Project

General

Profile

Activity

From 01/26/2018 to 02/24/2018

02/24/2018

11:05 PM Bug #6400: assign_interfaces.php issues with large numbers of interfaces
Retested With CE 2.4.3.a.20180224.1921 memstick installer and the interface names changed to match the NIC driver bei... Anonymous
10:17 PM Bug #6400: assign_interfaces.php issues with large numbers of interfaces
Tried logging out, WebGUI hung. Tried console menu options 11/16 to get the WebGUI back to no avail. Anonymous
09:59 PM Bug #6400: assign_interfaces.php issues with large numbers of interfaces
With the attached config's (1000-interface-config.xml) interfaces restored to 2.4.3.a.20180224.1542 running with 4G m... Anonymous
10:33 PM Bug #7308: ZFS installer - check storage capabilities
Tested with pfSense-CE-2.4.3-DEVELOPMENT-amd64-20180224-1921.iso and got the attached error with 2G memory, 4G storag... Anonymous
08:22 PM Revision 40a530a1: Filter vm.pmap.pti entries on loader.conf when necessary.
https://forum.pfsense.org/index.php?topic=144390.msg786182#msg786182 Luiz Souza

02/23/2018

09:30 PM Revision 93e287df: Merge remote-tracking branch 'upstream/master'
Phil DeMonaco
09:26 PM Revision db30293e: Bug 7905 - Auth Script & Openvpn Config
Replaces the current auth-user-pass-verify directive with the new plugin
call in the config-file generation code.
Al...
Phil DeMonaco
05:59 PM Revision 26a38669: Add GUI support to display and set the PTI state.
Luiz Souza
04:11 PM Bug #7905: OpenVPN Authentication Against Backend Stalls All Server Traffic
Note that the event_wait signal, the MULTI_sva, and the WARNING do not appear if the auth request fails. Phil DeMonaco
04:10 PM Bug #7905: OpenVPN Authentication Against Backend Stalls All Server Traffic
I'm really close to having this working on the 2.4.2-RELEASE code base, however, I'm running into an issue and I'm ho... Phil DeMonaco
07:39 AM Feature #8346 (New): Allow pfSense to act as an IPsec VPN client
It would be useful to let pfSense act as a VPN client itself and let it share a mobile style VPN connection to a remo... Michele Di Maria

02/22/2018

07:50 PM pfSense Packages Feature #8345 (Resolved): pfSense-pkg-softflowd: Added additional options now available in softflowd-0.9.9_1
See pull request: https://github.com/pfsense/FreeBSD-ports/pull/501
---
Updated package version to 1.2.3
Inc...
Paul Godard
05:59 PM Revision e0ed03f3: Update translation files
Renato Botelho
05:07 PM Revision 37e9cfbd: Regenerate pot
Renato Botelho
01:49 PM Bug #8056: Bridge + CARP crashes/freezes pfSense
I also have exactly the same issue on netgate appliances 8860. I first thought it is a hardware problem and migrated ... Andreas Kaindl
12:51 PM Revision 789cb7f5: Merge pull request #3892 from al-right/master
Renato Botelho
11:26 AM Revision 0152ee69: Enable build of net-mgmt/pfSense-pkg-lldpd
Renato Botelho
11:25 AM Revision 20c85efd: Enable build of net-mgmt/pfSense-pkg-lldpd
Renato Botelho
10:08 AM Bug #8337 (Resolved): System Authservers page Authentication Containers field should be marked required
Field is marked required now Jim Pingle
10:08 AM Bug #8338 (Resolved): Wrong LDAP host is reported when testing system auth server settings
Prints the correct server now Jim Pingle
06:52 AM Bug #7413 (Feedback): status_dhcpv6_leases.php: Some DHCPv6 leases are not displayed in the GUI
PR has been merged Renato Botelho

02/21/2018

08:26 PM Revision 40fd222c: Merge pull request #3906 from phil-davis/system_authservers-authentication-containers-01
Steve Beaver
08:26 PM Revision e8f6e66e: Merge pull request #3907 from phil-davis/auth-server-test-output-01
Steve Beaver
03:17 PM pfSense Packages Feature #7706 (Resolved): Add option to write certificate to the filesystem after renew
Works fine Jim Pingle
03:10 PM Todo #8331 (Resolved): Update Copyright Year on GUI Login page
Jim Pingle
03:08 PM pfSense Packages Bug #8339 (Resolved): quagga: ospfd crashes with assertion since upgrade to quagga-1.2.3
Everyone should have 1.2.4 now Jim Pingle
03:05 PM Bug #8337 (Feedback): System Authservers page Authentication Containers field should be marked required
PR is at https://github.com/pfsense/pfsense/pull/3906 and has been merged Jim Pingle
03:05 PM Bug #8338 (Feedback): Wrong LDAP host is reported when testing system auth server settings
PR is at https://github.com/pfsense/pfsense/pull/3907 and has been merged Jim Pingle
11:53 AM Bug #8344 (Not a Bug): zfs mountroot still broken in 2.4.3.a.20180221.0835
Current snapshots are fine with zfs. Most likely your last update from before this snapshot wiped that out, not the c... Jim Pingle
11:41 AM Bug #8344: zfs mountroot still broken in 2.4.3.a.20180221.0835
(might also have eaten load_dummynet, for the folks who have active limiters)
ROB VANHOOREN
11:38 AM Bug #8344 (Not a Bug): zfs mountroot still broken in 2.4.3.a.20180221.0835
loos' recent commit hosed loader.conf; systems fail reboot at mountroot> b/c opensolaris & zfs ko's don't get loaded.... ROB VANHOOREN
07:29 AM Feature #7321: DynDNS - Add DreamHost DNS support
Dreamhost is not an option in the ACME package. However, I was able to get around this by using the "standalone HTTP ... Corey Boyle
03:39 AM Feature #8289: OpenVPN - configurable username as common name
Greg M wrote:
> Hi!
>
> See here: https://forum.pfsense.org/index.php?topic=136533.msg778977#msg778977
>
> The...
Jose Angel Mateo

02/20/2018

04:34 PM Feature #7321: DynDNS - Add DreamHost DNS support
@corey I saw your note about adding this to the ACME package. Were you able to do this? I did not see Dreamhost in th... Joshua Kugler
03:24 PM Bug #8341: NAT Port forwarding issues (port collision from internal host)
Tried to reproduce in lab. Not successful. Some additional factor must be involved. Beat Siegenthaler
09:54 AM Bug #8341: NAT Port forwarding issues (port collision from internal host)
Jim Pingle wrote:
>the only time you'd have a collision is if you forward a port and both the local source port, loc...
Beat Siegenthaler
07:17 AM Bug #8341 (Rejected): NAT Port forwarding issues (port collision from internal host)
There isn't a way to automatically detect or predict that scenario to prevent it.
Outbound NAT uses random ports a...
Jim Pingle
04:37 AM Bug #8341 (Rejected): NAT Port forwarding issues (port collision from internal host)
I think this should be omitted by design:
Found following constellation who troubled me for many hours:
PortNAT: ...
Beat Siegenthaler
12:25 PM pfSense Packages Bug #8339: quagga: ospfd crashes with assertion since upgrade to quagga-1.2.3
We're aware, we'll have it updated soon.
In the meantime, consider switching to the FRR package.
Jim Pingle
11:58 AM pfSense Packages Bug #8339: quagga: ospfd crashes with assertion since upgrade to quagga-1.2.3
quagga 1.2.4 with the fix has been released:
https://savannah.nongnu.org/forum/forum.php?forum_id=9099
https://www....
Nico Weichbrodt
11:12 AM Bug #8336: ESXi 6.5u1 displays superfluous error message with Netgate OVA iamge
Confirming that it occurs (as expected) in 2.4.2_1. Warning text does not change.
Adam Thompson
10:30 AM Bug #7735 (Not a Bug): Switching to wildcard cert fails until reboot
Jim Pingle
10:28 AM Bug #7735: Switching to wildcard cert fails until reboot
I've been unable to reproduce this in the 2.4 stream, so please close either with CAN'T REPRODUCE or FIXED IN 2.4 (or... Adam Thompson
09:04 AM Bug #8343 (Resolved): Gateway Routes (Default Routes) not removed in Kernel when removed from GUI
When I disable the Gateway (default) in System > Routing > Gateways it is still visible as a static route in Diagnost... Sandro Bolliger
08:25 AM Bug #7308 (Feedback): ZFS installer - check storage capabilities
Changed installer to request more space to install on ZFS Renato Botelho

02/19/2018

05:43 PM pfSense Packages Bug #8340 (Rejected): Status_Traffic_Totals Error
While checking in on my traffic totals using the Status_Traffic_Totals package I've gotten an error that I can't fix.... Matthew Drury
04:21 PM Revision e6e7b00c: Trim domain for learned DNS entries. Ticket #6847
If the CN is already an FQDN on the given domain, this prevents the
domain from being present in the record twice (e....
Jim Pingle
03:33 PM pfSense Packages Bug #8339 (Resolved): quagga: ospfd crashes with assertion since upgrade to quagga-1.2.3
Hi, ospfd crashes with an assertion since I upgraded to 1.2.3 (upgraded Quagga_OSPF to 0.6.20_2):... Nico Weichbrodt
01:26 PM Bug #7469 (Resolved): local_sync_accounts() slowness can trigger GUI/XMLRPC failures with many accounts
Renato Botelho
11:44 AM Bug #8298 (Resolved): OpenVPN Wizard protocol defaults to "UDP IPv4 and IPv6 on all interfaces" causing problems
Wizard now has all of the current protocol choices and defaults to the correct selection (UDP on IPv4 only). Jim Pingle
11:30 AM Bug #8261 (Resolved): OpenVPN tunnel network handled incorrectly with a /31 tunnel network
Tunnel networks are calculated properly with /31 now Jim Pingle
10:53 AM Bug #8125 (Resolved): gateway 502 errors proposed fix for high ram systems
Parameters are changing with RAM size as expected, seems to work OK. Jim Pingle
10:52 AM Bug #7772: Regression of Bug #906
Steve Beaver wrote:
> Can you provide simple steps to reproduce please?
I eventually fixed the issue of the left ...
Lance Fogle
10:24 AM Feature #6847 (Resolved): Register CN of OpenVPN clients in DNS Resolver
Seems to work OK but needed a minor tweak in the script, see commit:e6e7b00c5c Jim Pingle
09:36 AM Feature #8205 (Resolved): Allow display of temperature in Fahrenheit
Works Jim Pingle
08:24 AM Feature #6886 (Resolved): Allow Dual-Stack IPSec VPN
Tested and working Jim Pingle
08:24 AM Feature #8186 (Resolved): ipsec, allow configuration of multiple ike phase1 encryption ciphers #3711
Jim Pingle
08:08 AM Bug #4310: Limiters + HA results in hangs on secondary
Fabrizio Pappolla wrote:
> Before open a new ticket, i will try here since the error looks really similar. My pfSens...
Jim Pingle
05:29 AM Bug #4310: Limiters + HA results in hangs on secondary
Before open a new ticket, i will try here since the error looks really similar. My pfSense got bootloop, the problem ... Fabrizio Pappolla
12:25 AM Revision ab105bf8: Do not wipe the existing file contents. Return the actual data.
Luiz Souza

02/18/2018

10:14 PM Revision d0490bd0: Merge branch 'master' of github.com:pdemonaco/pfsense
Because I did something out of order? Phil DeMonaco
10:13 PM Revision 4e74cced: Bug 7905 - Minor Tweaks
Switched to printf over echo to ensure strict POSIX compliance. Also
added some comments regarding the source of two ...
Phil DeMonaco
10:13 PM Revision b27ae464: Bug 7905 - New Auth Script
Initial pass at new auth script which will be called by an openvpn
plugin. See https://github.com/pdemonaco/auth-scri...
Phil DeMonaco
01:03 AM Revision 5a29b7d6: Bug 7905 - Minor Tweaks
Switched to printf over echo to ensure strict POSIX compliance. Also
added some comments regarding the source of two ...
Phil DeMonaco
12:55 AM Revision 1ed23afb: Bug 7905 - New Auth Script
Initial pass at new auth script which will be called by an openvpn
plugin. See https://github.com/pdemonaco/auth-scri...
Phil DeMonaco

02/17/2018

07:39 PM Revision 56b72761: Fix the variable name.
Pointy-hat to: me Luiz Souza
11:40 AM Revision 34925626: Report correct auth server host when testing LDAP auth server
Phillip Davis
10:47 AM Bug #7604: Bug #6594 is not resolved: Waiting for Internet connection to update pkg metadata and finish package reinstallation
I've just come across this bug now. Most.. infuriating .. nonsense. In my case I have a working WAN, but you can't se... Steve Allison
10:36 AM Revision 5520839e: Mark authentication containers label as required field
Phillip Davis
05:33 AM Bug #8338 (Resolved): Wrong LDAP host is reported when testing system auth server settings
To reproduce:
1) Add a few authentication servers (some Radius, at least 1 LDAP that is not the first entry in the l...
Phillip Davis
04:40 AM Bug #8337 (Resolved): System Authservers page Authentication Containers field should be marked required
Actually the box for entering the container data has the "background" text "*Containers"
Phillip Davis

02/16/2018

10:10 PM Bug #7469: local_sync_accounts() slowness can trigger GUI/XMLRPC failures with many accounts
Tested on Current Base System 2.4.3.a.20180216.1415
Syncing 106 users and adding a 107th took maybe two seconds, n...
Paighton Bisconer
10:50 AM Bug #7469 (Feedback): local_sync_accounts() slowness can trigger GUI/XMLRPC failures with many accounts
Applied in changeset commit:dc3bc1f8c9f5040762953b38df499ea5f86d13d5. Renato Botelho
09:58 PM Feature #8186: ipsec, allow configuration of multiple ike phase1 encryption ciphers #3711
Tested on 2.4.3.a.20180216.1415, works as expected. Anonymous
06:16 PM Bug #8266: Bogus error message occurs on killing OPenVPN connection
tested on 2.4.3.a.20180216.1415, no error.
Anonymous
04:54 PM Bug #8336: ESXi 6.5u1 displays superfluous error message with Netgate OVA iamge
Oops. Can someone fix my typo in the title, please? Adam Thompson
04:53 PM Bug #8336 (Closed): ESXi 6.5u1 displays superfluous error message with Netgate OVA iamge
No functional impact.
When pfSense-CE-2.4.2-RELEASE-amd64.ova is deployed and booted on an ESXi 6.5u1 host, the VM...
Adam Thompson
04:42 PM Revision dc3bc1f8: Fix #7469
Sort users / groups alphabetically on config.xml Renato Botelho
04:42 PM Revision 90510875: Be more verbose about users/groups sync
Renato Botelho
04:10 PM Revision f7aafd45: Fix typo
Jim Pingle
02:04 PM Bug #8335 (New): System hang with LACP downlink to UniFi switch
I have an RCC-VE 2440 (2015) with igb1 and igb2 aggregated into lagg0 and connected to a UniFi switch. UniFi supports... Mike Pastore
01:49 PM Bug #8334: Forwarding broadcast through firewall can cause broadcast storm
All that I understood, the part I think was a bug was it continuing to accept the packet on the WAN interface when th... Sam Bingner
01:47 PM Bug #8334 (Not a Bug): Forwarding broadcast through firewall can cause broadcast storm
The firewall in this case does not have any knowledge that the packet is broadcast. It does not know the subnet direc... Jim Pingle
01:34 PM Bug #8334 (Not a Bug): Forwarding broadcast through firewall can cause broadcast storm
I had a secondary IP on a windows system to test connectivity to a proprietary system. When it was added to windows,... Sam Bingner
01:31 PM Feature #8205 (Feedback): Allow display of temperature in Fahrenheit
PR was merged back in December Jim Pingle
01:25 PM Feature #8191 (Feedback): IPv6 - Support for configuring multiple DUID types
PR was merged a month ago Jim Pingle
01:16 PM Bug #8261 (Feedback): OpenVPN tunnel network handled incorrectly with a /31 tunnel network
PR was merged two weeks ago Jim Pingle
01:12 PM Bug #8333 (Resolved): Dynamic DNS updates may fail when using a gateway group as the interface when the default route is down
When the interface of a Dynamic DNS entry is set to a gateway group and the default route is down, the update may fai... Jim Pingle
08:19 AM Bug #8231 (Resolved): Undefined function while restoring config from older version
Jim Pingle
07:35 AM Todo #6647: Enable Additional Security Headers
While I am by no means an expert on what specific headers are appropriate... And the webgui really should be limited ... JohnPoz _

02/15/2018

05:12 PM Revision d0af08f5: Remove duplicate entries on loader.conf and loader.conf.local.
Luiz Souza
02:08 PM Feature #7643 (Resolved): Send notification when boot completed
This has been present and working as of commit:1c2ef5f22ff76419ff7f4ba620a02b8a14dc3078 Jim Pingle
02:00 PM Bug #8238 (Resolved): A global definition for $cpconfig is missing ...
Global declaration is present now. Jim Pingle
01:58 PM Bug #8239 (Resolved): If IPsec bypasslan is enabled while the LAN interface is disabled, all traffic bypasses IPsec
Works fine now. If the interface is disabled or otherwise has no address, then bypasslan is omitted. Jim Pingle
01:57 PM Bug #8252 (Resolved): Automatic SAN code for certificates does not work properly with additional SANs when the CN contains a space
Works properly now. A cert with a CN containing a space does not get an invalid SAN entry. Jim Pingle
01:56 PM Feature #8244 (Resolved): Add Dynamic DNS RFC 2136 Client server key algorithm choice
Option is present and functional. Jim Pingle
01:54 PM Bug #8259 (Resolved): Range description is not encoded in firewall_schedule.php
OK now. Jim Pingle
01:52 PM Feature #8267 (Resolved): OpenVPN tap bridge configurations without a tunnel network need a route-gateway for routes/redirects
Option is present and working Jim Pingle
01:50 PM Bug #8268 (Resolved): RAMdisk warning pop-up appears when no changes have been made
Works now, the prompt only appears when expected. Jim Pingle
01:49 PM Bug #8275 (Resolved): Input validation for Certificate SAN (Subject Alternative Name) allows IP addresses to be entered when FQDN/Hostname is selected
Input validation works properly now, an IP address is rejected when FQDN is selected. Jim Pingle
01:47 PM Feature #8278 (Resolved): Add control for source address of RFC2136 updates
Works Jim Pingle
01:46 PM Feature #7843 (Resolved): DynamicDNS Widget - Show Description
Works Jim Pingle
01:45 PM Bug #8182 (Resolved): Support shutdown scripts in /usr/local/etc/rc.d
Code is there on current snaps. Jim Pingle
01:40 PM Bug #8183 (Resolved): pkg, fix, reinstall missing package #3866
Jim Pingle
01:39 PM Todo #8245 (Resolved): use delayed compression for sshd
Delayed compression is in sshd_config on current snaps. Jim Pingle
01:38 PM Bug #4031 (Resolved): Notifications mail bomb in some gateway failure circumstances
This has been working great since it was merged. Jim Pingle
01:38 PM Bug #8185 (Resolved): status_queues, provide 'realtime' statistics #3792
Seems OK here, too. Jim Pingle
01:36 PM Bug #7469 (Assigned): local_sync_accounts() slowness can trigger GUI/XMLRPC failures with many accounts
Current code is better but is not putting the users back into matching order on both units. Renato is working on an i... Jim Pingle
01:31 PM Feature #8257 (Resolved): pfSense Diagnostics -> Packet Capture support for loopback interface
Jim Pingle
01:29 PM Bug #8301 (Resolved): Dashboard Widgets may no longer need CSRF disabled
Every widget I've tried still works, it's been in snaps for two weeks and no other complaints, I'd say it's resolved. Jim Pingle
01:29 PM Bug #8303 (Resolved): Undefined Function
Problematic function call is not present on current snaps. Looks OK here. Jim Pingle
01:26 PM Bug #8317 (Resolved): Captive Portal Sync Errors
Works on current snaps. Jim Pingle
01:20 PM Bug #8323 (Resolved): Remote Logging Options and IPv6
Jim Pingle
01:20 PM Bug #8322 (Resolved): PPP UI error
Jim Pingle
01:19 PM Bug #7131 (Resolved): DHCP v4&v6 DDNS missing options
Jim Pingle
01:13 PM Bug #8220 (Resolved): UI does not allow multiple MAC for same DHCP address
Jim Pingle
01:12 PM Bug #8321 (Resolved): IPv6 LAN Network missing from IPsec LAN bypass list
Jim Pingle
03:16 AM Bug #8321: IPv6 LAN Network missing from IPsec LAN bypass list
Looks good: bypasslan: child: 172.25.236.0/24|/0 2001:470:beef:7e01::/64|/0 === 172.25.236.0/24|/0 2001:470:beef:7... Chris Linstruth
01:12 PM Bug #8091 (Resolved): Limiters with fractional bandwidth values are not loaded correctly
Jim Pingle
04:24 AM Bug #8091: Limiters with fractional bandwidth values are not loaded correctly
Tested. Looks like it is doing the right thing. Chris Linstruth
12:17 PM Revision 0445f0d3: Update the copyright year in a couple of missing points.
Luiz Souza
12:14 PM Revision 7df5447d: Update the copyright year on login page.
Ticket: #8331 Luiz Souza
11:38 AM pfSense Packages Todo #8332 (Resolved): pfBlockerNG doesn't include L2TP interface in outbound floating rules
pfBlockerNG needs an option on the General tab for "L2TP Interface" similar to the "OpenVPN Interface" and "IPSec Int... Stuart Wyatt
06:25 AM Todo #8331 (Feedback): Update Copyright Year on GUI Login page
Fixed.
Thanks!
Luiz Souza

02/14/2018

07:29 PM Todo #8331 (Resolved): Update Copyright Year on GUI Login page
Copyright year shows 2018 once logged in but on login page it still shows 2017
Confirmed in 2.4.3-DEV Current Base...
Paighton Bisconer
05:35 PM Bug #8220: UI does not allow multiple MAC for same DHCP address
Confirmed working on Current Base System 2.4.3.a.20180213.0339 built on Tue Feb 13 03:39:40 CST 2018 Paighton Bisconer
04:28 PM Revision 79f7bc7f: Fix #7469
* Rename local_sync_accounts() to local_reset_accounts() and keep it
only being used /etc/rc.bootup
* Reimplement l...
Renato Botelho
12:35 PM Todo #7024: Replace copy of radius.inc by pear-Auth_RADIUS
Push for 2.4.4 Renato Botelho
12:26 PM Bug #8135: pfSense deletes itself after upgrade from 2.2.6 to 2.3.5 with haproxy installed
I have the same problem.
Any news about it?
Is it possible to upgrade to a previous version than 2.3.5 and then go ...
Mattia Martinello
10:50 AM Bug #7469 (Feedback): local_sync_accounts() slowness can trigger GUI/XMLRPC failures with many accounts
Applied in changeset commit:79f7bc7f61a9026cca8770d60d27cde15dd6f26a. Renato Botelho
09:46 AM Feature #8330 (New): add options for ddns-local-address statements
For Dynamic DNS updates please allow the option to select from ddns-local-address statements.
https://www.isc.or...
Matthew Fine
08:59 AM Bug #8165: Fragmented at source IPv6 packets (UDP + ICMP Ping) are not forwarded / v2.4.2 AMD64
Having done some more research it appears the problem has previously come up in FreeBSD, fixed and then come back in ... Mike Nichols
05:59 AM pfSense Packages Bug #8291 (Resolved): Auto Config Backup ACB Reports Success on invalid credentials then an error notice is logged

Anonymous
05:57 AM pfSense Packages Bug #8291: Auto Config Backup ACB Reports Success on invalid credentials then an error notice is logged

>
Anonymous

02/13/2018

08:32 AM pfSense Packages Bug #8329 (Closed): Cellular Package Change link to symlink
Ticket for PR:
https://github.com/pfsense/FreeBSD-ports/pull/500
Sven Auhagen
05:19 AM Bug #8117: IPSec statuspage shows both connected and connecting tunnel
It is set to respond only! (but I think previously it was set to initiate!)
This did not happen in the previous ve...
Ges Ture
05:12 AM Bug #8328 (Rejected): username/password not used by proxy support
Hello,
I open a new ticket because I have no news about ticket #8124. Can you tell me if you need more informati...
O 71

02/12/2018

04:26 PM Revision 9d706ff8: Break some long lines
Renato Botelho
04:26 PM Revision 356f29a0: Fix #8317
Verify if pipes were created in current system before attempt to remove
them
Renato Botelho
03:12 PM Revision ff8b4019: Do no try to lock when file doesn't exist
Renato Botelho
03:08 PM Revision b27df7cf: Implement dry_run mode in captiveportal_free_dnrules()
To be used later on a fix for ticket #8317 just return the array
containing pipes to be removed without removing them...
Renato Botelho
01:17 PM Bug #7905: OpenVPN Authentication Against Backend Stalls All Server Traffic
I'm actively working on implementing this in my pfSense environment. Currently I have a fork of the workaround linked... Phil DeMonaco
11:50 AM Bug #8317 (Feedback): Captive Portal Sync Errors
Applied in changeset commit:356f29a03f7a7c770cbd8492c20347f615e3fdd7. Renato Botelho
08:22 AM pfSense Packages Feature #8326 (Resolved): Acme.sh package - Add support for Azure DNS
I added a note to Azure in ACME pkg version 0.2.0.3 with that link. Jim Pingle
05:26 AM Bug #8056: Bridge + CARP crashes/freezes pfSense
I have exactly the same issue with my pfSense setup on a Netgate Physical Appliance. Is there any ETA when this will ... Scott Maxwell
04:47 AM Bug #8327: VLAN net, Default Deny and spoofed packets
I just want to add that in old version 2.1.2-RELEASE (i386), spoofed packets are correctly blocked on a VLAN interfac... Antonio Prado
04:40 AM Bug #8327 (Not a Bug): VLAN net, Default Deny and spoofed packets
Scenario:
VLAN interface 172.31.22.251/24
Rules for VLAN interface:
PASS Prot. IPv4 *; source VLAN_net, port *; ...
Antonio Prado

02/11/2018

07:02 PM Bug #8138: Option <spoofmac> is ignored on interfaces without hwaddr
I did this:... Michael Sh.
01:51 AM pfSense Packages Feature #8326: Acme.sh package - Add support for Azure DNS
Just noticed that jim-p implemented it in already https://github.com/pfsense/FreeBSD-ports/commit/329605fc469f7ba2e4a... Martin Grasruck
01:43 AM pfSense Packages Feature #8326 (Resolved): Acme.sh package - Add support for Azure DNS
UI support in the acme package for Azure DNS
See Azure DNS Support
Support in acme.sh was added with https://gith...
Martin Grasruck

02/09/2018

08:46 PM Bug #8324: bxe cards require promisc for OSPF
bxe seems to want IFF_ALLMULTI set, and something isn't setting it.
https://github.com/freebsd/freebsd/blob/master...
Jim Thompson
08:32 PM Feature #6886: Allow Dual-Stack IPSec VPN
Confirmed option available in Current Base System 2.4.3.a.20180209.1614 built on Fri Feb 09 16:14:19 CST 2018.
Paighton Bisconer
07:42 AM Feature #1826: PPPoE server IPv6 support
Delegation of a full prefixes or parts of the prefixes received on WAN to pppoe-Clients is needed.
Will there be any...
Thomas Levi
07:19 AM Bug #7958: Upgrade 2.4.0: IP alias with FQDN doesn't work any more
I have the same issue. filterdns appears to hang and must be killed for this to function. If not, any host based alia... Snarf Attack
06:52 AM Bug #8325 (New): UPnP not available for pppoe-Clients
Dear pfsense-Team,
I use pfsense on the current version and want to activate UPnP (Services / UPnp & NAT-PMP), but...
Thomas Levi

02/08/2018

06:12 PM Revision 236a198c: Fixing filename. Thanks Renato
Anders Lind
11:17 AM Bug #8324 (New): bxe cards require promisc for OSPF
Since at least 2.4.1, when using either Quagga or FRR, bxe cards require promisc to be enabled in order to receive OS... Jason Hurlbert
01:05 AM Bug #7131: DHCP v4&v6 DDNS missing options
Verified on pfSense-netgate-kvm-2.4.3-DEVELOPMENT-amd64-20180207-1106.qcow2.gz
DDNS DHCP Client Updates show under...
Paighton Bisconer

02/07/2018

07:30 PM Revision d1f69741: Allow Dual Stack IPsec P1 interface. Fixes #6886
Allow "Both" to be selected for IPv4/IPv6 on IPsec P1, in the config use both addresses as "left =" if they both exis... Jim Pingle
06:55 PM Revision 1dc6392b: Consider IPv6 for IPsec bypasslan. Fixes #8321
Jim Pingle
05:27 PM Revision b96b2ca0: Merge pull request #3905 from pulcov/master
Steve Beaver
05:23 PM Revision 031570c6: Merge branch 'master' of gitlab.netgate.com:pfsense/pfsense
Steve Beaver
02:31 PM Revision c6c2ea16: Correct variable used to populate the IPv4/IPv6 selector on status_logs_settings.php. Fixes #8323
(cherry picked from commit 0136888bde4e23ba99533d72de5f0b96545abb97) Jim Pingle
02:31 PM Revision 195a4e0c: Correct variable used to populate the IPv4/IPv6 selector on status_logs_settings.php. Fixes #8323
(cherry picked from commit 0136888bde4e23ba99533d72de5f0b96545abb97) Jim Pingle
02:31 PM Revision f4a68485: Correct variable used to populate the IPv4/IPv6 selector on status_logs_settings.php. Fixes #8323
(cherry picked from commit 0136888bde4e23ba99533d72de5f0b96545abb97) Jim Pingle
02:30 PM Revision 0136888b: Correct variable used to populate the IPv4/IPv6 selector on status_logs_settings.php. Fixes #8323
Jim Pingle
01:40 PM Feature #6886 (Feedback): Allow Dual-Stack IPSec VPN
Applied in changeset commit:d1f69741f57f9f049f80040a93278591c424a4cc. Jim Pingle
01:35 PM Revision b0e29e62: Fixed #8322 to accommodate case where no VIPs are defined
Steve Beaver
01:10 PM Bug #8321 (Feedback): IPv6 LAN Network missing from IPsec LAN bypass list
Applied in changeset commit:1dc6392b93b9baf869ad9437b9a01baf922a0b5a. Jim Pingle
12:14 PM Bug #7413: status_dhcpv6_leases.php: Some DHCPv6 leases are not displayed in the GUI
PR looks good to me. I had a number of leases on my edge firewall that were not showing before, and now they all show... Jim Pingle
11:40 AM Bug #8322: PPP UI error
Applied in changeset commit:b0e29e62c9fad8650d20dbc997af69c4fbe150ee. Anonymous
07:38 AM Bug #8322 (Feedback): PPP UI error
Fixed by initializing VIP array in interfaces.inc Anonymous
07:07 AM Bug #8322 (Resolved): PPP UI error
Warning: array_merge(): Argument #2 is not an array in /etc/inc/interfaces.inc on line 6664 Catchable fatal error: Ar... Anonymous
08:40 AM Bug #8323 (Feedback): Remote Logging Options and IPv6
Applied in changeset commit:0136888bde4e23ba99533d72de5f0b96545abb97. Jim Pingle
08:28 AM Bug #8323 (Confirmed): Remote Logging Options and IPv6
Jim Pingle
08:09 AM Bug #8323 (Resolved): Remote Logging Options and IPv6
I dare say that I have found a bug in version 2.4.2-RELEASE (amd64).
When setting up syslog forwarding in the "Rem...
Christoph Haas

02/06/2018

04:50 PM Revision d5636a2d: Enable Arpwatch
Renato Botelho
04:37 PM Revision b2605914: Do not apply a DHCP static mapping uniqueness test for hostnames or IP addresses. The DHCP daemon allows the entries to be duplicated provided they have unique MAC addresses or identifiers. Fixes #8220
Jim Pingle
03:35 PM pfSense Packages Bug #8251: Captiveportal + FreeRadius "Last activity" resets to Session start
Any help? Frotty Zaoldyeck
02:56 PM Revision 8e461d38: extended GUI to manage new feature
christian christian
02:42 PM Revision c971ddc4: Revert "Add cxgbe to ALTQ list. Fixes #8314"
Apparently it's not supported by the driver, despite what the man page claims.
This reverts commit 40f2c5d909220dd5a...
Jim Pingle
01:38 PM Bug #7015 (Resolved): IPsec not working behind NAT
The original bug here was fixed long ago. The other parts are covered by #7774 and #8321 Jim Pingle
01:30 PM Bug #8321 (Resolved): IPv6 LAN Network missing from IPsec LAN bypass list
From #7015 comment 21.
When bypasslan is enabled, it only covers IPv4, not IPv6. When an IPsec tunnel is setup usi...
Jim Pingle
01:20 PM Revision 6e14487b: supporting enhanced user management with strongswan
christian christian
10:50 AM Bug #8220 (Feedback): UI does not allow multiple MAC for same DHCP address
Applied in changeset commit:b2605914777a8026910bf8ce8b324fce61803ad2. Jim Pingle
10:43 AM Bug #8220: UI does not allow multiple MAC for same DHCP address
Also: This problem was introduced over 4 years ago when a contributor added the IP address check instead of removing ... Jim Pingle
10:40 AM Bug #8220: UI does not allow multiple MAC for same DHCP address
As the discussion in some of those former tickets and posts implied, the IP address can be reused as well as the host... Jim Pingle
10:10 AM Bug #8317: Captive Portal Sync Errors
That's not a discussion relevant to the bug, but in brief: The ONLY supported use of XMLRPC sync in any area is for H... Jim Pingle
10:03 AM Bug #8317: Captive Portal Sync Errors
Jim Pingle wrote:
> Using vouchers with a "central" host is not an approved or supported use of the voucher sync sys...
Jens Groh
09:46 AM Bug #8317: Captive Portal Sync Errors
Using vouchers with a "central" host is not an approved or supported use of the voucher sync system, but the problem ... Jim Pingle
09:12 AM Bug #8317 (Confirmed): Captive Portal Sync Errors
Jim Pingle
04:52 AM Bug #8317 (Resolved): Captive Portal Sync Errors
We have a CP setup running at a customer's site which uses a central pfSense VM as CP Voucher Sync target for central... Jens Groh
10:05 AM Bug #8310 (Not a Bug): Firewall ACL fails to parse / validate host alias entries after tenth entry in alias
I can't reproduce this with host or network aliases. I tried up to 50 entries in an alias and every entry worked as e... Jim Pingle
09:42 AM pfSense Packages Bug #8320 (Rejected): acme: dns_yandex plugin is broken at least on amd64 platform due to different sed behavior
We do not maintain that code, please report the problem to the acme.sh project: https://github.com/Neilpang/acme.sh Jim Pingle
09:21 AM pfSense Packages Bug #8320: acme: dns_yandex plugin is broken at least on amd64 platform due to different sed behavior
The plugin dns_yandex is broken due to to different sed behavior.
The error resides within PDD_get_domain() functi...
Artem Tambovskiy
09:18 AM pfSense Packages Bug #8320 (Rejected): acme: dns_yandex plugin is broken at least on amd64 platform due to different sed behavior
The plugin dns_yandex is broken due to to different sed behavior.
The error resides within _PDD_get_domain() func...
Artem Tambovskiy
08:43 AM Bug #8314 (Not a Bug): cxgbe missing from ALTQ interface list
It's possible that either the man page is wrong or it's been disabled in our driver for stability reasons. I'll take ... Jim Pingle
08:40 AM Bug #8314: cxgbe missing from ALTQ interface list
well this is odd.
altq(4) clearly "*indicates*":https://www.freebsd.org/cgi/man.cgi?altq that cxgbe(4) is supporte...
ROB VANHOOREN
06:53 AM pfSense Packages Bug #8318 (Resolved): PFBlockerNG removes alias file when using advanced inverted rule
I'm running 2 PFSense boxes in HA setup. Version 2.4.2-RELEASE-p1 (amd64) with PFBlockerNG version 2.1.2_2 . The mast... Sander Peterse
04:35 AM Feature #8316 (New): expiration date when creating new rules
Sometimes i want to create rules, that should only applied for a some days / weeks.
At the moment i only can create ...
Henrik Gießel
01:43 AM Bug #6295: Crash upon applying CODELQ to untagged parent interface when also applied to daughter VLAN
Hi all.
Just a heads up that this issue still exists in 2.4.2 (amd64).
Cheers.
Shaun.
Shaun Maher

02/05/2018

10:45 PM Bug #8165: Fragmented at source IPv6 packets (UDP + ICMP Ping) are not forwarded / v2.4.2 AMD64
Mike Nichols wrote:
> This issue came to light when I encountered a problem with a SIP phone not receiving SIP Invit...
Kevin A McGrail
09:55 PM Revision 40f2c5d9: Add cxgbe to ALTQ list. Fixes #8314
Jim Pingle
08:26 PM Revision 0f5bd6f8: Fixed #8091 Force Integers in GUI
It will use the ceil() function to always use the ceiling after loading a config.
Also onchange of bandwidth will cal...
Stephen Jones
07:02 PM pfSense Packages Bug #8315 (Closed): Mail Report mail_report_send() behavior different than notify_via_smtp()
@notify_via_smtp()@ correctly supports both SMTPS SSL and SMTP+StartTLS.
Mail Report @mail_report_send()@ supports S...
Dale Southard
05:47 PM Bug #6263: Encryption options for every P2 on a given P1 are written to each P2 individually inside ipsec.conf with multiple P2 entries + split conn entries
Looked into this and the attached patch appears to fix the issue in 2.4.2. The comparable change also corrected a 2.... PJ Goodwin
04:10 PM Bug #8314 (Feedback): cxgbe missing from ALTQ interface list
Applied in changeset commit:40f2c5d909220dd5aaa23515d25a04916438304d. Jim Pingle
03:56 PM Bug #8314: cxgbe missing from ALTQ interface list
T5 cards are called cxl; T4 cards are called cxgbe
... ref cxgbe(4) "*here*":https://www.freebsd.org/cgi/man.cgi?qu...
ROB VANHOOREN
03:45 PM Bug #8314 (Not a Bug): cxgbe missing from ALTQ interface list
patchset added 'cxl' ... line 5680 of src/etc/inc/interfaces.inc also needs 'cxgbe'
thanks,
R.
ROB VANHOOREN
03:36 PM Bug #8313: STARTTLS auto detection not working
That code is not ours but that of the Net_SMTP Pear package: https://pear.php.net/package/Net_SMTP -- That package do... Jim Pingle
03:26 PM Bug #8313 (Not a Bug): STARTTLS auto detection not working
When attempting to setup SMTP notifications to a mailserver which supports STARTTLS the following error occurrs:
Co...
David Martin
02:55 PM Bug #8226 (Resolved): Pass-through MAC automatic additions adds duplicate
Anonymous
06:46 AM Bug #8226: Pass-through MAC automatic additions adds duplicate
Its indeed solved. Thanks for the quick fix. Sander Naudts
02:40 PM Bug #8091 (Feedback): Limiters with fractional bandwidth values are not loaded correctly
Applied in changeset commit:0f5bd6f8ecf2a755cf2cef689e1e3bead04cc058. Anonymous
01:13 PM Bug #7425 (Confirmed): dhclient not sending option 77
Option 77 works on 2.4.3 snapshots, I'm checking what we can do about the VLAN priority. Luiz Souza
11:24 AM Feature #8186 (Feedback): ipsec, allow configuration of multiple ike phase1 encryption ciphers #3711
PR has been merged. Thanks! Renato Botelho
11:08 AM Feature #336: Option to create lagg under assign interfaces
+1
Absolute impossible to create a LAGG on the CLI :/
Kilian Ries
07:30 AM pfSense Packages Bug #8312 (Not a Bug): Can not init api (error code: 3)
It works fine here, it looks like it's something in your configuration, probably a problem with the key. If it can't ... Jim Pingle
05:09 AM pfSense Packages Bug #8312: Can not init api (error code: 3)
Relevant portion from acme_issuecert.log:... H. de Visser
03:57 AM pfSense Packages Bug #8312 (Not a Bug): Can not init api (error code: 3)
pfSense: 2.3.5_p1 (on amd64)
Acme Package: 0.1.34
Trying to manually renew our certificate, but getting error bel...
H. de Visser
07:19 AM Bug #7905: OpenVPN Authentication Against Backend Stalls All Server Traffic
Would a solution like Keepalived on the authentication servers back-end (if they are of the same type, e.g. RADIUS)wo... John Tikis

02/04/2018

09:02 PM pfSense Packages Feature #8311 (Rejected): Suricata persistent blocks
Please make blocks with suricata persistent through reboot. Jon Shoulders
08:05 PM Bug #8056: Bridge + CARP crashes/freezes pfSense
Set target. Luiz Souza
01:04 PM pfSense Packages Bug #8307: HAproxy in pfsense 2.42-p1 creating a new frontend with a Shared Frontend issues invalid ip error
The haproxy-devel 0.55_2 package will be build after the pull request is 'accepted' by official pfSense developers..
...
Pi Ba

02/03/2018

11:34 AM Bug #8310 (Not a Bug): Firewall ACL fails to parse / validate host alias entries after tenth entry in alias
This can be recreated 100% of the time.
When writing an ACL on the firewall, if I use a host alias as source or de...
Francisco Artes
10:13 AM Bug #8056: Bridge + CARP crashes/freezes pfSense
The previous patch works well on 2.3.x. Is it possible to apply the same patch for 2.4.x while FreeBSD folks decide w... Anonymous
01:07 AM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
I just started a bounty thread on the pfSense forums:
https://forum.pfsense.org/index.php?topic=143579.0
Essent...
Lynn Dixon

02/02/2018

08:41 PM Revision 76ca1bc5: Fix config version # arrising from merging older PR
Steve Beaver
08:26 PM Revision d205ac7a: Merge pull request #3711 from PiBa-NL/20170427-ipsec-multiple-P1-algo
Steve Beaver
08:17 PM Revision 3490784c: Merge branch 'master' of gitlab.netgate.com:pfsense/pfsense
Steve Beaver
08:16 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
Unfortunately, it looks like it keeps getting kicked down the road a bit. This would be a really nice bit of polish... Lynn Dixon
08:13 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
is there an ETA on this one? Oded Brilon
07:05 PM pfSense Packages Bug #8307: HAproxy in pfsense 2.42-p1 creating a new frontend with a Shared Frontend issues invalid ip error
Pi Ba wrote:
> Perhaps you could send me 'PiBa' a PM on the forum?
Pi
Other then manually patching the code. ...
Mark Saad
06:35 PM pfSense Packages Bug #8307: HAproxy in pfsense 2.42-p1 creating a new frontend with a Shared Frontend issues invalid ip error
The new package 0.55_2 should skip the check on 'secondary' frontends.
https://github.com/pfsense/FreeBSD-ports/pull...
Pi Ba
02:53 PM pfSense Packages Bug #8307: HAproxy in pfsense 2.42-p1 creating a new frontend with a Shared Frontend issues invalid ip error
Perhaps you could send me 'PiBa' a PM on the forum? Pi Ba
01:06 PM pfSense Packages Bug #8307: HAproxy in pfsense 2.42-p1 creating a new frontend with a Shared Frontend issues invalid ip error
Pi Ba wrote:
> Would be nice to know what your config looks like. As it doesn't seem to happen here. Can you share t...
Mark Saad
05:57 PM Revision 67784aa6: Add DDNS client update option to DHCPv4 configuraiton
Steve Beaver
04:51 PM Revision daf7490f: Fix #8290
On d9b05eb490a the way aliases containing a mix of IP address and FQDNs
works has changed and all items were added to...
Renato Botelho
04:50 PM Feature #8309 (New): Include apuled driver to add support for LEDs on PC Engines APU boards
Driver for adding support for LEDs and mode switch on PC engines APU boards.
See here for details: https://bugs.fr...
Darryn Storm
04:50 PM Revision 1c1613c5: Fix #8290
On d9b05eb490a the way aliases containing a mix of IP address and FQDNs
works has changed and all items were added to...
Renato Botelho
04:45 PM Revision a464eaf7: Fixed #8226 Check for MAC duplicates
loop through auto pass MAC addresses for duplicates
before automatically adding a pass thru.
Stephen Jones
04:20 PM Feature #7216: Allow user to choose date display format
I think a text field allowing standard PHP date() format would be ideal. https://secure.php.net/manual/en/function.da... Duncan Fairley
03:32 PM pfSense Packages Bug #8306: HAproxy in pfsense 2.42-p1 ha pair generates XMLRPC errors
Pi Ba wrote:
> Sync should be disabled on haproxy on the backup machine, can you check that is indeed the case?
P...
Mark Saad
02:51 PM pfSense Packages Bug #8306: HAproxy in pfsense 2.42-p1 ha pair generates XMLRPC errors
Sync should be disabled on haproxy on the backup machine, can you check that is indeed the case? Pi Ba
01:09 PM pfSense Packages Bug #8306: HAproxy in pfsense 2.42-p1 ha pair generates XMLRPC errors
Pi Ba wrote:
> Could it be that youve got sync configuration enabled in haproxy, but dont have it configured in pfSe...
Mark Saad
01:09 PM Bug #8290: filter.inc, make filter_expand_alias_array() return consistent results between first and second call.
Well now the haproxy usecase is broken both ways. start by 'apply config', and by 'restart service' neither fills the... Pi Ba
11:00 AM Bug #8290 (Feedback): filter.inc, make filter_expand_alias_array() return consistent results between first and second call.
Applied in changeset commit:1c1613c532cfca62724b490f44989dbbff3a170b. Renato Botelho
12:00 PM Bug #7131 (Feedback): DHCP v4&v6 DDNS missing options
DHCP client updates option added DHCP v4
ddns-update-style interim may be added later
Anonymous
11:00 AM Bug #8226 (Feedback): Pass-through MAC automatic additions adds duplicate
Applied in changeset commit:a464eaf72bb970cc3a26cef9b322f1ee9918cf9f. Anonymous
09:47 AM Bug #8226 (Assigned): Pass-through MAC automatic additions adds duplicate
Disregard that last message I was able to reproduce it. Anonymous
09:39 AM Bug #8226 (Feedback): Pass-through MAC automatic additions adds duplicate
Could we get more details on how to reproduce this? I do not see duplicate entries when logging in from different tab... Anonymous
09:41 AM pfSense Packages Bug #8308 (Resolved): FRR OSPF6D: interfaces not assigned to areas if they only have a link-local address
frr_ospf6d.inc:... Firstname Surname
09:34 AM Bug #3932 (Closed): Captive portal with greater than 9000 permanent MAC addresses causes timeout in loading CP
It is unreasonable to keep kicking this down the road to target_version++ Closing and recording it for future conside... Anonymous
09:31 AM Bug #6031 (Closed): Anti-Lockoug Rule Not Effective Against Canned Interface Block Rules
No one has been able to work on this in two years, and there is a work-around. Closing and recording for future consi... Anonymous
09:27 AM Bug #6578 (Closed): Filter reload hangs with IPsec hostnames that don't resolve configured
This will not be addressed in the next version or two, so is being shelved and recorded for future consideration. Anonymous
09:12 AM Bug #7082: pkg_edit.php - impossible to use default_value with rowhelperfield
This will not be addressed in 2.4.3 :( We are looking at alternative ways of providing this functionality. Anonymous
07:11 AM pfSense Packages Bug #7965 (Resolved): freeradius 3 with MySQL
Jim Pingle
12:19 AM pfSense Packages Bug #7965: freeradius 3 with MySQL
THX! It's worked! Konstantin Ab

02/01/2018

05:37 PM pfSense Packages Bug #8306: HAproxy in pfsense 2.42-p1 ha pair generates XMLRPC errors
Could it be that youve got sync configuration enabled in haproxy, but dont have it configured in pfSense itself? Pi Ba
09:29 AM pfSense Packages Bug #8306 (Rejected): HAproxy in pfsense 2.42-p1 ha pair generates XMLRPC errors
I have a number of http(s) sites setup under haproxy using a shared ssl cert .
After cloning an existing config I...
Mark Saad
05:36 PM pfSense Packages Bug #8307: HAproxy in pfsense 2.42-p1 creating a new frontend with a Shared Frontend issues invalid ip error
Would be nice to know what your config looks like. As it doesn't seem to happen here. Can you share the <haproxy> sec... Pi Ba
09:35 AM pfSense Packages Bug #8307 (Resolved): HAproxy in pfsense 2.42-p1 creating a new frontend with a Shared Frontend issues invalid ip error
This has existing since 2.3.x and has been worked around for some time.
We use a haproxy shared frontend for a com...
Mark Saad
05:33 PM Revision 12f16196: Fixed #8303
Steve Beaver
04:15 PM Revision ce7b40ce: Fixed #8301 CSRF Enabled on all widgets.
Enabled CSRF on all widgets. Stephen Jones
04:12 PM Bug #6677 (Resolved): CARP VIPs are configured on disabled interfaces at boot time
Luiz Souza
03:08 PM Bug #7195: pkg_edit.php - <checkenablefields> tag has no effect on fields other than checkbox/input
We hope to provide an alternative means of achieving this, but it won't make it in 2.4.3, so ++target_version :( Anonymous
12:46 PM Bug #7801: UDP fragments received over IPsec tunnel are not properly reassembled and forwarded
++target_version Anonymous
12:36 PM Bug #7905: OpenVPN Authentication Against Backend Stalls All Server Traffic
Sorry to have to kick this to ++version but the work required cannot be squeezed into the 2.4.3 schedule Anonymous
12:03 PM Bug #8263: Cannot create a nonlinear `Link Share` service curve because of: "the sum of the child bandwidth higher than parent"
Rescheduled for release 2.4.4 Anonymous
12:02 PM Bug #7413: status_dhcpv6_leases.php: Some DHCPv6 leases are not displayed in the GUI
Re-assigned for testing Anonymous
11:57 AM Bug #7480 (Feedback): pkg framework - textarea on rowhelperfield errors
Is there an existing package where this behavior can be seen? Anonymous
11:51 AM Bug #7481 (Rejected): pkg-framework - rowhelper ignores <advancedfield/>
The advancedfield tag is no longer supported in the rowhelper section. This may be addressed in the future, but more ... Anonymous
11:48 AM Bug #7599: System->Update unavailable in WebGUI after connection failure during update
Stephen. - Would you please retest and confirm this issue still exists? Anonymous
11:40 AM Bug #8303: Undefined Function
Applied in changeset commit:12f1619688ce2dc92e63e808cda3cd9317e96c13. Anonymous
11:34 AM Bug #8303 (Feedback): Undefined Function
Fixed.
That function has not been required for a number of years.
Anonymous
11:10 AM Bug #8303 (Confirmed): Undefined Function
Anonymous
11:09 AM Bug #7772 (Feedback): Regression of Bug #906
Can you provide simple steps to reproduce please? Anonymous
10:30 AM Bug #8301 (Feedback): Dashboard Widgets may no longer need CSRF disabled
Applied in changeset commit:ce7b40ce96bbd9e94d36d1779807bbe6b8efd356. Anonymous
08:16 AM pfSense Packages Bug #7965: freeradius 3 with MySQL
There should not be any need for manual corrections on the current version. The counters should be handled properly.
...
Jim Pingle

01/31/2018

09:45 PM pfSense Packages Bug #7965: freeradius 3 with MySQL
Thank you! It remains to fix "daily" in config to run freeradius
With "daily(and etc...)" in config freeradius not s...
Konstantin Ab
10:50 AM pfSense Packages Bug #7965 (Feedback): freeradius 3 with MySQL
Fixed in commit:a5d0e15340e1975a86fb5fe48f93032b3c574934 - pkg version 0.15.4 Jim Pingle
06:56 PM Revision 3c44c845: Silence warnings generated by sysctl to standard error.
Luiz Souza
02:07 PM Revision ae72e9e2: openvpn, clear route also for /31 for ptp interfaces
(cherry picked from commit a0f991ecb8247688bfc91b11176c0442e8d7327b) Pi Ba
02:07 PM Revision 489ff1a3: Change get_interface_subnet() to use configured value if available.
(cherry picked from commit 77a6cafbc02c0bbd4075237cca849841561bf6b3) Pi Ba
02:07 PM Revision dae6aba5: openvpn, fix the ifconfig ip1 ip2 when subnet /31 is used
(cherry picked from commit 10a8b5eea62e71aedc76e9eb3fc9630b73247a31) Pi Ba
02:07 PM Revision ba2b547f: Merge pull request #3895 from PiBa-NL/20180106-openvpn-fix-subnet31
Renato Botelho
08:47 AM Feature #8184 (Resolved): pppoe, allow configuring pppoe on a carp interface so its only active on the master #3830
Luiz Souza
08:46 AM Bug #6974 (Resolved): radvd enabled on a disconnected interface kills RA completely on all interfaces
Luiz Souza
08:45 AM Bug #8056 (Confirmed): Bridge + CARP crashes/freezes pfSense
Luiz Souza
07:55 AM Bug #8056: Bridge + CARP crashes/freezes pfSense
The underlying FreeBSD bug is still open:
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=200319
The previous p...
Jim Pingle
06:43 AM Bug #8056: Bridge + CARP crashes/freezes pfSense
Confirmed - We have 2 Netgate 8860 1u appliances setup with CARP + Bridge and when upgrading from 2.3.4 to 2.4.2_1 we... Adam Boyhan

01/30/2018

03:49 PM Bug #8304 (Not a Bug): pfSense locks up when Android device connects to L2TP/IPsec VPN that uses forces SHA-256 in phase 2
The two crash reports in the submission from that IP address are different and at very low levels of code in the oper... Jim Pingle
03:43 PM Bug #8304: pfSense locks up when Android device connects to L2TP/IPsec VPN that uses forces SHA-256 in phase 2
Ah, I see. I'm a bit new to bug reporting.
My WAN IP was 158.174.30.59.
I didn't make a Reddit post or anything...
Justin Lex
08:32 AM Bug #8304 (Feedback): pfSense locks up when Android device connects to L2TP/IPsec VPN that uses forces SHA-256 in phase 2
Is there a forum thread or reddit post with more detail? There isn't anything that stands out in what you have posted... Jim Pingle
02:04 AM Bug #8304: pfSense locks up when Android device connects to L2TP/IPsec VPN that uses forces SHA-256 in phase 2
I noticed I wasn't 100% clear on the conditions: The Android connection works just fine if I set for MD5 or SHA1 hash... Justin Lex
01:51 AM Bug #8304 (Not a Bug): pfSense locks up when Android device connects to L2TP/IPsec VPN that uses forces SHA-256 in phase 2
Discovered this by trying to follow this tutorial and messing with the encryption settings.
[[https://doc.pfsense.or...
Justin Lex
02:03 PM Bug #6263: Encryption options for every P2 on a given P1 are written to each P2 individually inside ipsec.conf with multiple P2 entries + split conn entries
Ran into this bug as well, though it appears to break things if you have too many phase 2 entries. After a certain n... PJ Goodwin
05:46 AM pfSense Packages Bug #8305 (Resolved): acme: "Key Size" value is not passed to acme.sh
Setting a "Key Size" in acme_certificates_edit.php has no effect. This variable is not passed on to the /usr/local/pk... Idar Lund

01/29/2018

06:56 PM Revision e0c3df40: Update OpenVPN wizard with current protocol selection options. Fixes #8298
(cherry picked from commit 7f054ea0b387cd8db372d92e04aed1a9c2ef028a) Jim Pingle
06:55 PM Revision 7f054ea0: Update OpenVPN wizard with current protocol selection options. Fixes #8298
Jim Pingle
05:27 PM Revision 834ac053: Fix a potential encoding issue in diag_system_activity.php. Fixes #8300
(cherry picked from commit c083e1e49af4902d15173d412feebd8b86a616ee) Jim Pingle
05:27 PM Revision f51de9fd: Add input validation to traffic_graphs_widget.php and fix JS encoding. Fixes #8302
(cherry picked from commit e7b5b82b121c76c4c6bf57229bfef0ea3bc33d5b) Jim Pingle
05:26 PM Revision e7b5b82b: Add input validation to traffic_graphs_widget.php and fix JS encoding. Fixes #8302
Jim Pingle
05:26 PM Revision fbcb1046: Re-enable CSRF protection in traffic_graphs_widget.php. Ticket #8301
(cherry picked from commit 9ee5030eecc99dd1e7a747f23870663715dfc21f) Jim Pingle
05:25 PM Revision 9ee5030e: Re-enable CSRF protection in traffic_graphs_widget.php. Ticket #8301
Jim Pingle
05:25 PM Revision 51992270: Fix a potential encoding issue in diag_system_activity.php. Fixes #8300
(cherry picked from commit c083e1e49af4902d15173d412feebd8b86a616ee) Jim Pingle
05:25 PM Revision bd866431: Fix a potential encoding issue in diag_system_activity.php. Fixes #8300
(cherry picked from commit c083e1e49af4902d15173d412feebd8b86a616ee) Jim Pingle
05:24 PM Revision c083e1e4: Fix a potential encoding issue in diag_system_activity.php. Fixes #8300
Jim Pingle
02:24 PM Bug #8303 (Resolved): Undefined Function
While looking over the widgets I noticed in the Gateways widget if you change the display type you get a Javascript e... Anonymous
01:10 PM Bug #8298 (Feedback): OpenVPN Wizard protocol defaults to "UDP IPv4 and IPv6 on all interfaces" causing problems
Applied in changeset commit:7f054ea0b387cd8db372d92e04aed1a9c2ef028a. Jim Pingle
11:40 AM Bug #8302 (Feedback): traffic_graphs.widget.php potential XSS via settings
Applied in changeset commit:e7b5b82b121c76c4c6bf57229bfef0ea3bc33d5b. Jim Pingle
11:23 AM Bug #8302 (Resolved): traffic_graphs.widget.php potential XSS via settings
traffic_graphs.widget.php does not perform input validation on its settings, which can lead to a potential XSS due to... Jim Pingle
11:40 AM Bug #8300 (Feedback): diag_system_activity.php: Potential XSS due to encoding of process output
Applied in changeset commit:c083e1e49af4902d15173d412feebd8b86a616ee. Jim Pingle
11:15 AM Bug #8300 (Resolved): diag_system_activity.php: Potential XSS due to encoding of process output
The @top@ command output is printed to the user without encoding, so if a malicious process is started which contains... Jim Pingle
11:20 AM Bug #8301 (Resolved): Dashboard Widgets may no longer need CSRF disabled
CSRF is deliberately disabled in some widgets stuch as traffic_graphs.widget.php but it's unclear if that is still ne... Jim Pingle
10:25 AM Revision 3b41c8f3: Fix dyndns update with gateway group
Vince C
10:23 AM Bug #7905: OpenVPN Authentication Against Backend Stalls All Server Traffic
I can also add that when two RADIUS servers are declared as backend authenticators and the first on the list fails (e... John Tikis
09:32 AM Bug #6400: assign_interfaces.php issues with large numbers of interfaces
The previous PR was reverted. Current PR is https://github.com/pfsense/pfsense/pull/3896 and it was merged on Jan 17. Jim Pingle
02:42 AM pfSense Packages Feature #8299 (Resolved): acme: ocsp must-staple
The acme.sh client supports ocsp must-staple;
if [ "$Le_OCSP_Staple" ] || [ "$Le_OCSP_Stable" ]; then
_savedo...
Idar Lund

01/27/2018

11:28 AM Bug #8298 (Resolved): OpenVPN Wizard protocol defaults to "UDP IPv4 and IPv6 on all interfaces" causing problems
The OpenVPN Wizard's default protocol is "UDP IPv4 and IPv6 on all interfaces (multihome). However, when you are bin... George Phillips
09:39 AM Feature #2358: NAT64 support
UPVOTE!!
at the moment I have to use an external router to do this!
Marco Vaschetto

01/26/2018

07:37 PM Revision d69a55e3: Fixed #8297 If user has no page permissions it will automatically log them out so they don't get stuck on the logout page
Stephen Jones
03:35 PM Bug #8297 (Resolved): User with no privileges cannot logout.
Works better now, thanks! Jim Pingle
01:47 PM Bug #8297 (Feedback): User with no privileges cannot logout.
Commit pushed. d69a55e3d647795477606e844f79bb94fc127f24 Anonymous
01:08 PM Bug #8297 (Resolved): User with no privileges cannot logout.
If there is a created user and they have no permissions they will see a page that says: "No page assigned to this use... Anonymous
03:28 PM Bug #7412 (Resolved): rtsold will not run on VLAN interfaces
Looks good now. SG-1000 with a VLAN WAN pulls an IPv6 address and default gateway now, without the "Do not wait for R... Jim Pingle
12:00 PM pfSense Packages Bug #8229: syslog-ng stops parsing logs after logrotate run
Well, tried syslog-ng-3.13.2_1 from http://pkg.freebsd.org/FreeBSD:11:amd64/latest/All/ but that went crazy after a c... Orion Poplawski
10:09 AM Feature #8257: pfSense Diagnostics -> Packet Capture support for loopback interface
Tested build 2.4.3.a.20180126.0706
Navigated to Diagnostics -> Packet Capture
Localhost is available in interfa...
James Snell
06:17 AM Bug #8056: Bridge + CARP crashes/freezes pfSense
Confirmed - I can also replicate this easily. CARP on a bridged interface, tested on 2.4.2 and 2.4.2_1 with no change... James Freeman
06:04 AM Revision 82f581d5: Improve the CARP description.
No functional change. Luiz Souza
06:04 AM Revision a9a74b49: Merge pull request #3830 from PiBa-NL/20170925-pppoe-on-carpmaster
Luiz Souza
 

Also available in: Atom