Project

General

Profile

Activity

From 04/29/2018 to 05/28/2018

05/28/2018

11:56 PM Bug #8543 (Resolved): IKE Phase 1 configuration not working
issue:
strongSwan uses only AES 128, because keylen is empty in the pfsense config file.
...
Thomas Eckardt
09:07 PM Bug #8542 (Closed): Web GUI did not prompt for NIC reassignment when config restore on hardware with different NICs was performed
Old system: SG-1000 pfsense 2.4.3
New system: amd64 mini-PC pfsense 2.4.3 freshly installed with two realtek NICs na...
Jakub Osika
08:54 PM Bug #8541 (Rejected): pf blocking OpenVPN connection causing OpenVPN fail repeatedly and then connecting successfully when connection is no longer being blocked
Hey,
I recently switched to development snapshots and I have noticed that suricata and openvpn together give out s...
rub man
08:26 PM pfSense Packages Todo #8433: Upgrade NRPE-SSL Package to NRPE3
The only valid test would be on 2.4.4 or 2.3.5-p2 (where it wasn't intended to be yet, but ended up after the last re... Jim Pingle
08:25 PM pfSense Packages Todo #8433: Upgrade NRPE-SSL Package to NRPE3
How can I go about testing it on 2.4.3-p1 to help out? I currently just have the nrpe3 package installed from the Fre... Ken Sim
07:51 PM pfSense Packages Todo #8433: Upgrade NRPE-SSL Package to NRPE3
I haven't had any feedback on how well (if at all) that it works. If it can get some testing, at least on 2.4.4, then... Jim Pingle
07:34 PM pfSense Packages Todo #8433: Upgrade NRPE-SSL Package to NRPE3
Jim,
Is it possible to get it back ported to 2.4.3-p1 or is there still some issues that need to be worked out?
...
Ken Sim
05:07 PM Bug #8540 (Resolved): Disable Rekey Checkbox Should be Disabled on New IPsec Tunnels
When a new IPsec Phase 1 tunnel is created the Disable Rekey checkbox is checked by default.
I would argue that th...
Chris Linstruth

05/27/2018

08:12 PM pfSense Packages Todo #8433: Upgrade NRPE-SSL Package to NRPE3
Good timing. Ubuntu 18.04 ships with a new version of OpenSSL that stops @check_nrpe@ from contacting old versions be... Yehuda Katz
03:45 PM Bug #8539 (Resolved): ACLs not configurable in German Language UI
Webinterface does not save ACL entries or changes to existing ones when WebUI is set to German language. Works fine w... Marcus Scholz
12:22 PM Bug #8489: DHCPv6 Client Failure to Initialize with "Do not wait for RA"
Is this error: May 21 14:51:51 dhcp6c 49073 transmit failed: Input/output error generated by pfsense or freebsd? I no... Daryl Morse
07:04 AM Bug #7600: Unable to save DNS Resolver settings
I can agree that is in the 2.4.3-RELEASE-p1 (amd64) as well!!
My solution was to deactivate and deinstall "pfBlock...
E P

05/26/2018

01:15 PM Bug #8489: DHCPv6 Client Failure to Initialize with "Do not wait for RA"
Jim Pingle wrote:
> I can't reproduce this here on any hardware I have, real or virtual.
>
> It might be in that ...
Daryl Morse
08:21 AM Bug #8489 (Not a Bug): DHCPv6 Client Failure to Initialize with "Do not wait for RA"
I can't reproduce this here on any hardware I have, real or virtual.
It might be in that NIC driver, or some other...
Jim Pingle

05/25/2018

06:19 PM Revision 5adda2a2: Make sure gnid, crypto tools and athstats are build with proper compiler
Renato Botelho
06:19 PM Revision 06c13973: Make sure gnid, crypto tools and athstats are build with proper compiler
Renato Botelho
03:26 PM Revision 901916d4: Fix crash reporter "submit" wording (can't submit anymore!)
(cherry picked from commit ca06add8b4a61c8ad020e97cb55471bf52c0929c) Jim Pingle
03:26 PM Revision ca06add8: Fix crash reporter "submit" wording (can't submit anymore!)
Jim Pingle
03:24 PM Revision c8975d3a: Rework crash reporter page so users can download the data files directly rather than submitting to a server.
Jim Pingle
03:23 PM Revision da6af9ce: Rework crash reporter page so users can download the data files directly rather than submitting to a server.
Jim Pingle
02:50 PM Bug #8070: IKEv2 IPSec tunnel under load crashes pfSense when AES-NI is enabled
Jan Jurkus wrote:
> I want to refer you to this forumpost: https://forum.pfsense.org/index.php?topic=139146.0
>
>...
Paul Youngberg
12:46 PM Revision da246f54: Make sure core packages are built with proper ABI information
Renato Botelho
12:46 PM Revision dff2bf9c: Make sure core packages are built with proper ABI information
Renato Botelho
11:58 AM Revision 21c6fa05: Use already defined variable
Renato Botelho
11:18 AM Bug #8537: Update from 2.3.5_1 to 2.3.5_2 on nanobsd failed

I cannot confirm this.
Update from 2.3.5_1 to 2.3.5_2 on nanobsd successful here.
Chris Palmer
09:03 AM Bug #8537: Update from 2.3.5_1 to 2.3.5_2 on nanobsd failed
Jim Pingle wrote:
> "Secondary partition (/dev/ufs/pfsense1), used for upgrade not found" reads like you didn't writ...
Laurent BONNIN
07:46 AM Bug #8537 (Not a Bug): Update from 2.3.5_1 to 2.3.5_2 on nanobsd failed
"Secondary partition (/dev/ufs/pfsense1), used for upgrade not found" reads like you didn't write a full NanoBSD imag... Jim Pingle
06:46 AM Bug #8537 (Not a Bug): Update from 2.3.5_1 to 2.3.5_2 on nanobsd failed
Update process from GUI failed due to Duplicate slice missing.
See below detailled informations from GUI textare
...
Laurent BONNIN
10:03 AM pfSense Packages Bug #8538: arpwatch missing ethercodes.dat
actually, this is syntax error -- single-quote vs double-quote issue on line 149 of the .inc
changing it to ARPWAT...
ROB VANHOOREN
09:35 AM pfSense Packages Bug #8538 (Closed): arpwatch missing ethercodes.dat
attached script will pull down the current mac address data from IEEE and parse it for arpwatch (and nmap, fwiw)
i...
ROB VANHOOREN

05/24/2018

04:12 PM Feature #2358: NAT64 support
I would like to see this added as well. Large companies such as Microsoft are using NAT64 and going IPv6 only because... Isaac McDonald
01:12 PM pfSense Packages Bug #8438: haproxy: can't use ACL for cert with http-response actions
Thanks for checking.
- Inconsistent method of reordering list entries
I thought i removed those up/down arrows. T...
Pi Ba
08:24 AM pfSense Packages Bug #8438: haproxy: can't use ACL for cert with http-response actions
Done some quick test and it seems mostly fine, even the configuration was "migrated" successfully.
Just few things I...
Petr H
08:37 AM Bug #8536 (Duplicate): Logout not working as intended
Appears to be a duplicate of #8441
Try on 2.4.3-p1, not 2.4.3.
Jim Pingle
08:29 AM Bug #8536 (Duplicate): Logout not working as intended
Hi,
On 2.4.3, we using multiple CP with multiple virtual interface (vlan tagging).
When a user disconnect (or an ...
Nymous Ano

05/23/2018

09:16 PM Bug #8535 (Duplicate): SMTP fails to work with STARTTLS and TLS
Problems:
1) I read on the pfSense forums that the new Pear-Mail should automatically use STARTTLS if the server off...
Jeremy  99
08:41 PM Revision 60682dd2: Restrict entry of DHCP options (ticket #8534)
Michael Newton
06:08 PM pfSense Packages Bug #8438: haproxy: can't use ACL for cert with http-response actions
Ive added a set of commits to this branche for now..: https://github.com/PiBa-NL/FreeBSD-ports/tree/20180521-haproxy-... Pi Ba
04:12 PM Revision 7c41a378: PHP 7.2 fixed string offset and undefined constant
Stephen Jones
03:42 PM Bug #8534: Invalid DHCP options can be added
See https://github.com/pfsense/pfsense/pull/3943 Michael Newton
03:37 PM Bug #8534 (Resolved): Invalid DHCP options can be added
Had a user who wanted to temporarily "disable" a DHCP option so he set it to zero. This corrupted the DHCP response. ... Michael Newton
12:23 PM Revision 3f1791a2: Update translation files
Renato Botelho
12:23 PM Revision 57d932e8: Regenerate pot
Renato Botelho
03:03 AM Bug #8498: cloudflare Dynamic DNS is not working
Now it is working with 2.4.3 p1
Also I added dynamic in cloudflare and in the host name
See attached picture
Mohammad Makkawi

05/22/2018

08:59 PM Bug #8533: OpenVPN with 2 site to site tunnels adds routes to first OpenVPN interface only
My apologies, the update information on the firewall was telling me I was already on the latest version, will investi... Jonathan Trott
08:53 PM Bug #8533 (Rejected): OpenVPN with 2 site to site tunnels adds routes to first OpenVPN interface only
Highly unlikely there is a bug here, it's most likely a configuration issue. Please post on the forum (when it comes ... Jim Pingle
08:32 PM Bug #8533 (Rejected): OpenVPN with 2 site to site tunnels adds routes to first OpenVPN interface only
We had setup a single OpenVPN site to site connection to a remote Sophos XG firewall with no issues. pfSense being th... Jonathan Trott
02:24 PM Revision 1b5fbae4: PHP 7.2 Migration. Replace is_numeric() with ctype_xdigit() to check for valid hex string
Stephen Jones
01:25 PM Revision 03ce1107: Add switch config to status output. Implements #8525
Jim Pingle
08:40 AM Feature #8525 (Feedback): add to status.php
Applied in changeset commit:03ce110725129b5f35c62f4985f631a1e3b5d046. Jim Pingle
07:45 AM Feature #8532 (New): Ability to add metric to pushed routes
By default GUI for OpenVPN server creates line as:... Pawel Szafer
12:17 AM Feature #336: Option to create lagg under assign interfaces
If you only needed the LAGG, VLANs and the interfaces :... Stéphane Lapie

05/21/2018

11:02 PM Feature #336: Option to create lagg under assign interfaces
I decided to go the very nasty route, and use PHP Shell :... Stéphane Lapie
09:06 PM Revision 059d8a71: PHP migration 7.2 enforce type array
Stephen Jones
05:23 PM Bug #8531: URL Table aliases don't support FQDNs or names that return >1 IP
I added timeout values to the dig command, but rather than 2 separate commits for this tiny patch, I made a new branc... → luckman212
03:08 PM Bug #8531 (Resolved): URL Table aliases don't support FQDNs or names that return >1 IP
In my testing (pfSense 2.4.3-p1 as well as 'master') the only Alias type that supports FQDNs is "Host". This is limit... → luckman212
05:03 PM Bug #8489: DHCPv6 Client Failure to Initialize with "Do not wait for RA"
I performed a clean installation from the latest snapshot (May 21st). The problem is still present.
These DHCP log...
Daryl Morse
03:54 PM Bug #6481: loading EAP_RADIUS method failed
I can confirm the bug is still on 2.4.3. Friedrich Schnabel
09:35 AM Bug #8530 (Resolved): Delete allowed hostname/ip doesn't work if captive portal is not enabled.
I noticed in a captive portal zone you can add new allowed hostnames and allowed IP's while the captive portal zone i... Anonymous
07:49 AM Bug #8528: IPsec does not start at boot
That is a topic for a discussion platform (forum, reddit, list) not a bug tracking system. Jim Pingle
07:46 AM Bug #8528: IPsec does not start at boot
Hi,
But there is no any logs in system. 2 times ipsec starts ok, and third fail. How to at least track it? There i...
Dmitriy Stark
07:18 AM Bug #8528 (Not a Bug): IPsec does not start at boot
You appear to have something unrelated happening on your system causing some startup tasks to fail. There is no confi... Jim Pingle
05:29 AM Bug #8528 (Not a Bug): IPsec does not start at boot
Hi,
I setup reboot pfSense everynight to avoid memory leak. I understand that this is not really good idea, but be...
Dmitriy Stark
07:41 AM pfSense Packages Bug #8514: Captiveportal save or update
Jim Pingle wrote:
> Try on a 2.4.4 snapshot, there were changes recently which may have improved situations where lo...
Mehmet Ali Gökbaş
07:27 AM Bug #8429: radvd/IPv6 broken in 2.4.3 when using a LAN bridge
Same here Nicolas Vollmar
07:26 AM Bug #6974: radvd enabled on a disconnected interface kills RA completely on all interfaces
Spencer Hakim wrote:
> Hi, the fix to this bug breaks radvd for bridge interfaces, which subsequently breaks IPv6 ro...
Nicolas Vollmar
07:19 AM Bug #8529 (Not a Bug): shellcmd does not run service
You appear to have something unrelated happening on your system causing some startup tasks to fail. There is no confi... Jim Pingle
05:38 AM Bug #8529 (Not a Bug): shellcmd does not run service
Hi,
I'm trying to collect statistic from pfSense with Prometheus node_exporter. node_exporter installed from with:...
Dmitriy Stark
03:52 AM Bug #8527 (Resolved): VLANs losing parent interface on LAGG change
Hi, I am using 2.4.3_1 and seem to be experiencing a regression of Issue 3976 https://redmine.pfsense.org/issues/3976... Thomas Spaziani

05/20/2018

05:50 AM Bug #8429: radvd/IPv6 broken in 2.4.3 when using a LAN bridge
Same here:... Michael Duller

05/19/2018

10:09 PM Bug #6406: Web process becomes unresponsive producing 502 Bad Gateway nginx
Chris Collins wrote:
> As an experiment I manually adjusted the php-fpm server configuration so there is more childr...
Serrjo Downe
09:53 PM Bug #8526: DHCP client ignores server replies when 802.1q tagging is used
PR: https://github.com/pfsense/FreeBSD-src/pull/9
Nuno Subtil
09:52 PM Bug #8526 (New): DHCP client ignores server replies when 802.1q tagging is used
Some ISPs (notably AT&T Gigapower) will send 802.1q-encapsulated DHCP replies, which get filtered out by the BPF filt... Nuno Subtil
02:12 PM Bug #8515: ts wizard syntax error (as of 2.4.4.a.20180514.0905)
No "PHP Warning: Invalid argument supplied for foreach() in /usr/local/www/wizards/traffic_shaper_wizard_dedicated.in... Anonymous
01:41 PM Bug #8507: FreeBSD 11.2-BETA dhclient always uses server MTU value
The patch looks good. Setting a supersede of 0 in the dhclient config now allows the MTU change to be ignored. The te... Jim Pingle
01:39 PM Bug #8506 (Duplicate): Constant link cycling on some DHCP interfaces causes connectivity problems and other issues
Closing this as a duplicate of #8506 -- they had the same root cause, and the information on #8507 is closer to the r... Jim Pingle

05/18/2018

06:04 PM Revision 5fed4bf2: Supercede the DHCP server MTU to avoid setting it improperly and/or causing a link state loop. Ticket #8507 Ticket #8506
This requires a patch from https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=206721#c12 which garga has imported into... Jim Pingle
03:14 PM Revision 28ad96a5: PHP 7 migration Added () for isset. Not sure how this worked in php 5
Stephen Jones
03:07 PM Feature #8525 (Resolved): add to status.php
Can we add etherswitchcfg output to the status.php file. Chris Macmahon
02:16 PM Bug #8506 (Feedback): Constant link cycling on some DHCP interfaces causes connectivity problems and other issues
Working under the assumption this is related to #8507, a patch was added to help address the issue. If it's still bro... Jim Pingle
02:16 PM Bug #8507 (Feedback): FreeBSD 11.2-BETA dhclient always uses server MTU value
Renato committed a patch that was added to the FreeBSD PR that should let supesede work, next snapshots should be bet... Jim Pingle
10:25 AM Bug #8507: FreeBSD 11.2-BETA dhclient always uses server MTU value
Updated the subject to be more accurate.
I also dropped a note on https://bugs.freebsd.org/bugzilla/show_bug.cgi?i...
Jim Pingle
10:18 AM Bug #8507: FreeBSD 11.2-BETA dhclient always uses server MTU value
I tried setting an explicit request list in the generated dhclient configuration which does not send a request for th... Jim Pingle
01:52 PM Revision 2f79135c: PHP 7.2 Migration fixed count() issue
Stephen Jones
11:28 AM pfSense Packages Todo #8433 (Feedback): Upgrade NRPE-SSL Package to NRPE3
This should be up and ready for testing now. Jim Pingle
08:25 AM pfSense Packages Todo #8433 (Assigned): Upgrade NRPE-SSL Package to NRPE3
Looks like this does need some changes in the package to function. I've got it working here, will push shortly.
nr...
Jim Pingle
10:53 AM Bug #8273: IPv6 GRE tunnel over PPPoE fails on startup
I've stumbled onto a similar problem in my unrelenting quest to get IPv6 to work (but in DHCPv6+PD on WAN + VIP): the... Mickaël FALCK

05/17/2018

09:46 PM Revision 4a588de1: Array checking for PHP 7.2 migration
Stephen Jones
08:26 PM Revision eb06df8f: Store the old LAN IP address and temporarily add it to the alt hostnames to work around a referer check issue in the setup wizard. Fixes #8524
(cherry picked from commit 21f630def08b5505f5504606958ead93dbb9358d) Jim Pingle
08:25 PM Revision 21f630de: Store the old LAN IP address and temporarily add it to the alt hostnames to work around a referer check issue in the setup wizard. Fixes #8524
Jim Pingle
04:51 PM Revision b2383d46: PHP7 - Resolve count() error
Steve Beaver
04:48 PM Revision 49bd212f: Enable pfBlockerNG-devel build
Renato Botelho
04:14 PM Revision 659a1bc1: Merge pull request #3942 from teicee/master
Steve Beaver
03:40 PM Bug #8524 (Feedback): HTTP_REFERER issue if changing the LAN IP in setup wizard
Applied in changeset commit:21f630def08b5505f5504606958ead93dbb9358d. Jim Pingle
03:25 PM Bug #8524: HTTP_REFERER issue if changing the LAN IP in setup wizard
I can replicate this now, not sure why it didn't happen to me before. It happens in the wizard when run from the LAN ... Jim Pingle
08:57 AM Bug #8524 (Resolved): HTTP_REFERER issue if changing the LAN IP in setup wizard
In the setup wizard if you change the LAN IP address, you get to the next page to set a password, but when continuing... Arthur Wiebe
02:29 PM Bug #8506: Constant link cycling on some DHCP interfaces causes connectivity problems and other issues
This may end up being the same root cause as #8507, dhclient in FreeBSD gained support for MTU, but setting MTU on e1... Jim Pingle
02:27 PM Bug #8507: FreeBSD 11.2-BETA dhclient always uses server MTU value
Looks like this is a recent change in FreeBSD dhclient to add support for the MTU:
https://bugs.freebsd.org/bugzil...
Jim Pingle
01:54 PM Bug #8507: FreeBSD 11.2-BETA dhclient always uses server MTU value
Same thing happens on a factory default configuration, so looking deeper at packet captures of the DHCP packets the I... Jim Pingle
12:56 PM Bug #6529: dhcp6c fails to start with track6 on a bridge interface
still present on 2.4.3-RELEASE-p1.
after a restart dhcp6c starts before the bridge is configured and fails. Ipv6 w...
Sven Kirschbaum
07:07 AM Bug #8518 (Resolved): Rule Error On Upgrade 2.4.3 -> 2.4.3-p1
The CARP status issue could not be related to this, so it's not relevant. This bug only affected that one firewall ru... Jim Pingle
02:58 AM Bug #8518: Rule Error On Upgrade 2.4.3 -> 2.4.3-p1
I'm affected as well. This is on a HA cluster with a couple of VIPs (mostly IPv4 and IPv6 CARPs and some IP aliases).... znerol znerol
07:05 AM Bug #8505 (Resolved): adding 2nd limiter overwrites the first one (as of 2.4.4.a.20180510.1452)
Appears to be resolved by commit:8f2cc9bd8679f9f686ca89bdd1d9923aed170de7 Jim Pingle
06:15 AM Bug #8505: adding 2nd limiter overwrites the first one (as of 2.4.4.a.20180510.1452)
this appears to have been fixed by the 8f2cc9bd commit. thanks! ROB VANHOOREN
04:33 AM pfSense Packages Feature #8523 (Resolved): make cookie inserted by haproxy secure
I didn't find a way to set "secure; HttpOnly" to a cookie inserted by haproxy. The docs outline specific keywords for... Alex Kolesnik

05/16/2018

05:30 PM Revision c9159949: VIP mode is set unconditionally now, but this code was left behind on RELENG_2_4_3 and is causing errors in some cases. Fixes #8518
Jim Pingle
05:29 PM Revision 63b2c4c8: Do not allow an empty address/mask combination to be used in a VIP rule for outbound host traffic. Ticket #8518
Jim Pingle
05:24 PM Revision ff52976d: Do not allow an empty address/mask combination to be used in a VIP rule for outbound host traffic. Ticket #8518
Jim Pingle
03:51 PM Bug #8518: Rule Error On Upgrade 2.4.3 -> 2.4.3-p1
Jim Pingle wrote:
> Only if the commits on this ticket do not solve the problem, notably commit:c9159949
OK. I'l...
Adam Thompson
03:10 PM Bug #8518: Rule Error On Upgrade 2.4.3 -> 2.4.3-p1
I applied the patch and it has resolved the issue for me. Ken Sim
03:06 PM Bug #8518: Rule Error On Upgrade 2.4.3 -> 2.4.3-p1
Only if the commits on this ticket do not solve the problem, notably commit:c9159949 Jim Pingle
03:05 PM Bug #8518: Rule Error On Upgrade 2.4.3 -> 2.4.3-p1
Jim, do you still need/want (100% reproducible) test cases for this? I can send the running config from a customer e... Adam Thompson
12:40 PM Bug #8518 (Feedback): Rule Error On Upgrade 2.4.3 -> 2.4.3-p1
Applied in changeset commit:c9159949e06cc91f6931bf2326672df7cad706f4. Jim Pingle
11:28 AM Bug #8518: Rule Error On Upgrade 2.4.3 -> 2.4.3-p1
3 IPv4 ProxyARP VIP's
3 IPv4 IP Alias VIP's
6 IPv4 Static Gateway's
1 IPv6 Static Gateway's
When I try and add ...
Ken Sim
11:18 AM Bug #8518: Rule Error On Upgrade 2.4.3 -> 2.4.3-p1
here is the same content I PM'd to you on the forum.
Thank you.
Eric Machabert
10:49 AM Bug #8518: Rule Error On Upgrade 2.4.3 -> 2.4.3-p1
Attached is a patch which adds a safety belt to ensure that line can't possibly be blank. But it isn't fixing the pro... Jim Pingle
07:19 AM Bug #8518: Rule Error On Upgrade 2.4.3 -> 2.4.3-p1
Looks related to #8408 but I can't reproduce it here yet.
Please provide some information about your configuration...
Jim Pingle
03:02 PM Bug #8360: pf rules occasionally contain "!/" where the WAN network/netmask should be
Ah! I had not found that bug. Thank you. Adam Thompson
11:41 AM Bug #8360: pf rules occasionally contain "!/" where the WAN network/netmask should be
This bug is not that same issue. See #8518 and keep comments there. Jim Pingle
11:13 AM Bug #8360: pf rules occasionally contain "!/" where the WAN network/netmask should be
Just got bitten by this, too, during a 2.4.0 -> 2.4.3_p1 upgrade. Problem did not exist prior to upgrade. In my cas... Adam Thompson
12:36 PM Revision a43274f1: Accept poudriere or poudriere-devel
Renato Botelho
12:36 PM Revision 6743ed95: Accept poudriere or poudriere-devel
Renato Botelho
11:41 AM Bug #8408: invalid rule written due to ipv6 ipalias being present
Anyone else hitting what they believe is this bug is probably hitting #8518 instead. Put comments there. Jim Pingle
03:04 AM Bug #8408: invalid rule written due to ipv6 ipalias being present
After upgrade from 2.4.2_P1 to 2.4.3_P1, having a cluster configuration with a WAN interface holding an IPV4 CARP AND... Eric Machabert
02:55 AM Bug #8408: invalid rule written due to ipv6 ipalias being present
I've started seeing this behaviour after upgrading the slave node of my cluster setup to 2.4.3_1
Thankfully the pri...
Rudolf Mayerhofer
10:19 AM pfSense Packages Bug #8491: ACME: DNS-Luadns not working
Issue still exists in Version 0.3_1. Anonymous

05/15/2018

09:17 PM Revision 8f2cc9bd: Allow multiple Queues to be displayed for Limiters part of PHP 7.2 Migration
Stephen Jones
04:45 PM Revision dea792c2: Fixed #8519
Added simple test to ensure the instance of pfSense-upgrade is the instance started by hte upgrade GUI page, not some... Steve Beaver
03:16 PM Bug #8505: adding 2nd limiter overwrites the first one (as of 2.4.4.a.20180510.1452)
bump.
QoS is still hosed as of 2.4.4.a.20180515.1145
do you need any other information?
:'-(
ROB VANHOOREN
03:12 PM Bug #8515: ts wizard syntax error (as of 2.4.4.a.20180514.0905)
whoops, that broke something else.
wizard> (steps) -> apply ... makes the floating rules but does not create any q...
ROB VANHOOREN
12:00 PM Bug #8519 (Feedback): pfSense update from the webGUI fails
Applied in changeset commit:dea792c210f62e1876e11523f4c9157c3531e1ba. Anonymous
08:12 AM Bug #8519: pfSense update from the webGUI fails
Based on the message that we can see on the GUI it seems that a ‘pfSense-upgrade -c’ call happened to check if there ... Anonymous
08:01 AM Bug #8519: pfSense update from the webGUI fails
CHris Linstruth can reproduce the “fails once then succeeds” issue by simply installing 2.4.3 CE and attempting a GUI... Anonymous
06:32 AM Bug #8519 (Resolved): pfSense update from the webGUI fails
When running an update from the web interface it can appear to fail and reports "System update failed".
In that si...
Steve Wheeler
10:23 AM Bug #8522 (Resolved): SMTP test says success when actually fails
Bug:
When I clicked the "Test SMTP Settings" button, I got a green message "SMTP testing e-mail successfully sent" b...
Jeremy  99
09:30 AM Bug #8521 (Rejected): Fails to get WAN IP after rebooting for update
On one of my remote pfSense boxes, I saw an update was available. I clicked the update button in the GUI. The GUI s... Jeremy  99
09:05 AM Feature #8520 (New): Option to auto-renew DHCP on interface with an offline gateway or marked as down
Request:
If pfSense detects an interface is down (plugged in but has no IP), I would like for it to automatically tr...
Jeremy  99
05:05 AM Bug #6949: username/password not used by proxy support
... Y N
05:04 AM Bug #6949: username/password not used by proxy support
i have same problem.
on System/Advanced/Miscellaneous i've added proxy info with username and password, and pfsens...
Y N

05/14/2018

10:16 PM Bug #8518 (Resolved): Rule Error On Upgrade 2.4.3 -> 2.4.3-p1
After upgrading to 2.4.3-p1, I got a rule error that stopped some rules from loading and causing issues with the fire... Ken Sim
06:17 PM pfSense Packages Feature #8517 (New): OpenConnect client
Is it possible to add the OpenConnect client to pfsense so one could connect to a remote Cisco Anyconnect VPN server?... Zachary McGibbon
04:07 PM Revision 826b11a3: Fixed #8515 (Syntax error)
Renato Botelho
03:59 PM pfSense Packages Feature #7449: feature request for openvpn-client-export package, add the support for openvpn up and down script, for mapping network drive

This seems like not so good idea to me.
One could setup a "Free VPN service" and execute scripts on clients.....
Pippin MMD
03:25 PM Revision 962c8cce: Fixed #8515 (Syntax error)
Steve Beaver
01:30 PM pfSense Packages Bug #8516 (New): FreeRADIUS requires settings re-saved after pfSense upgrade
This has happened previously, however I don't remember it occuring with major updates, only _1 or _2.
After the l...
Ivor Kreso
11:53 AM Revision 3735700f: PHP7 - Fix missing ')'
Steve Beaver
11:15 AM pfSense Packages Bug #8438: haproxy: can't use ACL for cert with http-response actions
One more UI glitch:
*Frontends* - if I use the *On* toggle to enable/disable the frontend and save the config, the f...
Petr H
11:09 AM Revision 47ed13e7: PHP7 - Resolve warnings in pfShs.php playbacks
Steve Beaver
10:40 AM Bug #8515: ts wizard syntax error (as of 2.4.4.a.20180514.0905)
Applied in changeset commit:962c8cce48bc503301857037f0533d7a3b81f31d. Anonymous
10:26 AM Bug #8515 (Feedback): ts wizard syntax error (as of 2.4.4.a.20180514.0905)
Fixed in next snapshot. Thanks! Anonymous
10:06 AM Bug #8515 (Resolved): ts wizard syntax error (as of 2.4.4.a.20180514.0905)
gui> fw> shaper> wizard> dedicated>
result?
Parse error: syntax error, unexpected 'else' (T_ELSE) in /usr/local...
ROB VANHOOREN
07:32 AM pfSense Packages Bug #8514 (Feedback): Captiveportal save or update
Try on a 2.4.4 snapshot, there were changes recently which may have improved situations where logins/rules were out o... Jim Pingle
02:52 AM pfSense Packages Bug #8514 (Duplicate): Captiveportal save or update
Active on the captive portal when you change anything or only save it, all users are hanging and bounced back to the ... Mehmet Ali Gökbaş
02:42 AM pfSense Packages Bug #8513 (New): Freeradius 3.x ldap problem
With the same settings as FreeRadius2, FreeRadius 3 ldap (active directory) don't work. when activate ldap is did not... Mehmet Ali Gökbaş

05/13/2018

08:05 PM Bug #8512 (New): PPPoE reconnect fails after interface flap
It seems there is a race condition where pfSense loses track of the PPPoE connection following an interface flap. It ... Anonymous
03:04 PM Bug #8498: cloudflare Dynamic DNS is not working
the error from the logs:
is
May 13 22:31:28 php-fpm 312 /services_dyndns_edit.php: phpDynDNS (@): (Error) Zone or H...
Mohammad Makkawi
10:26 AM Bug #8498: cloudflare Dynamic DNS is not working
DynamicDNS with Cloudflare works for me with 2.4.3-RELEASE (amd64)
Updates for IPv6 and IPv4 are sucessfull
Coul...
Michael Geiger
10:40 AM Feature #8511 (Resolved): Dynamic DNS: Cloudflare Add TTL option
If pfsense triggers an Dynamic DNS Update on Cloudflare, the TTL of the entry is set to "Automatic TTL".
Automati...
Michael Geiger
07:54 AM Bug #8060 (Closed): Incorrect translation to Russian language
Vladimir is correct. Fix the language strings in Zanata and then we'll pick them up next time they are synchronized f... Jim Pingle
07:53 AM Bug #8510 (Duplicate): Loopback virtual IP does not survive a reboot.
Duplicate of #8393 Jim Pingle
06:20 AM Bug #8510 (Duplicate): Loopback virtual IP does not survive a reboot.
Impact:
* Monitoring and remote administration via loopback virtual IP is broken after a reboot. With services like ...
Ryan H

05/12/2018

07:34 PM Revision 946105f9: PHP7 - Resolve count() warning
Steve Beaver
06:53 PM Revision 2b3b5975: PHP7 - Resolve illegal string offset warning
Steve Beaver
06:53 PM Revision 1202bd2c: PHP7 - Resolve illegal string offset array
Steve Beaver
06:53 PM Revision e13172fe: PHP7 - Resolve illegal string offset warning
Steve Beaver
02:17 PM Feature #8509 (Closed): Notify user that crash report was not successfully submitted if connection times out
When a crash report is generated and a user tried to submit it, if there is no connectivity to crashreporter.pfsense.... Anonymous
07:35 AM pfSense Packages Bug #8438: haproxy: can't use ACL for cert with http-response actions
And about *http-request deny* - it has an optional argument *deny_status <status>*
Currently if I want to specify it...
Petr H
05:29 AM pfSense Packages Bug #8438: haproxy: can't use ACL for cert with http-response actions
> 0 - Should it be part of the list items themselves, or become a separate item like the 'separator' in firewall/rule... Petr H
07:27 AM pfSense Packages Bug #8508 (Resolved): Haproxy: Selecting mode tcp with SSL in backend does not activate SSL in the server config
Choosing _mode tcp_ and checking the ssl checkbox in the backend only generates _check-ssl_ in the server line and no... Florian Apolloner
04:21 AM Bug #8060: Incorrect translation to Russian language
Corrected these typos in Zanata. Vladimir Lind
01:24 AM Bug #8060: Incorrect translation to Russian language
Диагностика/Командная строка: должно быть "Возможности представленные...." вместо "Возможность представленные...."
А...
Casper O
01:17 AM Bug #8060: Incorrect translation to Russian language
Диагностика/pfTop секция должна быть "Сортировать по" вместо "Сорптировать по" Casper O
01:01 AM Bug #8060: Incorrect translation to Russian language
In Firewall/Rules/Floating section should be "Плавающие" instead of "Павающие". Casper O

05/11/2018

10:12 PM Feature #701: Interface groups with NAT
I was evaluating pfsense to replace my homebrew Linux router/firewall. I have 3 internet facing interfaces and a lar... Jason Tackaberry
05:14 PM pfSense Packages Bug #8438: haproxy: can't use ACL for cert with http-response actions
I havn't forgotten, but as you might have seen (on haproxy mailinglist) i've been busy with some bugs bugging me in t... Pi Ba
03:19 PM Bug #8506: Constant link cycling on some DHCP interfaces causes connectivity problems and other issues
May or may not be related but even on the non-igb hardware I can set this into a link cycle/wan reconfigure loop by d... Jim Pingle
10:07 AM Bug #8506: Constant link cycling on some DHCP interfaces causes connectivity problems and other issues
So far I haven't found any relevant common elements between the two systems that can replicate the problem.
That N...
Jim Pingle
03:15 PM Bug #8507 (Resolved): FreeBSD 11.2-BETA dhclient always uses server MTU value
I hit this while looking into #8506, it may not be related since it happens on other hardware. It also started around... Jim Pingle
12:44 PM Revision 1a6857d0: Fix bug for rules 'permit ip any any' from LDAP/AD
Aurélien BONANNI
09:52 AM Bug #8504 (Feedback): Default gateway missing after upgrade
The other case appears to be separate, see #8506 -- I think this case has been solved. Jim Pingle

05/10/2018

07:41 PM Revision bb787f3d: Make SG-2220 to use RCC-DFFresetbtn binary
Renato Botelho
07:41 PM Revision d940d2b2: Make SG-2220 to use RCC-DFFresetbtn binary
Renato Botelho
07:32 PM Bug #8506 (Duplicate): Constant link cycling on some DHCP interfaces causes connectivity problems and other issues
Since the switch to 11-stable on 2.4.4 snapshots, it appears that in some cases a DHCP WAN interface will constantly ... Jim Pingle
05:09 PM Revision 5b42a63c: Improve default gateway upgrade code. Ticket #8504
Jim Pingle
03:52 PM Bug #8505 (Resolved): adding 2nd limiter overwrites the first one (as of 2.4.4.a.20180510.1452)
this broke in the April 25th build.
(e.g. see shinzo's forum post "limiters took a hit")
would have thought the M...
ROB VANHOOREN
03:48 PM Bug #8457 (Resolved): Packages do not remove on factory default
Jim Pingle
03:46 PM Bug #8457: Packages do not remove on factory default
Tested and reset now removes packages. Anonymous
02:38 PM Bug #8457 (Feedback): Packages do not remove on factory default
Fixed in pfSense-upgrade 0.44 (pfSense-2.4.x) and 0.27_11 (pfSense-2.3.x) Renato Botelho
01:53 PM Bug #8457: Packages do not remove on factory default
Somehow pkg_delete_all() in pfSense upgrade is not getting any packages to iterate. The query looks OK and works when... Jim Pingle
01:34 PM Bug #8457: Packages do not remove on factory default
Just tried this on 2.4.3 Factory running on a SG-2440, using the hardware reset button the packages did not remove. Anonymous
02:14 PM Revision fecb8603: Suppress route command errors and related debug output. Fixes #8497
Jim Pingle
12:10 PM Bug #8504: Default gateway missing after upgrade
At least part of this is related to the new GWG as default code. The upgrade code failed to handle several potential ... Jim Pingle
08:55 AM Bug #8504 (Closed): Default gateway missing after upgrade
Make a fresh install of 2.4.3 via USB
Update to latest snapshot
Firewall has no default gateway and is non-functi...
Anonymous
11:06 AM Revision 066df2d5: PHP7 - Resolve illegal string offset warning
Steve Beaver
11:04 AM Revision bd83535d: PHP7 - Resolve illegal string offset warning
Steve Beaver
11:02 AM Revision a9912980: PHP7 - Resolve illegal string offset warning
Steve Beaver
09:20 AM Bug #8497 (Feedback): route errors ("route has not been found") on current 2.4.4 snapshots
Applied in changeset commit:fecb8603984d96f6d73e469c55573f7e0b45e55c. Jim Pingle
07:28 AM Bug #8503 (Not a Bug): DHCP Server replicating statically inserted IPs
It was an intentional change, see #8220
Jim Pingle
07:19 AM Bug #8503 (Not a Bug): DHCP Server replicating statically inserted IPs

Version 2.4.3-RELEASE (amd64)
built on Mon Mar 26 18:02:04 CDT 2018
FreeBSD 11.1-RELEASE-p7
I use the dchp ser...
Julio Cesar Pereira

05/09/2018

08:00 PM Revision 81852be2: Prevent pressing Enter in the filter field of diag_pftop.php. Fixes #8494
(cherry picked from commit e2654541019b59f544cda76fb0e63ea7a4a5d040) Jim Pingle
08:00 PM Revision 4ce3d0ac: Prevent pressing Enter in the filter field of diag_pftop.php. Fixes #8494
(cherry picked from commit e2654541019b59f544cda76fb0e63ea7a4a5d040) Jim Pingle
06:13 PM Revision 424375fb: Fix setHelp syntax for diag_pftop.php
(cherry picked from commit 581b6f4217d813741f435a0ef3be0e54288617de) Jim Pingle
06:13 PM Revision 581b6f42: Fix setHelp syntax for diag_pftop.php
Jim Pingle
01:01 PM Revision a0944bfe: PHP7 - Resolve illegal string offset warning
Steve Beaver
01:00 PM Revision a737700a: PHP7 - Resolve illegal string offset warning
Steve Beaver
11:52 AM Revision 35298a2f: PHP7 - Resolve foreach() warning
Steve Beaver
11:48 AM Revision 46631db4: PHP7 - Resolved count() warning
Steve Beaver
11:44 AM Revision 29aca990: PHP7 - Corrected illegal string offset warning
Steve Beaver
08:26 AM Bug #8502 (Confirmed): main (top) menu items do not drop down in some cases
During testing php7 found main (top) menu items do not drop down on final pages of some pkgs, e.g. arpping, mtr. Thes... Constantine Kormashev
07:22 AM Bug #8480 (Resolved): common/user name not expaned in openvpn.attributes.php (when doing per-user fw rules)
Jim Pingle

05/08/2018

07:35 PM Revision 27e329ce: Use array tests and operations that are more friedly to PHP 7.2 in gwlb.
Jim Pingle
04:44 PM Revision ab197c42: PHP7 - Rewrite uploader to use curlFile class
Steve Beaver
04:07 PM Revision 6f0f75c1: Welcome 2.4.3-RELEASE-p1
Renato Botelho
03:26 PM Revision 981d6364: Change CRL generation to a pure PHP implementation which works with PHP 7.2 (and 5.6)
The old OpenSSL CRL patch we had been using does not work with 7.2, and this way also
opens up some new possibilities...
Jim Pingle
01:25 PM Revision 592b9dfa: PHP7 - Resolve illegal null in escapeshellarg() error
Steve Beaver
12:22 PM Revision 1c306dae: PHP7 - Resolve Illegal string offset warning
Steve Beaver

05/07/2018

08:58 PM Bug #8450 (Resolved): High Availability Sync / xmlrpc.php removes "remote system username" on backup cluster member
Jim Pingle
08:33 PM Bug #8450: High Availability Sync / xmlrpc.php removes "remote system username" on backup cluster member
Tested on 2.4.4.a.20180507.0753, confirmed resolved. Paighton Bisconer
07:50 PM Revision bcb08ced: Also delete scheduler on cleanup
Matt Underscore
07:28 PM Revision 50d4c4f2: Setters and getters for $aqm/sched params (anticipating a review will request that)
Matt Underscore
07:10 PM Revision 15acacb4: Welcome 2.3.5-RELEASE-p2
Renato Botelho
05:59 PM Revision 09b824f8: Merge remote-tracking branch 'origin/RELENG_2_3' into RELENG_2_3_5
Renato Botelho
05:32 PM Revision edd8c491: Add copyright notice logic
Steve Beaver
05:03 PM Revision e45c569d: Merge remote-tracking branch 'origin/RELENG_2_3' into RELENG_2_3_5
Renato Botelho
03:17 PM Feature #6620: CoDel, FQ-CoDel, PIE and FQ-PIE AQMs
PR: https://github.com/pfsense/pfsense/pull/3941 Matt _
03:12 PM Revision c83123b0: Fixed different warnings and errors for PHP 7.2 Migration Illegal String Offsets and undefined constants
Stephen Jones
02:59 PM Revision 1de72f61: Fix command syntax in format_parameters
Matt Underscore
02:09 PM Revision 254581a5: CRLF
Matt Underscore
02:08 PM Revision 926cdf81: PHP7 - Resolve illegal string offset warning
Steve Beaver
02:08 PM Revision 8ac763a0: Fix newlines back
Matt Underscore
02:05 PM Revision dbf56eb4: - Fix an incorrect assumption where I thought the sysctls were measured in ms. they appear to be microseconds instead (thanks Harvy66)
- Fix a problem where I was recursively assigning parameters in FormatParameters(), but that was not an ideal method ... Matt Underscore
01:40 PM Revision 58630347: PHP7 - Resolve count() warning
Steve Beaver
01:20 PM Revision d43354d2: PHP7 - Resolve invalid arguemtn and illegal string offset warnings
Steve Beaver
01:15 PM Revision 965eee64: PHP7 - Resolve illegal string offset warning
Steve Beaver
01:13 PM Revision 5b943d25: PHP7 - Resolve count() warning
Steve Beaver
12:59 PM Bug #4479: Firewall rules won't match GRE interface after applying IPSEC transport encryption on GRE tunnel
Does pfSense patch freebsd kernel for some custom/not working on plain kernel? It will take some time until somebody ... Wagner Sartori Junior
12:58 PM Revision 1cf76cb0: PHP7 - Resolved "Cannot create references to/from string offsets"
Steve Beaver
12:55 PM Revision 07ada3f1: PHP7 - Resolve error "ese of undefined constant sn"
Steve Beaver
12:51 PM Revision aba7f367: Merge branch 'master' of gitlab.netgate.com:pfsense/pfsense
Steve Beaver
12:50 PM Bug #8273: IPv6 GRE tunnel over PPPoE fails on startup
As we're not having traction here, is there a way to manually trigger the GRE interface restart from the command line... Wagner Sartori Junior
09:31 AM pfSense Packages Bug #8501 (Resolved): Incorrect categorization of status/info messages from suricata
Hi, When suricata_check_for_rule_updates.php runs, it unnecessarily logs informational messages as errors - thus caus... Mark Hassman
09:30 AM Bug #8500 (New): Incorrect categorization of status/info messages from phpDynDNS
Hi, When phpDynDNS runs, it unnecessarily logs informational messages as errors - thus causing pfsense to forward mes... Mark Hassman
08:24 AM Bug #8499 (Resolved): IPv6 fragment logging causes panic in some circumstances
From customer ticket #4934.
The system crashes repeatedly with near identical back traces:...
Steve Wheeler
07:19 AM Bug #8355 (Not a Bug): Upgrades and packages unavailable after upgrade from 2.3.3_1 to 2.3.4_1
This message only appears if you have enabled a non-standard/third-party unofficial pkg repository, which is unsuppor... Jim Pingle
04:38 AM Revision d237e648: Change back to PHP7 compliance
Matt Underscore
04:20 AM Revision e9685c45: - Fixed a bug where you could not get an ECN-incapable scheduler or AQM to work: noecn was appended in rules.limiter.
- Made a change to an array reference that was breaking my test Matt Underscore

05/06/2018

08:54 PM Bug #8429: radvd/IPv6 broken in 2.4.3 when using a LAN bridge
I have the same issue with LAN bridged over 3 ethernet interfaces. The following error is logged every 16 seconds:
...
William Haworth
11:26 AM Bug #8497: route errors ("route has not been found") on current 2.4.4 snapshots
Two reboots since 10am, routes ok. James Snell

05/05/2018

08:42 PM Bug #8469 (Resolved): DHCP Server configuration page errantly expands Dynamic DNS advanced parameters even when none are configured
Jim Pingle
08:36 PM Bug #8469: DHCP Server configuration page errantly expands Dynamic DNS advanced parameters even when none are configured
Got it, the Dynamic DNS settings remained collapsed. Anonymous
08:27 PM Bug #8469: DHCP Server configuration page errantly expands Dynamic DNS advanced parameters even when none are configured
Hello James,
The issue is not whether or not the ddnsdomainkeyalgorithm element contains a value in the config; th...
Michael Alden
04:21 PM Bug #8469: DHCP Server configuration page errantly expands Dynamic DNS advanced parameters even when none are configured
Tested on 2.4.3.a.20180308.1837 - from stock pfSense, visited Services > DHCP Server and clicked Save at the bottom. ... Anonymous
07:51 PM Revision eace74f4: Wrote to wrong file.
Matt Underscore
07:43 PM Revision 5fefcdab: Revising my PR as it was not PHP7 compliant.
Matt Underscore
05:55 PM Todo #8394 (Resolved): status.php - Some package password fields are not redacted
Jim Pingle
04:01 PM Todo #8394: status.php - Some package password fields are not redacted
Tested in 2.4.4.a.20180504.1639 .. cannot reproduce, sensitive information is replaced with xxxxx Anonymous
05:19 PM Revision a60a9db9: Add dummynet AQM and scheduler configuration support to pfSense Limiters through the GUI. Only shaper.inc was changed.
Presently, the traffic shaper is versatile however outbound shaping can be tricky. This patch aims to solve that, al... Matt Underscore
03:57 PM Bug #8497: route errors ("route has not been found") on current 2.4.4 snapshots
FYI - I do have routing issues along with this error following a reboot (initial reboot from install was ok).
Rout...
James Snell
03:49 PM Bug #8457: Packages do not remove on factory default
On a SG-2440 .. pfSense-CE-memstick-ADI-2.4.3-RELEASE-amd64 installed, Branch set to Latest development snapshots and... Anonymous
02:50 PM Bug #8457: Packages do not remove on factory default
In a VM .. pfSense-CE-2.4.4-DEVELOPMENT-amd64-20180503-1839 installed, synced to master, setup wizard clicked through... Anonymous
10:32 AM Bug #8457: Packages do not remove on factory default
Adding notes: All packages are removed from the menu, but not removed from the system:
stunnel-5.44_1,1 ...
Chris Macmahon

05/04/2018

11:31 PM Bug #8498 (Not a Bug): cloudflare Dynamic DNS is not working
cloudflare Dynamic DNS is not working Mohammad Makkawi
06:52 PM Revision 5c4fcabc: Remove references for new classes instances adding a temporary variable. We will revisit it later
Renato Botelho
05:57 PM Revision 769ae881: PHP7 - Resolve illegal offset error
Steve Beaver
05:52 PM Revision 3987186c: PHP7 - Resolve illegal offset error
Steve Beaver
05:51 PM Revision ee6649b0: PHP7 - Resolve illegal offset error
Steve Beaver
05:50 PM Revision 1a5e85f6: PHP7 - Resolve illegal offset error
Steve Beaver
05:49 PM Revision 7272b169: PHP7 - Resolve illegal offset warnings
Steve Beaver
01:46 PM Revision 6ae5d9cb: Check for valid array before call foreach()
Renato Botelho
11:50 AM Revision 5d4cccc8: Add missing FSLABEL definition
Renato Botelho
11:23 AM Revision 70350cb1: Remove ISO from default build, memstick is hybrid
Renato Botelho
11:22 AM Revision bb3aa747: Use mkisoimages.sh to build memstick images after FreeBSD made ISO hybrid
Renato Botelho
11:15 AM Bug #8494 (Resolved): pressing Enter in pftop filter field redirects to another page
Jim Pingle
11:14 AM Bug #8494: pressing Enter in pftop filter field redirects to another page
The issue is not present on latest 2.4.4 snap (2.4.4.a.20180504.0747). Anonymous
11:14 AM Bug #8495 (Resolved): /etc/rc.reboot does not work on latest 2.4.4 snapshot
Jim Pingle
11:12 AM Bug #8495: /etc/rc.reboot does not work on latest 2.4.4 snapshot
Works successfully on latest 2.4.4 snap (2.4.4.a.20180504.0747). Anonymous
08:45 AM Bug #8497 (Resolved): route errors ("route has not been found") on current 2.4.4 snapshots
During boot, the console logs numerous identical errors:... Jim Pingle

05/03/2018

09:10 PM Revision caf4d712: Merge pull request #3781 from PiBa-NL/20170712-defaultgateway-group
Steve Beaver
09:05 PM Revision 65cde57f: Merge pull request #3918 from RepositPower/default-route-preference-in-radvd.conf
Steve Beaver
09:02 PM Revision 1761c8a2: Merge pull request #3927 from peterberbec/master
Steve Beaver
09:02 PM Revision 53a72784: Delete loader.conf.local
Peter Berbec
09:02 PM Revision f8227fe2: Delete IF_URNDIS.KO
Peter Berbec
09:02 PM Revision 267cf2d6: rename
Peter Berbec
09:02 PM Revision 7cb4c2ae: Create loader.conf.locat
Peter Berbec
09:02 PM Revision 7a3cdc11: ndis driver
Peter Berbec
09:02 PM Revision feae1ba4: Add array check
Even though I now set `$ns` equal to `array_unique(get_nameservers()`, just to be safe we check with `is_array($ns)` ... Peter Berbec
09:02 PM Revision 0637a69b: scope error?
Error on reboot.
```
[04-Apr-2018 02:21:54 EST5EDT] PHP Warning: in_array() expects parameter 2 to be array, null g...
Peter Berbec
09:02 PM Revision 2d0f86ba: Fixing debug errors.
Peter Berbec
09:02 PM Revision 43a1b4bd: hideCheckbox. The 'o' is important. And use js instead of php like we're supposed to.
Peter Berbec
09:02 PM Revision b458b3d3: Change array index to use php-style
Peter Berbec
09:02 PM Revision 1e238af4: Add fixed suggested by jim-p
Peter Berbec
09:02 PM Revision 0877fe87: Moved out of my root directory :(
Peter Berbec
09:02 PM Revision 80f95a62: Allow ocsp-staple to override
Enable ocsp stapling to on if forced that way through configuration Peter Berbec
09:02 PM Revision 4bdc654b: Change option text
Make it a force-on option
Hide option if ocsp is enabled
Peter Berbec
09:02 PM Revision 5067844c: Use cert_get_ocspstaple
Use cert_get_ocspstaple during nginx configuration generation Peter Berbec
09:02 PM Revision 0276ff2e: add cert_get_ocspstaple
Peter Berbec
09:02 PM Revision b7a4321c: Create get_dns_nameservers function
Put code in a function since it gets called in two places. Peter Berbec
09:02 PM Revision 8d76d71a: Steal resolvconf
Steal the nameserver generation code from the resolvconf code Peter Berbec
09:02 PM Revision d7a0bbbe: Improve description, reorder
make ordering proper Peter Berbec
09:02 PM Revision 63a0cb97: Use option properly
Use the option created by the config to control stapling
(and add a missed semicolon!)
Peter Berbec
09:02 PM Revision 895a7b90: Add OCSP option in config
Peter Berbec
09:02 PM Revision 2bf437ba: Beginings of enabling SSL Stapling
Add the option. Default to enable Peter Berbec
08:05 PM Feature #8496 (Duplicate): Allow user to backup multiple sections of their configuration
At Diagnostics > Backup & Restore, the user is able to select All or one specific section of the config to back up.
...
Anonymous
08:04 PM Revision a08b017c: Redact some more info from the status.php output. Fixes #8394
(cherry picked from commit 21fdf72c0b3caf960512373ad903fe03ccc578ff) Jim Pingle
08:04 PM Revision 34935fb8: Redact some more info from the status.php output. Fixes #8394
(cherry picked from commit 21fdf72c0b3caf960512373ad903fe03ccc578ff) Jim Pingle
07:57 PM Revision 21fdf72c: Redact some more info from the status.php output. Fixes #8394
Jim Pingle
07:19 PM Revision c1d8f66b: Remove 'now' from reboot command, it is no longer accepted or necessary. Fixes #8495
(cherry picked from commit 63642806eb11d2a1d8b203d85252f4afa15876ce) Jim Pingle
07:19 PM Revision 22b43392: Remove 'now' from reboot command, it is no longer accepted or necessary. Fixes #8495
Jim Pingle
06:32 PM Revision cdd30801: Bug #8469 - Modify show_advdns function pageload conditions to allow for ddnsdomainkeyalgorithm default value, i.e., hmac-md5
(cherry picked from commit 3e1b29c7ba3a586cb94268d76ecb78874c2f5007) Michael Alden
05:59 PM Revision 6fd98c6f: Enable build of drm-next-kmod
Renato Botelho
05:31 PM Revision 98dfd103: Backport table size increase for larger bogons. Ticket #8417
Jim Pingle
03:10 PM Todo #8394 (Feedback): status.php - Some package password fields are not redacted
Applied in changeset commit:21fdf72c0b3caf960512373ad903fe03ccc578ff. Jim Pingle
03:04 PM Revision c8febf6e: Revert "Do not assign classes with =& to make PHP 7 happy"
This reverts commit e33c96162a33b52a9152ce0b05dba8b25f1dc2b4. Renato Botelho
02:45 PM Revision 6fb33591: Enforce array type for PHP 7.2 Migration
Stephen Jones
02:39 PM Revision ab1387e6: Prevent pressing Enter in the filter field of diag_pftop.php. Fixes #8494
(cherry picked from commit e2654541019b59f544cda76fb0e63ea7a4a5d040) Jim Pingle
02:39 PM Revision e2654541: Prevent pressing Enter in the filter field of diag_pftop.php. Fixes #8494
Jim Pingle
02:30 PM Bug #8495 (Feedback): /etc/rc.reboot does not work on latest 2.4.4 snapshot
Applied in changeset commit:22b43392c24ef1c8fd165a5fa6b30098d127c010. Jim Pingle
02:17 PM Bug #8495 (Resolved): /etc/rc.reboot does not work on latest 2.4.4 snapshot
/etc/rc.reboot calls "/sbin/reboot now" and apparently that has been disabled in 11.2-PRE, see https://github.com/fre... Jim Pingle
01:33 PM Bug #8439 (Not a Bug): Trailing whitespace on username not respected in LDAP filter
After talking with others this is all up to the target server. AD respects the space, for example, while OpenLDAP doe... Jim Pingle
01:32 PM Bug #8469 (Feedback): DHCP Server configuration page errantly expands Dynamic DNS advanced parameters even when none are configured
Jim Pingle
10:05 AM Bug #8493: Assigned OpenVPN interface does not send traffic via right route until reboot
Got it, no more questoins Constantine Kormashev
09:57 AM Bug #8493: Assigned OpenVPN interface does not send traffic via right route until reboot
It's noted in "book section on assignment":https://portal.pfsense.org/docs/book/openvpn/assigning-openvpn-interfaces.... Jim Pingle
09:55 AM Bug #8493: Assigned OpenVPN interface does not send traffic via right route until reboot
Did not know about OpenVPN restart. Perhaps we need some hook for autorestart or warning there, because this is not o... Constantine Kormashev
09:47 AM Bug #8493 (Not a Bug): Assigned OpenVPN interface does not send traffic via right route until reboot
After assignment, you must restart the VPN manually so OpenVPN can reapply the interface setttings which are stripped... Jim Pingle
03:25 AM Bug #8493 (Not a Bug): Assigned OpenVPN interface does not send traffic via right route until reboot
In case of using several OpenVPN instances, e.g. Client (has its own default route) and Server on pfsense, assigned O... Constantine Kormashev
09:50 AM Bug #8494 (Feedback): pressing Enter in pftop filter field redirects to another page
Applied in changeset commit:e2654541019b59f544cda76fb0e63ea7a4a5d040. Jim Pingle
09:35 AM Bug #8494 (Confirmed): pressing Enter in pftop filter field redirects to another page
Jim Pingle
04:40 AM Bug #8494 (Resolved): pressing Enter in pftop filter field redirects to another page
If I press Enter in pftop filter field system redirects me to another page instead showing result in Output frame.
...
Constantine Kormashev

05/02/2018

08:51 PM Revision 714c15d7: Cleaner fix for ##8447
(cherry picked from commit 96fa3e3616c1b46cbd23593df8c08cceb23a61e6) Steve Beaver
08:51 PM Revision e3dfbd9c: Fixed #8447
(cherry picked from commit 1d523d1e4e7b16519ed3fd9dfb9e6b4dd84b4285) Steve Beaver
07:52 PM Revision d62d089d: Since OpenVPN user attributes come from RADIUS which keys off username, use that and not common_name which may be empty. Fixes #8480
(cherry picked from commit a2e92e18a35112ec59d18d3555f89668d9e07a11) Jim Pingle
07:52 PM Revision 8228ea91: fix #8441;
ipfw rules must be deleted before cp record delete.
(cherry picked from commit 29a272f7361689c87dd7ad9fc1c903e843a1c...
Selman ULUG
07:51 PM Revision 8d06b6c2: Reword bogon block size error text. Ticket #8417
(cherry picked from commit 6ad146e0445961ccba5323cccadcdfddc98e7d55) Jim Pingle
07:51 PM Revision b4bb2544: Correct text for reserved alias name checks against protocols and services. Fixes #8409
(cherry picked from commit a2405c1a8c366e1ad2ececd4f62c577eed31ab7c) Jim Pingle
07:51 PM Revision 39ee89ab: Correct pconfig_to_address() so its logic matches the input validation used for checking port numbers. Fixes #8410
(cherry picked from commit 885e9b2a1df256f4d50367f96b4d39c1106b2448) Jim Pingle
07:51 PM Revision a8ad9098: Cleaner fix for ##8447
(cherry picked from commit 96fa3e3616c1b46cbd23593df8c08cceb23a61e6) Steve Beaver
07:51 PM Revision ca0ca1c5: Fixed #8447
(cherry picked from commit 1d523d1e4e7b16519ed3fd9dfb9e6b4dd84b4285) Steve Beaver
07:51 PM Revision ef799458: Replace incomplete list of pf reserved words with a list of pf tokens pulled from the pf source. Fixes #8445
Also, move the list to a central location so it does not need to be duplicated.
(cherry picked from commit b20cfb551...
Jim Pingle
07:51 PM Revision 1ed92658: fixed code style
(cherry picked from commit a7e859b80d55abfbdcae1918065aaf59baba4900) Benjamin Schweizer
07:51 PM Revision 2d6255e1: avoid firwall rules for proxyarp addresses
(cherry picked from commit 7c0e431a878d63fdb0440dbd2c1fad1e7d379f8c) Benjamin Schweizer
04:48 PM Revision 6dde4c10: Type check for array, Part of php 7.2 migration
Stephen Jones
04:12 PM Revision e3df164a: Added a check to make sure ['ipsec'] was an array, Part of PHP 7.2 Migration
Stephen Jones
03:42 PM Revision d3cc158c: Only alter users/groups via XMLRPC when the primary is set to do so. Fixes #8450
Jim Pingle
03:42 PM Revision ff13ca0d: Only alter users/groups via XMLRPC when the primary is set to do so. Fixes #8450
(cherry picked from commit be4693a1e79d89cfc6ea797fcb7fb56b5052c26d) Jim Pingle
03:41 PM Revision bb24d66e: PHP7 Resolve count() parameter warning
Steve Beaver
12:55 PM Feature #8430 (Resolved): Add DNS Resolver status page
What's there now is enough for this purpose. I haven't yet been able to come up with a good way to represent the data... Jim Pingle
10:50 AM Bug #8450 (Feedback): High Availability Sync / xmlrpc.php removes "remote system username" on backup cluster member
Applied in changeset commit:ff13ca0dfe2e016cb21141f0dbd7cdad44e55a46. Jim Pingle
07:57 AM pfSense Packages Feature #8490: pfSense-pkg-acme: acme_certificates_edit.php - Add ability to specify (vs generate) private key
PR Link: https://github.com/pfsense/FreeBSD-ports/pull/518 Jim Pingle
07:43 AM pfSense Packages Feature #8299 (Resolved): acme: ocsp must-staple
This is in the package and working OK now Jim Pingle

05/01/2018

09:06 PM Revision a2e92e18: Since OpenVPN user attributes come from RADIUS which keys off username, use that and not common_name which may be empty. Fixes #8480
Jim Pingle
06:22 PM Revision f1552738: PHP7 - Resolev undefined constant warning
Steve Beaver
05:47 PM Revision 72f363ed: Fixed #8486 via htmlspecialchars()
(cherry picked from commit 687e50fd439179ba61a518c7b68c91b168e56e50) Steve Beaver
05:47 PM Revision 8d7458f6: Fixed #8485 by POSTing fixed string and looking up the required file name
(cherry picked from commit c29a1fe90f89c1ae392df2ef2092207e282ddc37) Steve Beaver
05:46 PM Revision 5c856a1d: Fixed #8486 via htmlspecialchars()
(cherry picked from commit 687e50fd439179ba61a518c7b68c91b168e56e50) Steve Beaver
05:46 PM Revision 9d918214: Fixed #8485 by POSTing fixed string and looking up the required file name
(cherry picked from commit c29a1fe90f89c1ae392df2ef2092207e282ddc37) Steve Beaver
05:46 PM Revision b662c5e4: Fixed #8486 via htmlspecialchars()
(cherry picked from commit 687e50fd439179ba61a518c7b68c91b168e56e50) Steve Beaver
05:46 PM Revision 48f8b5ad: Fixed #8485 by POSTing fixed string and looking up the required file name
(cherry picked from commit c29a1fe90f89c1ae392df2ef2092207e282ddc37) Steve Beaver
04:20 PM Bug #8480 (Feedback): common/user name not expaned in openvpn.attributes.php (when doing per-user fw rules)
Applied in changeset commit:a2e92e18a35112ec59d18d3555f89668d9e07a11. Jim Pingle
11:37 AM Bug #8492 (Duplicate): Enable setting PKCS#12 export password in Certificate Manager
Several use cases exist for using an exported keypair as a .p12 archive, but are complicated by pfSense not setting a... Darren Spruell
08:04 AM pfSense Packages Bug #8491 (Resolved): ACME: DNS-Luadns not working
Hello,
I'm using acme 0.2.8_2 with LuaDNS. If I want to obtain a certificate with the DNS-Luadns method, I should ...
Anonymous

04/30/2018

08:14 PM pfSense Packages Feature #8490: pfSense-pkg-acme: acme_certificates_edit.php - Add ability to specify (vs generate) private key
Scott Smith wrote:
> * Like other user-entered data, the user-entered _Private Key_ text would be stored in the co...
Michael M
01:36 PM Revision aa6184b6: Enable support for php72 variant
Renato Botelho
01:36 PM Revision b395c4f2: Add a global to keep valid meta package suffixes
Renato Botelho
11:28 AM Revision 88a8b4da: Sort
Renato Botelho
05:27 AM Bug #6880: Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
Luke Hamburg wrote:
> Thanks. I first checked out master and didn't find that commit... then drank some coffee & re...
Daniel Helgenberger
03:39 AM Bug #6223: IPsec + OpenBGPD fails with "PF_KEY socket: No buffer space available"
Just finish to migrate to FRRouting
IPV4 OK but IPV6 bad dream... fortunately there is a great thing called vtysh ...
xavier Lemaire
 

Also available in: Atom