphabetically across BIND package
The BIND package has many lists (ACLs, Views, Zones, Zone Domain records, etc.) whose order seems to be fixed permane... Chaos215 Bar2
01:57 AM pfSense Packages Feature #8198 (Resolved): pfSense-pkg-LCDproc: Add a link status screen for each interface
see pull request: https://github.com/pfsense/FreeBSD-ports/pull/377 Christian Schwamborn
01:56 AM pfSense Packages Bug #8197 (Resolved): BIND UI fails to properly update zone with inline DNSSEC signing enabled
2.4.2-RELEASE with BIND 9.11_9 on SG-4860
Steps to reproduce:
1) Install pfSense 2.4.2-RELEASE and the BIND packa...
Chaos215 Bar2
01:56 AM pfSense Packages Feature #8196 (Resolved): pfSense-pkg-LCDproc: add a shutdown/reboot control menu
see pull request: https://github.com/pfsense/FreeBSD-ports/pull/376 Christian Schwamborn
01:47 AM pfSense Packages Bug #8195 (Closed): BIND packages launches two instances of /usr/local/sbin/named on boot
2.4.2-RELEASE with BIND 9.11_9 on SG-4860
With the BIND package installed and enabled, I see two identical "/usr/l...
Chaos215 Bar2
12:22 AM pfSense Packages Bug #8193: Cellular Package Update
https://github.com/pfsense/FreeBSD-ports/pull/414 Sven Auhagen
12:21 AM pfSense Packages Bug #8193 (Resolved): Cellular Package Update
Hi,
this is the ticker for a PR for a larger update to the cellular package.
The main changes are:
Add a fixed...
Sven Auhagen

12/11/2017

08:51 PM Bug #8192 (New): dpinger - Change in ISP link-local IPv6 address drops connectivity
When connecting via PPPoE on a DSL connection, the IPv6 link-local address on an ISP's router may change periodically... Kristopher Kolpin
08:09 PM Feature #7596: Ting Config
to update this issue, i have pushed the Ting apn settings to upstream and should be added soon. wesley jackson
07:57 PM Feature #8191: IPv6 - Support for configuring multiple DUID types
Sorry about Post 1, I typo'd the type numbers. Post 2 is correct. kang tastic
07:55 PM Feature #8191: IPv6 - Support for configuring multiple DUID types
There are currently four types of DUID (DHCP Unique Identifier) defined in IETF RFCs - DUID-LLT, DUID-EN, and DUID-LL... kang tastic
06:33 PM Feature #8191 (Resolved): IPv6 - Support for configuring multiple DUID types
There are currently four types of DUID (DHCP Unique Identifier) defined in IETF RFCs - DUID-LLT, DUID-EN, and DUID-LL... kang tastic
07:06 PM Bug #8122: openvpn client is unable to use OTP (temporary) passwords
PR implementing this feature https://github.com/pfsense/pfsense/pull/3877 Sorin Sbarnea
06:27 PM pfSense Packages Bug #8189: JavaScript does not work to disable/enable form elements
https://github.com/pfsense/FreeBSD-ports/pull/489
Not sure how this got assigned to me when I created it, hopefull...
Michael Newton
03:47 PM pfSense Packages Bug #8189 (Resolved): JavaScript does not work to disable/enable form elements
There's some ancient DOM Level 0 code present, and it does not work. This should be updated to use jQuery. Will uploa... Michael Newton
05:37 PM Revision 5ab3724d: Make necessary changes to pkg_chroot() use correct ABI/ALTABI information
Renato Botelho
05:37 PM Revision 00717e03: Define build repo to be used during build process
Renato Botelho
05:37 PM Revision 27d23b73: Make necessary changes to pkg_chroot() use correct ABI/ALTABI information
Renato Botelho
05:37 PM Revision 013e93a6: Define build repo to be used during build process
Renato Botelho
05:36 PM Revision a76b4810: Make necessary changes to pkg_chroot() use correct ABI/ALTABI information
Renato Botelho
05:36 PM Revision dbd615c4: Define build repo to be used during build process
Renato Botelho
04:59 PM Revision c0ccf138: Use correct format for altabi
Renato Botelho
04:44 PM Revision c7d6a5f5: Replace %%ARCH%% by arch
Renato Botelho
04:29 PM Revision 96dc3579: Make necessary changes to pkg_chroot() use correct ABI/ALTABI information
Renato Botelho
04:02 PM pfSense Packages Feature #8190 (Resolved): Enhance RRD_Summary package with historical reporting
RRD_Summary should allow display of available historical data beyond current and previous month. Created PR https://... John Silva
03:55 PM Revision e0b28058: Bootstrap pkg from 2.3 repo
Renato Botelho
03:51 PM Feature #8187: Gateways, allow for configuring a gatewaygroup as the default gateway. #3781
PR: https://github.com/pfsense/pfsense/pull/3781 Jim Pingle
03:33 PM Feature #8187 (Resolved): Gateways, allow for configuring a gatewaygroup as the default gateway. #3781
Gateways, allow for configuring a gatewaygroup as the default gateway.
-Avoid changing routes by just visiting a web...
Pi Ba
03:43 PM pfSense Packages Feature #8188 (Resolved): Support response policy zones in bind package
An RPZ "selectively intercepts DNS resolution for known-malicious network assets including domain names, IP addresses... Michael Newton
03:35 PM Revision 8dfe6ef4: Use 2.3 repo during build process
Renato Botelho
03:30 PM Feature #8186 (Resolved): ipsec, allow configuration of multiple ike phase1 encryption ciphers #3711
ipsec, allow configuration of multiple ike phase1 encryption ciphers (algo/bits/hash/dh)
this is useful for mobile...
Pi Ba
03:29 PM Bug #8185 (Resolved): status_queues, provide 'realtime' statistics #3792
status_queues, provide 'realtime' statistics
-retrieve 'current' numbers from pfSense
not using qstats provides t...
Pi Ba
03:27 PM Feature #8184 (Resolved): pppoe, allow configuring pppoe on a carp interface so its only active on the master #3830
pppoe, allow configuring pppoe on a carp interface so its only active on the master
https://github.com/pfsense/pfsen...
Pi Ba
03:26 PM Bug #8183 (Resolved): pkg, fix, reinstall missing package #3866
change the reference from install_package(.) as this function does not exist.
https://github.com/pfsense/pfsense/pul...
Pi Ba
03:13 PM Bug #8182: Support shutdown scripts in /usr/local/etc/rc.d
Associated PR is https://github.com/pfsense/pfsense/pull/3867 Denny Page
03:12 PM Bug #8182 (Resolved): Support shutdown scripts in /usr/local/etc/rc.d
Support shutdown scripts in /usr/local/etc/rc.d. This allows packages to take critical shutdown actions such as UPS p... Denny Page
03:12 PM pfSense Packages Feature #8181: Quagga OSPF failover mechanism takes too much time to converge in HA environments
[[https://github.com/pfsense/FreeBSD-ports/pull/413#issuecomment-336879042]] Tim Economides
03:11 PM pfSense Packages Feature #8181 (Resolved): Quagga OSPF failover mechanism takes too much time to converge in HA environments
In order to improve uptime in HA environments, we developed a mechanism to dynamically change OSPF interface costs on... Tim Economides
02:43 PM Feature #5112: LDAP support for Captive Portal
Another potential PR: https://github.com/pfsense/pfsense/pull/3640 Jim Pingle
02:30 PM Feature #6621: Permit DHCP Server Dynamic DNS server key algorithm type selection and use
PR: https://github.com/pfsense/pfsense/pull/3887 Jim Pingle
02:29 PM Bug #6319 (New): DHCP6 DDNS tsig key missing from dhcpv6.conf for reverse zone
New PR: https://github.com/pfsense/pfsense/pull/3890 Jim Pingle
01:30 PM Revision 9a22bd60: It's time for 2.4.2-RELEASE-p1
Renato Botelho
01:29 PM Revision c6fbc61a: It's time for 2.3.5-RELEASE-p1
Renato Botelho
11:25 AM Feature #7671: Gateway Monitoring Via Custom Script or Telnet.
Interesting.
There is a "Mark Gateway as Down" option in the GUI. If you could figure out how to script that flag...
Brendon Baumgartner
10:55 AM Feature #7671: Gateway Monitoring Via Custom Script or Telnet.
Well it seems that the man behind the curtain of support says that this isn't possible... I refuse to accept that thi... Bridgetowermedia IT
09:29 AM pfSense Packages Bug #8180 (Closed): syslog-ng default log file
The main problem is that default log file produced by syslog-ng is never handled according rules mentioned under Gene... Miroslav Dvorak
07:18 AM Bug #8172 (Resolved): Patch to make ping_hosts.sh faster and avoid carp deadlock
Jim Pingle
07:18 AM Bug #8116 (Resolved): status_graph.php: Premature session termination when monitoring live traffic graphs
Jim Pingle
07:10 AM Bug #8175 (Not a Bug): DNS server not updated correctly
Sounds like a configuration or procedural issue. Post on the forum, mailing list, or reddit and discuss the problem t... Jim Pingle

12/10/2017

09:27 PM Bug #8179 (Resolved): Incorrect reverse DNS zone in DHCP server config for non-octet-aligned subnet mask
I have a DHCP server running on pfSense 2.4.2 on an interface with subnet 172.24.208.0 and subnet mask 255.255.254.0.... Chaos215 Bar2
12:04 AM Revision 7e3bdbaa: Set default key algorithm to hmac-md5
Joeri Capens

12/09/2017

09:36 PM Revision 0e13a3a6: Fix #6319 again by adding missing dns-servers
Joeri Capens
07:48 PM Feature #8178: Allow setting attributes for form elements in package XML
Good suggestions. The package manager XML thing is something of a nightmare to work on, but this might not be too bad.
Anonymous
07:01 PM Feature #8178 (New): Allow setting attributes for form elements in package XML
I'd like to suggest a couple of enhancements that would make package interfaces easier to work with when enhancing th... Michael Newton
07:03 PM Bug #8177: "../xsl/package.xsl" is referenced in package XML files but not on the firewall
Hit 'create' too soon by mistake. Anyhow:
cron.xml, arping.xml, shellcmd.xml, etc. etc. make reference to ../xsl/...
Harry Coin
06:58 PM Bug #8177 (New): "../xsl/package.xsl" is referenced in package XML files but not on the firewall
Harry Coin
06:52 PM Bug #8176 (New): ../schema/packages.dtd -- referenced in *xml, but missing?
Nearly every xml file in the packages collection includes
<!DOCTYPE packagegui SYSTEM "../schema/packages.dtd">
H...
Harry Coin
06:43 PM Bug #8174: DNS server option in wireless missing
The title should be: "DHCP server option in wireless missing" instead of "DNS server option in wireless missing", unf... h s
06:39 PM Bug #8174 (Not a Bug): DNS server option in wireless missing
You have a configuration issue, not a bug. Post on the forum, reddit, or mailing list for assistance. Jim Pingle
06:35 PM Bug #8174 (Not a Bug): DNS server option in wireless missing
I am using the Pfsense 2.4 with a wireless card.
The dhcp server (enable or disable) option is not available in th...
h s
06:41 PM Bug #8175 (Not a Bug): DNS server not updated correctly
I am using the Pfsense 2.4 with a wireless card.
I had to setup the settings of the wireless interface, but when c...
h s
11:31 AM Bug #7425: dhclient not sending option 77
Is this still planned for 2.4.3 ? Kev Willers
05:44 AM Feature #8173: dhcp6c - RAW Options
Sorry, that's not looking at what I have written... the keyword is raw-option in the config, not RAW. Martin Wasley
05:38 AM Feature #8173 (New): dhcp6c - RAW Options
The lack of available options in dhcp6c prevents pfSense from being used with certain ISPs.
For example, Orange Fr...
Martin Wasley
02:16 AM Revision 64b9d133: Support for configuring additional DUID types
dhcp6c stores the entirety of the OPTION_CLIENTID option in DHCPv6 datagrams in
its DUID file (named dhcp6c_duid), ex...
kang tastic

12/08/2017

09:53 PM Revision 1ce1eac5: After recent fixes to auth_check.inc, move the IPsec widget back to auth_check.inc since its timeout problems are likely now fixed.
(cherry picked from commit 9af697ce606ce583f406af6987b579a63b7be9a8) Jim Pingle
08:58 PM Revision 9af697ce: After recent fixes to auth_check.inc, move the IPsec widget back to auth_check.inc since its timeout problems are likely now fixed.
Jim Pingle
05:14 PM Revision 4544e192: local authentication option, use key value instead of translated name.
(cherry picked from commit 3e90d18b562fcf2ad60a64cc9458034a121c66a2) Pi Ba
04:53 PM Revision 4a29508c: Bug in get_interface_ip
Global variable $config was not available, and IP was always fetched using find_interface_ip
(cherry picked from com...
Jackson Laskoski
04:53 PM Revision 4922fd89: Bug in get_interface_ip
Global variable $config was not available, and IP was always fetched using find_interface_ip
(cherry picked from com...
Jackson Laskoski
04:53 PM Revision 382abef3: Bug in get_interface_ip
Global variable $config was not available, and IP was always fetched using find_interface_ip
(cherry picked from com...
Jackson Laskoski
03:21 PM Revision f6e83ca2: Skip IPsec ping host CARP check when there are no IPSec ping hosts. Also, add a safety belt so cat can't get stuck waiting on input. Fixes #8172
(cherry picked from commit 45d078c5964b94dd2aa7f1a609fcb47e89eaac49) Jim Pingle
03:21 PM Revision f2e610bc: Skip IPsec ping host CARP check when there are no IPSec ping hosts. Also, add a safety belt so cat can't get stuck waiting on input. Fixes #8172
(cherry picked from commit 45d078c5964b94dd2aa7f1a609fcb47e89eaac49) Jim Pingle
03:21 PM Revision c5dde24a: Skip IPsec ping host CARP check when there are no IPSec ping hosts. Also, add a safety belt so cat can't get stuck waiting on input. Fixes #8172
(cherry picked from commit 45d078c5964b94dd2aa7f1a609fcb47e89eaac49) Jim Pingle
03:20 PM Revision 45d078c5: Skip IPsec ping host CARP check when there are no IPSec ping hosts. Also, add a safety belt so cat can't get stuck waiting on input. Fixes #8172
Jim Pingle
12:56 PM Bug #7969: md5 bgp sessions fail in 2.4.0
Attaching config files from /var/etc/frr Andrew Dul
12:38 PM Bug #7969: md5 bgp sessions fail in 2.4.0
I downloaded the new 2.4.2 and tried to get this working and still was unable to make it work.
The "Type of Pass...
Andrew Dul
12:12 PM Bug #8056: Bridge + CARP crashes/freezes pfSense
Re-tested a few days ago on 2.4.2 and I can observe the same crash.
Can anyone move this report to status Confirme...
Anonymous
11:22 AM Feature #6847 (Feedback): Register CN of OpenVPN clients in DNS Resolver
PR was merged on 11/29 Jim Pingle
11:21 AM Bug #8106 (Feedback): dhcp6c lock files not removed after unclean shutdown when using "Do not wait for an RA" on IPv6 WAN interface
Jim Pingle
11:12 AM Bug #6400 (Feedback): assign_interfaces.php issues with large numbers of interfaces
PR https://github.com/pfsense/pfsense/pull/3868 was merged on 11/29 Jim Pingle
11:08 AM Bug #7502 (Feedback): Cannot set router lifetime to 0 in radvd
Jim Pingle
09:30 AM Bug #8172 (Feedback): Patch to make ping_hosts.sh faster and avoid carp deadlock
Applied in changeset commit:45d078c5964b94dd2aa7f1a609fcb47e89eaac49. Jim Pingle
09:23 AM Bug #8172: Patch to make ping_hosts.sh faster and avoid carp deadlock
It wasn't quite as simple as changing that one line, but I made a change that should have the same net effect. Jim Pingle

12/07/2017

09:32 PM Revision d0d6d27f: Pretty up the new smtp notification header.
Jim Pingle
08:28 PM Feature #7321: DynDNS - Add DreamHost DNS support
You cannot set the TTL through the API - https://help.dreamhost.com/hc/en-us/articles/217555707-DNS-API-commands Frank Gruman
08:26 PM Feature #7321: DynDNS - Add DreamHost DNS support
Thanks so much! The logs helped me figure it out. I didn't realize I needed to create the record manually first. Seem... Corey Boyle
05:44 PM Feature #7321: DynDNS - Add DreamHost DNS support
The logs should appear under Status > System Logs under the "General" section. Most of the log entries will start wi... Frank Gruman
02:18 PM Feature #7321: DynDNS - Add DreamHost DNS support
I tried to set this up today, but did not have any luck. I selected "Verbose" logging, but I'm not sure where to find... Corey Boyle
08:14 PM Revision d1a8f91c: Fix auth_check.inc to perform a commit to avoid PHP session gc from reaping the session. Fixes occasional timeouts when sitting on pages that only fetch AJAX for prolonged periods. Fixes #8116
(cherry picked from commit 2138aad96c7046bff8000cb1febd85f16b9292bb) Jim Pingle
08:14 PM Revision 2138aad9: Fix auth_check.inc to perform a commit to avoid PHP session gc from reaping the session. Fixes occasional timeouts when sitting on pages that only fetch AJAX for prolonged periods. Fixes #8116
Jim Pingle
08:13 PM Revision 99e592be: Fix auth_check.inc so it conforms to the rest of the session management code. While here, make sure it performs a commit to avoid PHP session gc from reaping the session. Fixes occasional timeouts when sitting on pages that only fetch AJAX for prolonged periods. Fixes #8116
(cherry picked from commit fe7c4634fd49ae02298f41bc2b6a8030fa99ac07) Jim Pingle
08:13 PM Revision fe7c4634: Fix auth_check.inc so it conforms to the rest of the session management code. While here, make sure it performs a commit to avoid PHP session gc from reaping the session. Fixes occasional timeouts when sitting on pages that only fetch AJAX for prolonged periods. Fixes #8116
Jim Pingle
08:04 PM Revision 534d7d69: Add DHCP Dynamic DNS key algorithm choice. Implements #6621
Joeri Capens
04:37 PM Revision fea6f84d: Remove ix from the ALTQ interface list. See ticket #7378
(cherry picked from commit d0bb073b2023c0551e1812f96aa8c6e2d7baba79) Jim Pingle
04:30 PM Revision d0bb073b: Remove ix from the ALTQ interface list. See ticket #7378
Jim Pingle
04:11 PM Bug #8172 (Resolved): Patch to make ping_hosts.sh faster and avoid carp deadlock
In /usr/local/bin/ping_hosts.sh we have
..
# Read in ipsec ping hosts and check the CARP status
if [ -f /var/db/ip...
Harry Coin
03:21 PM Bug #8169 (Not a Bug): Captive Portal Default download/upload
The current way is correct, otherwise you would have to manually specify a limit for all Allowed IP Address entries s... Jim Pingle
03:11 PM Bug #8159 (Resolved): services_dnsmasq.php: Deleting a Host Override entry removes the wrong item
Jim Pingle
03:03 PM Bug #7710 (Resolved): IGMP Proxy
Jim Pingle
03:00 PM Bug #7989 (Resolved): Cannot update Nano from 2.3.4 to 2.3X snapshots
Jim Pingle
02:59 PM Bug #7991 (Closed): Bunch of webGUI fixes for 2.3.5
Jim Pingle
02:57 PM Bug #8112 (Resolved): Internal IP mask is always reset to /32 when editing a 1:1 NAT
Jim Pingle
02:55 PM Bug #8164 (Resolved): PPPoE Server and L2TP Server Login Event Log is not functional
Jim Pingle
02:38 PM Revision 3b4dad1b: Merge pull request #6319 from JoeriCapens/master
Steve Beaver
02:20 PM Bug #8116 (Feedback): status_graph.php: Premature session termination when monitoring live traffic graphs
Applied in changeset commit:fe7c4634fd49ae02298f41bc2b6a8030fa99ac07. Jim Pingle
02:19 PM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
It appears that without a session_commit() the session appears to be stale to PHP's session garbage collection. I've ... Jim Pingle
02:15 PM Feature #8171 (Duplicate): Close TCP connections if associated rule just has been disabled
Hi !
Sometimes, I need to block a machine to prevent it from having access to the internet.
The problem is that...
csphoenix1 X
11:20 AM Feature #8170 (New): XMLRPC Sync deletes entires on remote System
Hello!
I've got a setup of three pfSense instances: c01, c02 and c03.
They share the public IPs via carp.
c01 sy...
Karl Winchester
10:38 AM Bug #7916 (Duplicate): There were error(s) loading the rules: pfctl: ix0: driver does not support altq - The line in question reads [0]: | Intel X520-DA2
Duplicate of #7378 Jim Pingle
10:31 AM Bug #7378: pfctl: ix0: driver does not support altq
Ultimately this was reverted at the time due to instability in the driver with ALTQ enabled.
See: https://forum.pf...
Jim Pingle
08:50 AM Bug #6319 (Feedback): DHCP6 DDNS tsig key missing from dhcpv6.conf for reverse zone
Applied in changeset commit:3b46a9cf6968ebe742981b4a55f84e65224fdc38. Joeri Capens

12/06/2017

07:51 PM Bug #8169 (Not a Bug): Captive Portal Default download/upload
Since version 2.4.0 the Captive portal service no longer acknowledges either 0 or a blank field in the Allowed IP Add... Leon Shadow
07:14 PM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
Changing auth_check.inc to guiconfig.inc in ifstats.php and bandwidth_by_ip.php seems to correct the behavior. With g... Jim Pingle
03:48 PM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
One more thing, the graph call to ifstats.php that happens when the session fails contains the login page, but still ... Jim Pingle
03:45 PM Bug #8116 (Confirmed): status_graph.php: Premature session termination when monitoring live traffic graphs
We have confirmed this does happen in some cases but we have not yet definitively narrowed down a specific cause or e... Jim Pingle
03:16 PM Feature #8168: strongswan dhcp option
Ges Ture wrote:
> I've asked for this 3 versions ago :)
Did you create a feature request for it or did you just w...
Lars Pedersen
05:01 AM Feature #8168: strongswan dhcp option
I've asked for this 3 versions ago :) Ges Ture
04:59 AM Bug #8117: IPSec statuspage shows both connected and connecting tunnel
Any follow up? Will this be reported to Strongswan developers? Ges Ture

12/05/2017

11:30 PM Feature #3377: OAuth2 authentication in captive portal
is there further developments on the above feature radius with oauth backend to support google apps id it will be ver... Ponvannan Sankaran
03:42 PM Revision 6ee7e27a: Fix logging for L2TP and PPPoE server login/logout events. Fixes #8164
See https://redmine.pfsense.org/issues/8164 for the reasoning about why it was done this way.
(cherry picked from co...
Jim Pingle
03:41 PM Revision 902a31e3: Fix logging for L2TP and PPPoE server login/logout events. Fixes #8164
See https://redmine.pfsense.org/issues/8164 for the reasoning about why it was done this way. Jim Pingle
03:17 PM Feature #8168 (New): strongswan dhcp option
Would be nice to have the dhcp plugin for strongswan in pfsense. This feature could be useful for a simple way to ass... Lars Pedersen
02:32 PM pfSense Packages Bug #8167 (Resolved): FRR OSPF6 range problem (subnet not advertized)
The range statement inside the router ospf6 clause seems to have the opposite effect of what is expected.
FRR docs...
Andrew Webster
01:56 PM pfSense Packages Bug #8162 (Duplicate): Add virtual server support to FreeRadius
Duplicate of #8161 Jim Pingle
01:56 PM pfSense Packages Bug #8154 (Resolved): FRR OSPF6 not working
Thanks for testing!
The update/delete interface part is somewhat expected, and unrelated to this issue. The best w...
Jim Pingle
01:39 PM pfSense Packages Bug #8154: FRR OSPF6 not working
OSPF3 hello packets now emanating from the interface when the interface is added to the interface list.
Passive mode...
Andrew Webster
11:19 AM pfSense Packages Bug #8154 (Feedback): FRR OSPF6 not working
I pushed a fix for this and a couple other syntax issues I found along the way. Hopefully it behaves properly now, gi... Jim Pingle
01:54 PM Bug #8166 (Not a Bug): FRR Interfaces list does not show Interface Description like the rest of pfSense
That's not a package specific bug. It's a byproduct of how the pkg_edit.php select_source control type works. It only... Jim Pingle
01:46 PM Bug #8166 (Not a Bug): FRR Interfaces list does not show Interface Description like the rest of pfSense
This is just a question of standardizing the output so it looks the same everywhere...
On the OSPF Interfaces, and...
Andrew Webster
11:37 AM Bug #8165 (Closed): Fragmented at source IPv6 packets (UDP + ICMP Ping) are not forwarded / v2.4.2 AMD64
This issue came to light when I encountered a problem with a SIP phone not receiving SIP Invite messages resulting in... Mike Nichols
10:08 AM Bug #8163 (Not a Bug): dpinger default payload fails 70%
Most likely the device on the other end doesn't like the small payload, in which case you can set the larger size and... Jim Pingle
06:00 AM Bug #8163: dpinger default payload fails 70%
Can you post the ICMP packets transmitted by this HW ? (I need see the packets as they go on wire, packet captures on... Luiz Souza
09:50 AM Bug #8164 (Feedback): PPPoE Server and L2TP Server Login Event Log is not functional
Applied in changeset commit:902a31e3fd419e2fc360ad891ee3a82209264e1a. Jim Pingle
09:25 AM Bug #8164 (Resolved): PPPoE Server and L2TP Server Login Event Log is not functional
Both the PPPoE server and L2TP server rely on vpn.log to track login/logout events. On 2.4.x these logs are not funct... Jim Pingle

12/04/2017

10:30 PM Revision 3b46a9cf: Fix #6319 by setting ptr-domain and key variables correctly for dhcpdzones()
Joeri Capens
09:06 PM Bug #8163: dpinger default payload fails 70%
It's happening with two different links on different vlans on the same *realtek(re)* interface. Marcello Silva Coutinho
09:02 PM Bug #8163 (Not a Bug): dpinger default payload fails 70%
using 2.4.2 on a intel network card with vlan tagged and a monitor ip from first hop after gateway
with default le...
Marcello Silva Coutinho
06:57 PM Revision 7662ec2a: Merge pull request #3884 from stilez/patch-71
Steve Beaver
06:56 PM Revision c21b1dd3: Merge pull request #3882 from PiBa-NL/20171130-remove-console-output
Steve Beaver
06:55 PM Revision a283cfe0: Merge pull request #3883 from stilez/patch-70
Steve Beaver
06:54 PM pfSense Packages Bug #8162 (Duplicate): Add virtual server support to FreeRadius
It's great and super convenient that the FreeRadius server is included as a package with pfSense.
I currently use ...
Victor Hooi
06:53 PM pfSense Packages Feature #8161 (New): Add virtual server support to FreeRadius
It's great and super convenient that the FreeRadius server is included as a package with pfSense.
I currently use ...
Victor Hooi
05:36 PM Feature #8160 (Resolved): Accomodate both RADIUS and pool IP addresses in IPsec
Strongswan now allows multiple dynamic address pools in mobile IPsec.
I was able to coerce it to work by forcing e...
Chris Linstruth
04:18 PM Revision 90ac6971: Backported for bug #8159 so sort by index before deleting to delete the correct one
Stephen Jones
04:17 PM Revision aed8febb: Backported for bug #8159 so sort by index before deleting to delete the correct one
Stephen Jones
04:13 PM Revision a96f945a: Revert "Fixed #8159 added a sort by index after a delete call has been made to make sure it lines up correctly."
This reverts commit 1e659e027c5cd9f42a20286f84f0e2967bb01c3c. Stephen Jones
04:09 PM Revision 1e659e02: Fixed #8159 added a sort by index after a delete call has been made to make sure it lines up correctly.
Stephen Jones
04:02 PM Revision c254f9b4: Fixed #8159 added a sort by index after a delete call has been made to make sure it lines up correctly.
Stephen Jones
03:59 PM Revision 581c2d5f: Fixed #8159 added a sort by index after a delete call has been made to make sure it lines up correctly.
Stephen Jones
12:28 PM Bug #7774: No TCP Reply State Established on GRE in IPsec Transport
Is this the same as #4479? Any hopes this can be fixed? I think the other bug report got lost track of. Jorge Albarenque
10:10 AM Bug #8159 (Feedback): services_dnsmasq.php: Deleting a Host Override entry removes the wrong item
Applied in changeset commit:581c2d5f4de0671d5ab2bf30701430351a3cf1d7. Anonymous
08:32 AM Bug #8159: services_dnsmasq.php: Deleting a Host Override entry removes the wrong item
I think there was a recent PR that added sorting. That probably broke the relationship between the list and the indices. Anonymous
08:29 AM Bug #8159 (Resolved): services_dnsmasq.php: Deleting a Host Override entry removes the wrong item
On Services > DNS Forwarder, when there are multiple Host Override entries the wrong item can be deleted from the lis... Jim Pingle
09:46 AM Bug #8153 (Resolved): Post-auth RCE in cert_get_publickey() from certs.inc, used in system_camanager.php and system_certmanager.php
Fixed in current snapshots. Jim Pingle
03:58 AM Bug #6319: DHCP6 DDNS tsig key missing from dhcpv6.conf for reverse zone
YAY! It's working! It's generating a key definition in dhcpdv6.conf now. Bogdan P
01:52 AM pfSense Packages Bug #8047: XG-2758 - Coreboot Upgrade - Different ROM size
It worked just had to unplug the power instead of pushing the red button the back. Tino Zidore
01:38 AM pfSense Packages Bug #8047: XG-2758 - Coreboot Upgrade - Different ROM size
I am experiencing a problem similar to this.
except my XG-2758 is rebooting by it self after upgrade. And it stays...
Tino Zidore

12/03/2017

03:57 PM Bug #6319: DHCP6 DDNS tsig key missing from dhcpv6.conf for reverse zone
The attached patch fixes this issue for me. Please test. Joeri Capens
03:48 PM Feature #6621: Permit DHCP Server Dynamic DNS server key algorithm type selection and use
I also ran into this problem after following some bind9 guides which use the newer ddns-confgen command. This tool us... Joeri Capens
03:06 PM Bug #7413: status_dhcpv6_leases.php: Some DHCPv6 leases are not displayed in the GUI
I have made a patch that addresses the issue, but it is
also a rewrite of a large part of the status leases
page, t...
Anders Lind
01:00 PM Bug #8015: IPsec VPN Not Reconnecting until complete reboot
I think this must be a duplicate but I'm unable to find another ticket that matches it exactly right now. Possibly th... Steve Wheeler
09:00 AM Bug #8158 (New): IPv6 Track Interface issue with more than one WAN-Gateway and a number of internal interfaces... at least track interface from one interface does not work on regular base
*Configuration*
* WAN interfaces are configured as WAN_KD and WAN_DTAG, the first is getting its configuration from ...
Ingo-Stefan Schilling
06:40 AM Bug #8157 (New): Traffic Graph clutter from time to time
When traffic is more occasional with (great) peaks the graph clutters. See attached file. This happens since version ... Ingo-Stefan Schilling

12/02/2017

10:40 PM Bug #8106: dhcp6c lock files not removed after unclean shutdown when using "Do not wait for an RA" on IPv6 WAN interface
J L wrote:
> Martin Wasley wrote:
> > Just do a PR on it Luke, it'll get reviewed there as part of the process.
> ...
J L
02:01 PM Bug #8156 (Resolved): Prefix not being included in DNS entry registered by DHCP6 server
I have a static DHCP6 mapping for a host on my network. The configured suffix for that host is ::1. The address is be... Dylan Piergies

12/01/2017

09:40 PM Revision c618a621: Fixed #8112
Steve Beaver
09:07 PM Revision 39ceb5d5: Fix typo
(cherry picked from commit cedfb2bc0442e8f2225b05792a6ef3097a8aebcf) Jim Pingle
09:07 PM Revision cedfb2bc: Fix typo
Jim Pingle
05:44 PM Revision d3e0194e: When retrieving a the modulus for a certificate, private key, or signing request, write the certificate data out to a temp file instead of echoing it through a pipe. Fixes #8153
(cherry picked from commit 6e316e955350ad69d4f86cb332a1a48bfa028e2e) Jim Pingle
05:44 PM Revision 6e316e95: When retrieving a the modulus for a certificate, private key, or signing request, write the certificate data out to a temp file instead of echoing it through a pipe. Fixes #8153
Jim Pingle
05:43 PM Revision 552d7750: When retrieving a public key for a certificate, private key, or signing request, write the certificate data out to a temp file instead of echoing it through a pipe. Fixes #8153
(cherry picked from commit b6dcbd646feb9c7197b4e94a6031b69c2113d679) Jim Pingle
05:41 PM Revision b6dcbd64: When retrieving a public key for a certificate, private key, or signing request, write the certificate data out to a temp file instead of echoing it through a pipe. Fixes #8153
Jim Pingle
03:36 PM Bug #8143 (Resolved): XSS in status_filter_reload.php
This looks good in current snapshots. Jim Pingle
02:48 PM Revision 9038f44c: Revert "Mitigate possible vuln in cert manager"
This reverts commit 1a68f4badd58de8694ac6a4208e11d7265c97df3. Steve Beaver
02:43 PM pfSense Packages Bug #8154 (Resolved): FRR OSPF6 not working
FRR's OSPF6 configuration pages don't appear to be generating the correct output into the /var/etc/frr/ospf6d.conf fi... Andrew Webster
02:30 PM Revision 1a68f4ba: Mitigate possible vuln in cert manager
Steve Beaver
12:00 PM Bug #8153 (Feedback): Post-auth RCE in cert_get_publickey() from certs.inc, used in system_camanager.php and system_certmanager.php
Applied in changeset commit:b6dcbd646feb9c7197b4e94a6031b69c2113d679. Jim Pingle
11:29 AM Bug #8153 (Resolved): Post-auth RCE in cert_get_publickey() from certs.inc, used in system_camanager.php and system_certmanager.php
cert_get_publickey() in source:src/etc/inc/certs.inc takes user input and uses it in a shell command without encoding... Jim Pingle
11:50 AM Revision deb575ab: Add isset, other vars seem to use it
Doesn't seem to have a point though :) Stilez y
11:48 AM Revision d30fa363: typo
Stilez y
11:46 AM Revision d2ec5844: Unbound: Disable IPv6 outgoing queries if IPv6 blocked in firewall, as they can never go anywhere
If IPv6 is disallowed in system->advanced->network, then any IPv6 lookups by Unbound will always be blocked, so there... Stilez y
11:11 AM Revision 7596c4c8: correct %d -> %s
As previous code used a string. Probably makes no difference and a number is simpler but doesn't matter Stilez y
11:08 AM Revision 300010be: Clarify the unexplained numbers in "log verbosity"
At the moment verbosity is a bare list of digits, 0 to 5. No explanation, nothing else. This PR replaces the visible ... Stilez y
10:01 AM Bug #8150: upgrade from 2.3* to 2.4* caused new self signed ssl cert to be selected for WebConfig
Been using pfSense for 10years. Thanks to the team for all their efforts.
For what it's worth, here is the config...
Oliver Schonrock
09:18 AM Bug #8150 (Not a Bug): upgrade from 2.3* to 2.4* caused new self signed ssl cert to be selected for WebConfig
The only way that will happen is if the certificate is invalid in some way. Missing entirely, incorrect reference, or... Jim Pingle
02:34 AM Bug #8150 (Not a Bug): upgrade from 2.3* to 2.4* caused new self signed ssl cert to be selected for WebConfig
We recently upgraded several pfsense installs from 2.3.x to 2.4.y.
All these installs had properly signed SSL cer...
Oliver Schonrock
09:52 AM Bug #8152 (Not a Bug): No DHCP on WAN with cable modem
I have a similar modem and it works fine here.
With modems that behave in that way you should go to Interfaces > W...
Jim Pingle
09:41 AM Bug #8152 (Not a Bug): No DHCP on WAN with cable modem
My cable modem (SagemCom FAST3686v2 - in bridge mode) when rebooting, first assigns an IP address in the 192.168.100.... Andras Gaal
09:21 AM pfSense Packages Bug #8144: Failed coreboot upgrade
Then you may be hitting the issue on the other ticket, read through the discussion on #8047 and leave a comment there. Jim Pingle
02:16 AM pfSense Packages Bug #8144: Failed coreboot upgrade
Now I have tried running the command:
/sbin/poweroff
And have hit the power button and it is still ADI_RCC-01.00....
Tino Zidore
01:55 AM pfSense Packages Bug #8144: Failed coreboot upgrade
When I try to do the upgrade through the web GUI, this is the warning:
WARNING: This operation requires a reboot.
...
Tino Zidore
07:31 AM Bug #8151: Changing name on a gateway is not allowed
ok. i`m curious why is it so more complex to do besides renaming other things like Aliasses etc...
what can i do o...
Roland Kletzing
07:25 AM Bug #8151: Changing name on a gateway is not allowed
The gateway is referenced by name throughout the configuration in places like firewall rules for policy routing, rout... Jim Pingle
07:23 AM Bug #8151 (Resolved): Changing name on a gateway is not allowed
I want to change the name of a WAN gateway.

When editing the name field in the dialog, on save i get
"Changing...
Roland Kletzing
06:23 AM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
We got access to the machine this morning, and tested for ~30 mins could not duplicate the results. This seems loca... Chris Macmahon

11/30/2017

11:02 PM pfSense Packages Bug #8139: LADVD not working on LAGG interfaces
Random User wrote:
> Tom Cosmos wrote:
> > Issue was not occurring before 2.4.
>
> Never ever worked with lagg/...
Tom Cosmos
03:17 PM pfSense Packages Bug #8139: LADVD not working on LAGG interfaces
Tom Cosmos wrote:
> Issue was not occurring before 2.4.
Never ever worked with lagg/bridge (Bug #3962). It's eve...
Random User
10:48 PM Revision 79330f5d: Merge pull request #3880 from bibz0r/master
Steve Beaver
10:47 PM Revision 761b39f9: Merge pull request #3863 from PiBa-NL/20171103-routes-recursive-alias
Steve Beaver
10:46 PM Revision 7cde5013: Merge pull request #3873 from PiBa-NL/20171121-localauth-translated-problem
Steve Beaver
09:07 PM Feature #8149 (New): NTPsec
Would pfSense integrate NTPsec client/sever support to help protect OpenVPN against MITM attacks? Denial of service c... Richard Yao
08:57 PM Revision 71f0623e: routing, support use of recursive network aliases in static routes
Pi Ba
07:30 PM Revision 9fa718d7: Merge pull request #3823 from PiBa-NL/20170919-bootupcomplete
Steve Beaver
07:17 PM Revision ae6a2218: Merge pull request #3810 from svenauhagen/bugfix/mpd
Steve Beaver
07:15 PM Revision 745bf227: Merge pull request #3801 from cgull/radvd-zero-router-lifetime
Steve Beaver
06:56 PM Revision 42824fc3: notify_monitor, don't write EXITQUEUELOCK debug output to system-console
Pi Ba
01:24 PM pfSense Packages Feature #8148: OpenVPN - Output Windows Client .MSI Installer for GPO deployment
The procedure you linked is for the (paid) OpenVPN Access Server client. There is no MSI for the OpenVPN community cl... Jim Pingle
01:16 PM pfSense Packages Feature #8148 (New): OpenVPN - Output Windows Client .MSI Installer for GPO deployment
First, pfSense is a great product. I appreciate all of the development efforts.
It would be very helpful if the O...
Jason Gibbons
12:07 PM Bug #8124: username/password not used by proxy support
Hello,
Thank you for your answer.
Yes it work for HTTP request. You can see the picture "pfsense http and https...
O 71
08:14 AM Bug #8124 (Feedback): username/password not used by proxy support
There was a FreeBSD bug about that, see #6949, but that's been fixed for a while now. If the proxy auth works for HTT... Jim Pingle
10:21 AM Bug #8142: OpenVPN client does not remove static route for custom monitor IP
I'll have to try to setup a reproduction scenario in my lab on a vm, but fwiw, I am using the same vpn provider as th... Derek Battams
07:59 AM Bug #8142 (Feedback): OpenVPN client does not remove static route for custom monitor IP
There must be something more to it than that alone, as I can't reproduce the problem by simply setting an alternate m... Jim Pingle
09:37 AM Bug #7266: SNMP does not listen on IPv6 interface
Yes, use net-snmp. This is not the place for discussion or instruction, however. Post a thread on the forum, mailing ... Jim Pingle
08:53 AM Bug #7266: SNMP does not listen on IPv6 interface
@Marcel Hellwig: We just upgraded to pfSense 2.4.2 but snmp is still not listening on IPv6. Is the solution to manual... Stefan Kooman
08:53 AM pfSense Packages Feature #8147: include a serial console file tranfer utility like "kermit" in the installer image
I agree this should be closed, because your recovery process is very good (if it works and people know about it and u... Oliver Schonrock
07:35 AM pfSense Packages Feature #8147 (Closed): include a serial console file tranfer utility like "kermit" in the installer image
The automatic restore looks at the selected disk, runs a disk check, then mounts it and looks in /cf/conf/config.xml ... Jim Pingle
06:47 AM pfSense Packages Feature #8147: include a serial console file tranfer utility like "kermit" in the installer image
Just found this article (I had limited internet access during recovery)
https://doc.pfsense.org/index.php/Automati...
Oliver Schonrock
06:36 AM pfSense Packages Feature #8147 (Closed): include a serial console file tranfer utility like "kermit" in the installer image
h3. Scenario
- I updated from 2.3 => 2.4 (FreeBSD 11) and it went badly
- I wanted to recover my config.xml (I kn...
Oliver Schonrock
08:24 AM Bug #8137 (Rejected): 2.4.2 openvpn stop working
There is not enough detail here for a proper bug report. Please post on the forum, mailing list, or pfSense subreddit... Jim Pingle
08:22 AM Bug #8134 (Rejected): upgrading sg-8860 unit with online upgrade trashes unit to non-working state (packages, libraries missing and so on)
Unable to reproduce the issue. It works here when we try it and as Clinton said that is a test we run before every re... Jim Pingle
08:16 AM Bug #8133 (Rejected): PPPoE over Vlan is no longer work after update.
Please post on the forum, mailing list, or pfSense subreddit with more detail to discuss the issue before opening a b... Jim Pingle
08:06 AM Bug #8128 (Rejected): Port Forwarding over VPN connections
Jim Pingle
07:52 AM pfSense Packages Bug #8144 (Duplicate): Failed coreboot upgrade
Based on the serial number this appears to be an XG-2758, is that correct?
On that model you have to physically po...
Jim Pingle
07:37 AM Bug #8145 (Duplicate): Recurring deadlock during normal operation.
Duplicate of #8056 Jim Pingle
12:00 AM Revision dcf0318a: Merge pull request #3759 from PiBa-NL/20170618-option-disable-dragging
Steve Beaver

11/29/2017

11:18 PM Revision 2c131b10: Increase FPM process availability in high ram systems
To reduce chance of nginx gateway error when interacting with FPM backend, this patch does the following, starts up e... Martin Wasley
11:15 PM Revision 52e91f70: webgui, option to disable dragging of rules
Pi Ba
07:41 PM Revision 04168bdd: Merge pull request #3776 from nazar-pc/ram-disk-reboot-fix
Steve Beaver
06:10 PM Revision 74c55258: Merge pull request #3868 from loonylion/master
Steve Beaver
06:05 PM Revision 2acb4025: Merge pull request #3818 from chewrocca/master
Steve Beaver
06:04 PM Revision d7dc67f9: interfaces_fast.inc: removed accidental rolling 'r' from comment
removed unused parameters from definition of convert_real_interface_to_friendly_interface_name_fast()
interfaces_ass...
Peter Schofield
06:03 PM Revision 7dee52b7: Merge branch 'master' into master
Matthew Fine
06:02 PM Revision 12e3bbce: Merge branch 'master' into master
Matthew Fine
05:40 PM Bug #8145: Recurring deadlock during normal operation.
Harry Coin wrote:
> Note also the web interface is not responsive during the deadlock. Basically, any process that ...
Harry Coin
02:32 PM Bug #8145: Recurring deadlock during normal operation.
Note also the web interface is not responsive during the deadlock. Basically, any process that doesn't touch the net... Harry Coin
02:26 PM Bug #8145: Recurring deadlock during normal operation.
... Harry Coin
10:28 AM Bug #8145 (Duplicate): Recurring deadlock during normal operation.
At seemingly random intervals during normal operation, intervals as long as several hours and as short as several min... Harry Coin
05:13 PM Revision f2d91ecf: Merge pull request #3870 from jtl999/v2.4.2rc-dhcp6fix
Steve Beaver
05:12 PM Revision f9e1a5dc: Merge pull request #3844 from luckman212/ovpn-gw-patch-2
Steve Beaver
05:06 PM Revision 65a8a5ad: Merge pull request #3769 from PiBa-NL/20170626-phpfpm-status
Steve Beaver
05:05 PM Revision 2dbc276d: Merge pull request #3183 from znerol/feature/master/register-openvpn-cn
Steve Beaver
02:57 PM Revision c1a2c6c8: Changed license as requested and added a missing apostrophe in a comment.
Peter Schofield
02:50 PM Revision 6cce4ec9: Merge pull request #3875 from LedPighp/dyndns_godaddy
Steve Beaver
02:48 PM Revision a84fb545: Changed maximum length of usernames from 16 to 32 characters. This seems to be some old FreeBSD requirement which is not needed anymore.
Andrei Miu
02:47 PM Revision 3a402755: Merge pull request #3872 from jackfagner/patch-1
Steve Beaver
02:35 PM Revision 2730dcce: Merge pull request #3865 from VPSrv/v2_3-patch-1
Steve Beaver
02:15 PM Revision 47741e4c: Merge pull request #3825 from adam820/helptext-cleanup
Steve Beaver
02:14 PM Revision cca4802a: Merge pull request #3824 from cfazendin/ddns_widget
Steve Beaver
02:07 PM Revision 884ea644: Merge pull request #3820 from phil-davis/status-if-disabled
Steve Beaver
02:05 PM Revision f5cd3884: Merge pull request #3819 from PiBa-NL/20170910-show-interface-openvpn
Steve Beaver
01:56 PM Revision 98e865f1: Merge pull request #3802 from svenauhagen/bugfix/ppp
Steve Beaver
01:52 PM Revision 327d7996: Merge pull request #3797 from IknowJoseph/patch-1
Steve Beaver
01:51 PM Revision 2ba7f14f: Remove haproxy-devel from i386
haproxy-devel 1.8.0 doesn't build on i386 with old clang versions. It
produces errors like:
cannot compile this at...
Renato Botelho
01:41 PM Revision 258a5feb: Merge pull request #3768 from PiBa-NL/20170625-notices-queue
Steve Beaver
01:38 PM Revision 57a01a3a: Remove haproxy-devel from i386
haproxy-devel 1.8.0 doesn't build on i386 with old clang versions. It
produces errors like:
cannot compile this at...
Renato Botelho
01:32 PM Revision c6ce0d99: Merge pull request #3747 from PiBa-NL/20170529-dhcprelay-destination-interface-discovery
Steve Beaver
01:18 PM Revision 5de5c48a: Merge pull request #3738 from PiBa-NL/20170521-oneonone-nat-fix-empty-ip
Steve Beaver
12:49 PM pfSense Packages Feature #8146 (New): Zone Domain Records more powerfull for BIND Zones
Hi guys.
Thanks in advance for your effort.
Please, could you add on the UI?:
* Availability to move the reco...
Hernan Nacimiento
08:20 AM Feature #7843 (Feedback): DynamicDNS Widget - Show Description
Applied in changeset commit:4c53dfbe72a0bd25afeb8f8203c0daf008bb41a4. Christopher Fazendin
03:00 AM pfSense Packages Bug #8144: Failed coreboot upgrade
I forgot it was a Netgate coreboot upgrade I tried;-) Tino Zidore
02:59 AM pfSense Packages Bug #8144 (Duplicate): Failed coreboot upgrade
Hi
I have tried to upgrade through the Web GUI and I get this error....
Tino Zidore

11/28/2017

09:41 PM Revision 36ca9be2: Fixed #8143 Remove any html special characters for request variable
Stephen Jones
09:39 PM Revision 11b3b8e6: Fixed #8143 Remove any html special characters for request variable
Stephen Jones
09:30 PM Revision fea5a8af: Fixed #8143 Remove any html special characters for request variable
Stephen Jones
09:28 PM Revision 82b1d76f: Fixed #8143 Remove any html special characters for request variable
Stephen Jones
04:42 PM Revision e9f2afc4: 2.4.2 was released
Renato Botelho
03:40 PM Bug #8143 (Feedback): XSS in status_filter_reload.php
Applied in changeset commit:82b1d76f934d793fe681c9c80da1a8e32cefc1f5. Anonymous
03:17 PM Bug #8143: XSS in status_filter_reload.php
Usually we will push a fix to master and cherry pick it to the latest development and release branches, which right n... Jim Pingle
03:01 PM Bug #8143 (Resolved): XSS in status_filter_reload.php
I am not sure the procedure for pushing fixes like this. If I push it to gitlab will it be public? I wouldn't want to... Anonymous
12:03 PM pfSense Packages Bug #8141: ACB uploads a version several times each second/minute when CaptivePortal is active.
Where can I find a updated version for me to test? klaus johnstad
11:58 AM pfSense Packages Bug #8141 (Feedback): ACB uploads a version several times each second/minute when CaptivePortal is active.
Updated to add an input to ignore uploading a config if it contains 'Syncing vouchers' as the reason. This is default... Anonymous
08:32 AM pfSense Packages Bug #8141: ACB uploads a version several times each second/minute when CaptivePortal is active.
Coincidentally this issue was discovered a couple of days ago and is under investigation. Anonymous
07:52 AM pfSense Packages Bug #8141 (Resolved): ACB uploads a version several times each second/minute when CaptivePortal is active.
When I have CaptivePortal enabled, ACB uploads a copy of my config between once and 5 times every second during peak ... klaus johnstad
11:52 AM Bug #8142 (Resolved): OpenVPN client does not remove static route for custom monitor IP
Since upgrading from 2.3.4 to 2.4.2 I've had this problem with my OpenVPN clients that specify a custom monitoring IP... Derek Battams
05:46 AM Bug #8134: upgrading sg-8860 unit with online upgrade trashes unit to non-working state (packages, libraries missing and so on)
Clinton Cory wrote:
> Installed ADI 2.3.5-RELEASE on SG-8860-1U
> An upgrade displayed for 2.4.1
> Selected the op...
Eero Volotinen
03:10 AM pfSense Packages Feature #7519: Add support for --listen-v6 to ACME standalone webserver
+1
I just ran into this today. I tried to get the Lets Encrypt working. I only have an IPv6 DNS name associated ...
David Summers
03:04 AM pfSense Packages Bug #8126: ACME standalone HTTP not listening on IPv6
I'm having the exact same problem.
I only have an IPv6 address for the DNS name of my pfsense router.
Once I ha...
David Summers

11/27/2017

11:55 PM Feature #8140 (Duplicate): Feature Request: Zone Firewall between interfaces
Zone Firewalls are very powerful and solve a lot of the current problems with firewalls using the current non-Zoned f... David Summers
08:33 PM pfSense Packages Bug #8139 (Resolved): LADVD not working on LAGG interfaces
https://forum.pfsense.org/index.php?topic=138119.0
Interfaces in bond reporting in logs as invalid for LADVD
No...
Tom Cosmos
12:43 PM Bug #8138 (Resolved): Option <spoofmac> is ignored on interfaces without hwaddr
MAC Address in GUI is not applyed to interface and allways set to random value. This causes a lot of problems if inte... Michael Sh.
11:26 AM Bug #8137 (Rejected): 2.4.2 openvpn stop working
My openvpn setup have worked for multiples years and survive multiple upgrades, but since I have upgrade from 2.4.1 t... Eric D
10:26 AM Bug #8134: upgrading sg-8860 unit with online upgrade trashes unit to non-working state (packages, libraries missing and so on)
Installed ADI 2.3.5-RELEASE on SG-8860-1U
An upgrade displayed for 2.4.1
Selected the option to upgrade and was upg...
Clinton Cory
12:43 AM Bug #8134 (Rejected): upgrading sg-8860 unit with online upgrade trashes unit to non-working state (packages, libraries missing and so on)
upgrading sg-8860 unit with online upgrade trashes unit to non-working state (packages, libraries missing and so on)
...
Eero Volotinen
09:46 AM Bug #8136 (Resolved): dpinger for WAN DHCPv6 gets fails to update gateway IP
There appears to be an issue with dpinger when the IPv6 link-local address for a native DHCPv6 connection changes.
...
Kristopher Kolpin
07:35 AM Bug #7532: SG-1000 autonegotiation 10baseT speed and duplex
10FD still does not work.
Steve found that 100FD works with crossover. I checked manual 100FD on both sides with cro...
Constantine Kormashev
05:11 AM Feature #7666: Adding SAN DNS:username to User Certificates that are created via User Manager the same way as it is done via Cert. Manager
Pardon for late reply.
Yes, user certs that are (auto)generated via _System > User manager > Users > Add_ now work w...
Reinis Adovics
04:26 AM Bug #8135 (Closed): pfSense deletes itself after upgrade from 2.2.6 to 2.3.5 with haproxy installed
How to reproduce:
# Install 2.2.6 (I used an APU.2C2)
# Install haproxy
# Upgrade to 2.3.5...
Tom Mü-Ko
02:31 AM Bug #8079: XMLRPC Issues with Captive Portal Vouchers
Master and slave servers still do not communicate 100% properly in relation to expired/active vouchers and do not upd... Dejan Milojevic

11/26/2017

10:27 PM Bug #8133: PPPoE over Vlan is no longer work after update.
I downgrade to 2.3.3 and everything work. Hoan Bui Huy
10:24 PM Bug #8133 (Rejected): PPPoE over Vlan is no longer work after update.
I got 2 Wans, the first one is running PPPoE without Vlan, another one is running PPPoE over Vlan 0/35. Everything is... Hoan Bui Huy
04:51 PM Bug #8132: OpenVPN tap device support is very limited/buggy
Here is another use case for fixing the issues OpenVPN tap support. If you want to enforce least privilege such that ... Richard Yao
04:30 PM Bug #8132 (Rejected): OpenVPN tap device support is very limited/buggy
I am (ab)using OpenVPN to extend my network across wireless bridges to mitigate both KRACK and future WPA2 exploits o... Richard Yao
04:29 PM Bug #8131 (Rejected): No way to configure static ARP entries on a /31 (need a better way to configure static ARP entries)
Configuration of static ARP entries is done through the DHCP server interface, even if it is not enabled. When using ... Richard Yao
01:40 PM Bug #8130 (New): Status - Monitoring - Area chart displays traffic data differently than Line or Bar charts
When setting a traffic chart to Area, portions of the chart where +Y (inpass) values are relatively high show 0 value... Eduard Rozenberg
01:14 PM Bug #8129 (Resolved): NTP Status -> Server time value incorrect for timezone Asia/Kolkata
When using timezone set to Asia/Kolkata (a timezone on the 1/2 hour), the time showing in the dashboard widget NTP St... Eduard Rozenberg
09:47 AM pfSense Packages Bug #8115: After update 2.3.4_1-> 2.4.0 ospf over gre looks broken
In my case:... Wagner Sartori Junior
09:39 AM pfSense Packages Bug #8115: After update 2.3.4_1-> 2.4.0 ospf over gre looks broken
Hi Wagner .Could you advice on exact cronjob workaround ? Konstantin Pobudzey
09:30 AM pfSense Packages Bug #8115: After update 2.3.4_1-> 2.4.0 ospf over gre looks broken
same here. GRE under ipsec. I setup a cronjob every minute correcting the mtu when needed, my tunnels are up now. I'm... Wagner Sartori Junior
09:41 AM Bug #8125: gateway 502 errors proposed fix for high ram systems
Chris had asked me to do a commit for this, but I was a bit slack in doing so, now done. PR 3881 Martin Wasley
05:33 AM Bug #8124: username/password not used by proxy support
Hello,
I did other tests.
The proxy works with websites in http but not in https. If I do 'fetch -v http: //www...
O 71

11/25/2017

10:34 PM pfSense Packages Feature #7519: Add support for --listen-v6 to ACME standalone webserver
Pim, thanks for the info about @ncaddr@. My request was not about the script itself but about the UI, to provide a an... Michael Duller
08:18 AM pfSense Packages Feature #7519: Add support for --listen-v6 to ACME standalone webserver
The acme.sh script also knows the _ncaddr_ variable. If it is set to a specific IPv6 address all works so no modifica... Pim Pish
02:55 PM Bug #8128: Port Forwarding over VPN connections
Please post to the forum at https://forum.pfsense.org/ and return if consensus is reached that it is a bug and not a ... Chris Linstruth
02:37 PM Bug #8128 (Rejected): Port Forwarding over VPN connections
After upgrade from 2.3.4 to 2.4.0, I am unable to port forward SMTP through my VPN interface. I have verified Port Fo... Tyler Yokley
08:16 AM Feature #8127 (Duplicate): searching for certificates
Hi
For easier working - if you have a lot of certificats (users and servers) that there's kind of tab interface or ...
Chris Macmahon
07:37 AM pfSense Packages Bug #8126 (Duplicate): ACME standalone HTTP not listening on IPv6
Duplicate of #7519 Jim Pingle
07:07 AM pfSense Packages Bug #8126 (Duplicate): ACME standalone HTTP not listening on IPv6
When I try to register a certificate via the ACME service I have a DNS name that only has an IPv6 record (AAAA). When... Pim Pish

11/24/2017

08:26 PM Revision f810e576: GoDaddy allows a hostname of @
Sam Neely
03:32 PM Bug #8125: gateway 502 errors proposed fix for high ram systems
I’m in favor of incorporating this. Assigned to Beaver for evaluation. Target set to 2.4.3
Thanks, Chris.
Jim Thompson
02:42 PM Bug #8125 (Resolved): gateway 502 errors proposed fix for high ram systems
I noticed lately multiple forum threads on gateway 502 errors, when this occurs it is because nginx cannot talk to FP... Chris Collins
10:44 AM Feature #3185: Accommodate a DHCPv6 failover-like mechanism
A tick box to detect if the DHCPv6 server should be running based on interface CARP state and copy of the reservation... Neal Harrington
06:51 AM Bug #8124: username/password not used by proxy support
I add a file, with a packet capture.
Thanks a lot
O 71
04:30 AM Bug #8124 (Closed): username/password not used by proxy support
Hello,
I have problem to configure Proxy with authentification. I go in System>Advanced>Miscellaneous and I config...
O 71
03:40 AM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
I tried everything I can, but I cannot find why the GUI gives a "session_Timeout" after around 10 minutes.
I tried...
Jimmy Meskens
01:23 AM Revision 456ba14f: Feature #8123: Add GoDaddy as a Dynamic DNS provider
Sam Neely

11/23/2017

07:59 PM Bug #8071: DNSimple support for Dynamic DNS no longer working
The offending file is:
/etc/inc/dyndns.class
pfSense has the ability to edit files from the webpage GUI (Diagnost...
Peter Wilson
07:41 PM Feature #8123: Add GoDaddy as a Dynamic DNS provider
Pull request https://github.com/pfsense/pfsense/pull/3875 submitted. Sam Neely
07:21 PM Feature #8123 (Resolved): Add GoDaddy as a Dynamic DNS provider
Add GoDaddy and GoDaddy (v6) to the list of Dynamic DNS providers. Sam Neely
07:04 PM Feature #1831: Captive portal IPv6 support
With the growing demand for IPv6 it is essential that this feature is implemented ASAP.
Do we have a timeline on whe...
James Webb
01:14 PM Bug #6400: assign_interfaces.php issues with large numbers of interfaces
I have submitted a pull request that addresses this, waiting on pfSense devs now. Peter Schofield
11:49 AM Bug #8122 (New): openvpn client is unable to use OTP (temporary) passwords
While the upstream OpenVPN client is able to load one-time passwords from the file mentioned by the auth-user-pass pa... Sorin Sbarnea
10:28 AM Bug #7916: There were error(s) loading the rules: pfctl: ix0: driver does not support altq - The line in question reads [0]: | Intel X520-DA2
Same error on 2.4.2 :( Roman Fidi
04:04 AM pfSense Packages Feature #8121: haproxy, allow to generate backends even they don't seem to be used
just a side note: I didn't get it to work, having this action at the bottom of all actions in the generated configura... Thomas Spalinger
03:53 AM pfSense Packages Feature #8121 (New): haproxy, allow to generate backends even they don't seem to be used
I try to use my backends with custom action "use_backend bk_%[hdr(host)]" in the frontend.
The problem is, because t...
Thomas Spalinger
03:29 AM Bug #8120 (Resolved): Unable to disable DHCP Server on interface when DNS Resolver "DHCP Registration" is enabled
Subject covers this pretty clearly I think, but I'll elaborate with my repro steps. I chose "all" for affected arch b... Braden McGrath
03:15 AM Bug #8081: NICs malfunction
I'm having a similar problem, which persists into 2.4.2, with igb interfaces. The problem exhibits itself for me wit... Braden McGrath
01:47 AM Bug #8117: IPSec statuspage shows both connected and connecting tunnel
Hello Stephen,
The same connection as in the picture shows up (twice!) as follows in the cli:
bq. con59000: #17...
Ges Ture

11/22/2017

08:15 PM pfSense Packages Bug #7965: freeradius 3 with MySQL
new version package. Thx
And new problem with parsing. I use sql module with 1 sql server (NOT 2 servers!)
its lo...
Konstantin Ab
07:43 PM Bug #8119 (Not a Bug): Site to Site IPsec On a VM Not Routing
Following the guide at:
https://doc.pfsense.org/index.php/Routing_internet_traffic_through_a_site-to-site_OpenVPN-...
Kristopher Kolpin
07:35 PM Bug #7928: LAGG interfaces lose MAC address
Just the re2 NIC or the lagg interface also?
That sounds like a different issue if the parent NIC is actually losi...
Steve Wheeler
11:44 AM Bug #7928: LAGG interfaces lose MAC address
Similar issue here with 2.4.1 and 2.4.2. using LAG groups for statefull failover where nic on two generations of APU ... Gareth Jones
11:34 AM pfSense Packages Bug #8118 (Resolved): Note default key name when using RFC 2136
The Acme package assumes the key name _acme-challenge.<domain name> when using the "DNS-NSupdate / RFC 2136" update m... Isaac McDonald
10:52 AM Bug #8117: IPSec statuspage shows both connected and connecting tunnel
One thing to try would be in the command shell or in Diagnostics > Command Prompt type the command `swanctl --list-sa... Anonymous
09:25 AM Bug #8117 (Not a Bug): IPSec statuspage shows both connected and connecting tunnel
The bug started after upgrading from 2.3.4 to v2.4.1. Once in a while a number of IPSec tunnels show up as both conne... Ges Ture
10:00 AM Bug #7975 (Resolved): ESXi 6.5 UEFI boot stops at framebuffer info
Luiz Souza
03:47 AM Bug #7975: ESXi 6.5 UEFI boot stops at framebuffer info
Luiz Souza wrote:
> The changed that possibly cause this issue was reverted, please check with the next snapshot.
...
Rich Murphey
09:20 AM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
Thanks for your help, and I fully understand it is not that simple :)..
As a test, I tried to run same on another ...
Jimmy Meskens
09:09 AM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
As I stated above, if it was the timeout, there would be a log message. There is no log message, so it is not actuall... Jim Pingle
09:01 AM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
No the connection does not go through the Proxy.
Since all was working fine with 2.3.3, it definitely is something w...
Jimmy Meskens
08:35 AM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
Does your connection to the GUI go through the proxy? Usually that would not be the case if the proxy is on the firew... Jim Pingle
08:33 AM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
About nr. 5 ( Proxy ), Squid is configured in PFSENSE.
But it is weird that all worked fine with version 2.3.X, and ...
Jimmy Meskens
08:27 AM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
If there is no log message at all, then 5 in that list is the most likely issue. But I've gone through the base syste... Jim Pingle
08:27 AM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
It worked fine with version 2.3.x but I have the problem since 2.4.x Jimmy Meskens
08:25 AM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
No there is no timout logged in the log, I can only see when I reconnect again. Jimmy Meskens
08:25 AM Bug #8116 (Feedback): status_graph.php: Premature session termination when monitoring live traffic graphs
This does not appear to be a general issue. I've left that page open for nearly an hour now with the same settings yo... Jim Pingle
06:35 AM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
Is there a session timeout logged in the main system log when this happens? Jim Pingle
05:15 AM Bug #8116: status_graph.php: Premature session termination when monitoring live traffic graphs
Vladimir Lind wrote:
> During around 5 minutes RRD webpage shows the traffic data, then it shows a "SESSION_TIMEOUT"...
Jimmy Meskens
05:06 AM Bug #8116 (Resolved): status_graph.php: Premature session termination when monitoring live traffic graphs
During around 5 minutes RRD webpage shows the traffic data, then it shows a blank screen, and when refresh, logon to ... Vladimir Lind

11/21/2017

09:36 PM Revision 3e90d18b: local authentication option, use key value instead of translated name.
Pi Ba
07:41 PM pfSense Packages Bug #8115: After update 2.3.4_1-> 2.4.0 ospf over gre looks broken
Sorry picture broken . GRE tunnel inside IPSEC Konstantin Pobudzey
07:39 PM pfSense Packages Bug #8115 (Duplicate): After update 2.3.4_1-> 2.4.0 ospf over gre looks broken

#
#site1 ( 2.3.4_1 )
logs
Nov 4 09:47:58 ospfd 45632 Packet[DD]: Neighbor 10.10.10.18 MTU 1400 is large...
Konstantin Pobudzey
03:44 PM Bug #8114 (Not a Bug): DHCPv6 PD client not working after 2.4.2 upgrade
I was just double checking this and confirmed it was working here on a test box. Thanks for the follow-up. Jim Pingle
03:37 PM Bug #8114: DHCPv6 PD client not working after 2.4.2 upgrade
I'm sorry, somehow I made a mistake in my configuration just before the upgrade (disabled interface tracking). After ... Tim Balmer
02:27 PM Bug #8114 (Not a Bug): DHCPv6 PD client not working after 2.4.2 upgrade
I just upgraded from 2.4.1 to 2.4.2 but after the upgrade IPv6 is not working anymore. After checking the logs I see ... Tim Balmer
03:22 PM Revision db28039e: Fixed #8112
Steve Beaver
02:07 PM Bug #8108 (Closed): IPSec NAT issue
Ivor Kreso
02:07 PM Bug #8108: IPSec NAT issue
Please submit a bug with your problem description as we cannot pull random fixes.
Thank you.
Ivor Kreso
01:42 PM Bug #8075: OpenVPN binds to wrong interface with no ip on first interface
Workaround: bind both OpenVPNs to 127.0.0.1 (localhost) (use different ports). Then forward these ports to their resp... robi robi
01:38 PM Bug #8089: VLAN page breaks after config restore to new hardware.
Also related to https://redmine.pfsense.org/issues/8076 robi robi
01:33 PM Bug #8089: VLAN page breaks after config restore to new hardware.
Same here.
Workaround is to replace manually interface names from emX to igbX in config.xml, before restoration.
robi robi
01:38 PM Bug #8076: User can easily apply an unusable interface configuration after restore
Also related to https://redmine.pfsense.org/issues/8089 robi robi
01:37 PM Bug #8076: User can easily apply an unusable interface configuration after restore
In the interface setup page, when a mismatch of the network interfaces is detected, there should be options to fix VL... robi robi
12:46 PM Bug #8113 (New): MTU setting on bridge, openvpn clients ignored
I set the MTU field in the GUI for a pair of openvpn clients and the bridge interface to 1492.
However, the 'inter...
Harry Coin
10:57 AM Feature #6742: OAuth2 authentication for OpenVPN (and for FreeRadius)
+1 as well! we are building a ton of infrastructure just to tackle with this issue! would be so great to be able to a... Luis Paolini
10:40 AM Revision 5f56dee4: Bug in get_interface_ip
Global variable $config was not available, and IP was always fetched using find_interface_ip Jackson Laskoski
09:30 AM Bug #8112 (Feedback): Internal IP mask is always reset to /32 when editing a 1:1 NAT
Applied in changeset commit:db28039e4e8606cb8fdb4a342e5193f1a8a3db36. Anonymous
08:10 AM Bug #8112 (Confirmed): Internal IP mask is always reset to /32 when editing a 1:1 NAT
Jim Pingle
04:20 AM Bug #8112 (Resolved): Internal IP mask is always reset to /32 when editing a 1:1 NAT
Hi,
Whenever I edit a _1:1_ NAT, the mask of @Internal IP@ is always reset to @/32@, even when it was set to a diffe...
Louis Sautier
04:14 AM Bug #8111: Disabled 1:1 NATs are not passed the "disabled" class (not greyed out)
This seems to have been fixed in 2.4. Could we get it backported to 2.3? Louis Sautier
04:06 AM Bug #8111 (Resolved): Disabled 1:1 NATs are not passed the "disabled" class (not greyed out)
Hi,
I noticed that _Port Forward_ NATs get a @disabled@ CSS class in addition to the @fa-times@ icon. This makes the...
Louis Sautier

11/20/2017

06:07 PM Bug #8061: LAN WAN Interfaces missing in Traffichshaper
I have the same issue. WAN is nfe0. LAN is em0. Corey Boyle
02:49 PM Bug #8110: undefined functions validate_gateway($_post, $id) and save_gateway($_POST, $realid) in system_gateways_edit.php
The update process does check the integrity, but it's possible some other problem (disk issue, for example) can cause... Jim Pingle
02:47 PM Bug #8110: undefined functions validate_gateway($_post, $id) and save_gateway($_POST, $realid) in system_gateways_edit.php
those functions are NOT present in gwlb.inc in my install, and the file is not damaged. Clearly this is a partial upd... Peter Schofield
01:05 PM Bug #8110: undefined functions validate_gateway($_post, $id) and save_gateway($_POST, $realid) in system_gateways_edit.php
Jim Pingle wrote:
> hose functions are defined in source:src/etc/inc/gwlb.inc which is included through functions.in...
Random User
12:53 PM Bug #8110 (Not a Bug): undefined functions validate_gateway($_post, $id) and save_gateway($_POST, $realid) in system_gateways_edit.php
Those functions are defined in source:src/etc/inc/gwlb.inc which is included through functions.inc which is included ... Jim Pingle
12:44 PM Bug #8110 (Not a Bug): undefined functions validate_gateway($_post, $id) and save_gateway($_POST, $realid) in system_gateways_edit.php
While setting up he.net 6 to 4 tunnel as per the howto documented in the wiki, I ran into this while making the edits... Peter Schofield
02:23 PM Revision 1248a2fa: Add -i parameter to define SKIP_FNAL_RSYNC
Renato Botelho
02:23 PM Revision 693b0903: Add -i parameter to define SKIP_FNAL_RSYNC
Renato Botelho
02:21 PM Revision 6d448e2a: Add -i parameter to define SKIP_FNAL_RSYNC
Renato Botelho
02:21 PM Revision 1de3ef87: Add -i parameter to define SKIP_FNAL_RSYNC
Renato Botelho
02:21 PM Revision 158999e9: Add -i parameter to define SKIP_FNAL_RSYNC
Renato Botelho
01:42 PM Revision 196427f9: Add missing %%REPO_BRANCH_PREFIX%%
Renato Botelho
01:42 PM Revision 4b1f7145: Add missing %%REPO_BRANCH_PREFIX%%
Renato Botelho
01:28 PM Revision 98476258: Prevent Clickjacking in CSRF error page
Yorick Koster
01:21 PM Revision 386d89b0: Prevent Clickjacking in CSRF error page
(cherry picked from commit 6026c9dabdd66a154c8a9a5170947ea098959835) Jim Pingle
01:21 PM Revision 6026c9da: Prevent Clickjacking in CSRF error page
Jim Pingle
01:15 PM Revision ae268fd4: Point release to 2.4.2
Renato Botelho
01:14 PM Revision cf34b5d1: Fill REPO_BRANCH_PREFIX on poudriere make.conf
Renato Botelho
01:14 PM Revision 1b3abaab: Use REPO_BRANCH_PREFIX to define POUDRIERE_PORTS_GIT_URL
Renato Botelho
01:14 PM Revision 77c66e2d: Merge pull request #3871 from ykoster/master
Jim Pingle
01:14 PM Revision 55c31005: Stop trying to guess REPO_BRANCH_PREFIX
Renato Botelho
01:11 PM Revision b40ac1b2: Reduce the need to always track branch changes for factory
Renato Botelho
01:11 PM Revision a6e2c666: Remove specific repository for 2.4.2-RC
Renato Botelho
01:08 PM Revision efd01b2c: Point release to 2.4.2
Renato Botelho
01:07 PM Revision fc960e71: Fill REPO_BRANCH_PREFIX on poudriere make.conf
Renato Botelho
01:07 PM Revision 3f7100c1: Use REPO_BRANCH_PREFIX to define POUDRIERE_PORTS_GIT_URL
Renato Botelho
01:05 PM Revision 385e812b: Stop trying to guess REPO_BRANCH_PREFIX
Renato Botelho
01:05 PM Revision 9765570d: Reduce the need to always track branch changes for factory
Renato Botelho
01:01 PM Revision 4d07faca: Remove specific repository for 2.4.2-RC
Renato Botelho
12:49 PM Revision 441d1d4f: Make RELEASE repo branch point to 2.4.2
Renato Botelho
12:41 PM Revision 84a6c526: Fill REPO_BRANCH_PREFIX on poudriere make.conf
Renato Botelho
12:41 PM Revision e60d620b: Use REPO_BRANCH_PREFIX to define POUDRIERE_PORTS_GIT_URL
Renato Botelho
12:40 PM Revision 9a8b9949: Stop trying to guess REPO_BRANCH_PREFIX
Renato Botelho
12:40 PM Revision 3d2dba58: Reduce the need to always track branch changes for factory
Renato Botelho
12:39 PM Revision fd50e40e: Remove specific repository for 2.4.2-RC
Renato Botelho
12:36 PM Revision c1f18417: Fill REPO_BRANCH_PREFIX on poudriere make.conf
Renato Botelho
12:35 PM Revision 6c9689f4: Use REPO_BRANCH_PREFIX to define POUDRIERE_PORTS_GIT_URL
Renato Botelho
12:34 PM Revision 97f3f602: Stop trying to guess REPO_BRANCH_PREFIX
Renato Botelho
12:34 PM Revision 743cc0cc: Reduce the need to always track branch changes for factory
Renato Botelho
12:31 PM Revision 2d982d5b: Remove specific repository for 2.4.2-RC
Renato Botelho
12:09 PM Revision 8ffdcf26: Fill REPO_BRANCH_PREFIX on poudriere make.conf
Renato Botelho
11:48 AM Revision 568caf26: Use REPO_BRANCH_PREFIX to define POUDRIERE_PORTS_GIT_URL
Renato Botelho
11:48 AM Revision 956f71e8: Stop trying to guess REPO_BRANCH_PREFIX
Renato Botelho
11:42 AM Feature #8109 (Duplicate): UPnP & NAT-PMP ACL Aliases
Not sure if it's possible, but being able to use aliases in UPnP & NAT-PMP ACLs would be great.
That way I can jus...
Jonny Proud
11:31 AM Revision eacf9c93: Reduce the need to always track branch changes for factory
Renato Botelho
11:16 AM Revision 819e3ba4: Remove specific repository for 2.4.2-RC
Renato Botelho
11:14 AM Revision 8ab2e1ac: It's 2.4.2-RELEASE time
Renato Botelho
11:11 AM Revision 79a33eba: Send images to release-staging when SKIP_FINAL_RSYNC is set
Renato Botelho
11:11 AM Revision 2bf444aa: Send images to release-staging when SKIP_FINAL_RSYNC is set
Renato Botelho
11:11 AM Revision 8a0db282: Send images to release-staging when SKIP_FINAL_RSYNC is set
Renato Botelho
11:11 AM Revision dab621ab: Send images to release-staging when SKIP_FINAL_RSYNC is set
Renato Botelho
11:10 AM Revision 3c489426: Send images to release-staging when SKIP_FINAL_RSYNC is set
Renato Botelho
10:35 AM Bug #8108 (Closed): IPSec NAT issue
Hi,
I was searching to resolve a IPSec NAT issue on my platform and I found this bug on OpenSense (pfSense fork) :...
Thomas du Boÿs
06:53 AM Bug #8003: IPsec weirdness with 2.4.1
I've had these problems, as well as duplicate entries in the list, one in the state 'CONNECTING' and one in the state... Ges Ture
 

Also available in: Atom