Project

General

Profile

Activity

From 10/03/2018 to 11/01/2018

11/01/2018

11:51 PM Bug #9087 (New): Traffic Graph Widget Legend Not Updating
This issue was first posted to the Netgate Forums, but no solution was posted.
The traffic graph widget shows a le...
Brent Clothier
08:45 PM Revision 307ee672: Fix 9086: Remove gettext() from all 'Local Databases' strings
Renato Botelho
08:45 PM Revision 296c16bd: Fix 9086: Remove gettext() from all 'Local Databases' strings
Renato Botelho
08:42 PM Revision a7b0d338: Update translation files
Renato Botelho
08:42 PM Revision 58bf585e: Regenerate pot
Renato Botelho
08:41 PM Revision d5b70264: Update translation files
Renato Botelho
08:41 PM Revision 840494c0: Regenerate pot
Renato Botelho
04:05 PM Bug #8954 (Feedback): hn0: driver does not support altq
I pushed a fix on FreeBSD-src. Please try next round of 2.4.5 snapshots Renato Botelho
03:06 PM Bug #8954: hn0: driver does not support altq
I've created a new "System Tunable" with : hw.hn.use_if_start with value of 1 Then rebooted the VM.
Output of s...
Ben T
12:01 PM Bug #8954: hn0: driver does not support altq
Ben T wrote:
> On psense 2.4.4 running as vm gen2 on windows 10 build 1803 Hyper-V, the output of the command: (scre...
Renato Botelho
10:51 AM Bug #8954: hn0: driver does not support altq
On psense 2.4.4 running as vm gen2 on windows 10 build 1803 Hyper-V, the output of the command: (screenshot also atta... Ben T
09:45 AM Bug #8954 (In Progress): hn0: driver does not support altq
Renato Botelho
09:21 AM Bug #8954: hn0: driver does not support altq
Jon Gav wrote:
> > hyper-v 2016
> > gen1 and gen2
>
> Issue persistent in 2.4.5.development as well
can you p...
Renato Botelho
03:45 PM Bug #9086 (Resolved): Local Database authentication is failing in other languages
A user reported this problem on a pt_BR group. After changing language it stopped working. I noted it is storing tran... Renato Botelho
08:44 AM Bug #9064: voucher to device binding
Jim Pingle wrote:
> If you add a pass-through MAC, the time on the voucher is irrelevant. Don't set it that long.
...
ishtiaq ahmad
08:35 AM Bug #9064: voucher to device binding
If you add a pass-through MAC, the time on the voucher is irrelevant. Don't set it that long. Jim Pingle
08:06 AM Bug #9064: voucher to device binding
Jim Pingle wrote:
> If the voucher adds a pass-thru MAC, then you could also make the voucher only last 1 minute. Sm...
ishtiaq ahmad
08:03 AM Bug #9064: voucher to device binding
A FL wrote:
> This is actually not a bug.
>
> If the MAC address of the previous computer has been added as pass-...
ishtiaq ahmad
07:06 AM Bug #9064: voucher to device binding
If the voucher adds a pass-thru MAC, then you could also make the voucher only last 1 minute. Smaller window for abus... Jim Pingle
05:08 AM Bug #9064: voucher to device binding
This is actually not a bug.
If the MAC address of the previous computer has been added as pass-through, "Disable c...
A FL
08:07 AM pfSense Packages Todo #9041: update ntopng 3.6.0
json-c upgrade was not necessary since we don't have plans to import a new quarterly to 2.4.4 branch. Renato Botelho
08:07 AM pfSense Packages Todo #9041 (Feedback): update ntopng 3.6.0
Renato Botelho
07:36 AM Todo #8898 (Feedback): Update strongswan to 5.7.1
Both 5.7.0 and 5.7.1 commits were cherry-picked to 2.4.4 branch Renato Botelho
07:09 AM Bug #9058: Kernel panic during L2TP retransmit
yes it's always the same (except the hex addresses)... Bianco Veigel
07:07 AM Bug #9058 (New): Kernel panic during L2TP retransmit
OK, and is the backtrace in the crash report always the same?
I have not seen a recurrence of this on my local set...
Jim Pingle
04:18 AM Bug #9058: Kernel panic during L2TP retransmit
Thanks for waiting. My pfsense crashed two times in the last two days. From the monitoring (telegraf, 300s interval) ... Bianco Veigel
05:17 AM Revision 125ae17e: Update src/usr/local/www/vendor/d3/d3.min.js
make sure to only pass valid options when supported by the browser Marco Pannetto
04:33 AM Revision 36742b46: Removed js warnings
Marco Pannetto

10/31/2018

09:13 PM pfSense Packages Feature #9085 (New): OpenVPN connect/disconnect scripts
I'm running pfSense 2.4.4 and the Windows openVPN 2.4.6 client.
I was trying to get the openVPN server to log *use...
Phil Biggs
05:07 PM Revision e65a15e4: Add help text to sshguard whitelist
Reduce delete button size
Change label text to "Add address"
(cherry picked from commit 5514e368421171482e3e5b945f4c...
Steve Beaver
04:59 PM Revision 1f7ea9ce: Skip empty IPsec P1 during upgrade to 17.5. Fixes #9083
(cherry picked from commit 024e5de242661219bb8a62f183b1601cec44aa3c) Jim Pingle
04:59 PM Revision 024e5de2: Skip empty IPsec P1 during upgrade to 17.5. Fixes #9083
Jim Pingle
02:34 PM Revision 5514e368: Add help text to sshguard whitelist
Reduce delete button size
Change label text to "Add address"
Steve Beaver
12:19 PM Revision 087a1f6b: Fix #8864: Let users modify sshguard parameters and whitelist
Renato Botelho
12:19 PM Revision ef4a242c: Fix #8864: Let users modify sshguard parameters and whitelist
Renato Botelho
12:10 PM Bug #9083 (Feedback): Config upgrade issue with empty IPsec P1
Applied in changeset commit:024e5de242661219bb8a62f183b1601cec44aa3c. Jim Pingle
09:02 AM Bug #9083 (Resolved): Config upgrade issue with empty IPsec P1
An older configuration will fail to upgrade with an incomplete or empty IPsec Phase 1 section:... Jim Pingle
11:27 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
The Gateway Group was set as Trigger Level: Packet Loss or High Latency. I changed that to "Member Down" and now the... Mitch Claborn
11:09 AM Bug #9084 (Duplicate): PHP crash after deleting NAT 1:1 rule
Duplicate of #9080 which is already fixed in the repo. Jim Pingle
10:45 AM Bug #9084 (Duplicate): PHP crash after deleting NAT 1:1 rule
There was only one rule on the NAT 1:1 list. After deleting it the the crash occurred. This happened several times an... Guilherme Orcutt
07:25 AM Bug #8864 (Feedback): SSH Guard Sensitivity/Whitelist on 2.4.4
Applied in changeset commit:ef4a242c0df1b69b3348997165afc8555471202c. Renato Botelho

10/30/2018

10:15 PM pfSense Packages Bug #9082 (Resolved): freeradius eap-tls CA validation trying to use fields that may not exist
This issue is reproduced in this thread: https://forum.netgate.com/topic/137168/freeradius-ca-validation-broken-2-4-5... rub man
02:24 PM Revision f989b4f6: Array initialization in NAT pages. Fixes #9080
(cherry picked from commit 42ad3b8b51e12b9e4c89b94e2a191495318f42dc) Jim Pingle
02:24 PM Revision 42ad3b8b: Array initialization in NAT pages. Fixes #9080
Jim Pingle
02:18 PM Revision f5c56bf8: Fix issue where Alias URL lists are not correctly stored
Paul.Bramhall
10:16 AM Bug #9081: signed long rollover in "Log file size (Bytes)" can cause self-inflicted DoS
That certainly sounds fun. I'll have a look. Jim Pingle
10:14 AM Bug #9081 (Closed): signed long rollover in "Log file size (Bytes)" can cause self-inflicted DoS
Values between 2147483648 and 4294967295 and cause fire-y disk-full death at the hands of @clog -i -s@ Izaac Falken
09:30 AM Bug #9080 (Feedback): firewall_nat_1to1.php: PHP error with empty 1:1 NAT rule list
Applied in changeset commit:42ad3b8b51e12b9e4c89b94e2a191495318f42dc. Jim Pingle
09:02 AM Bug #9080 (In Progress): firewall_nat_1to1.php: PHP error with empty 1:1 NAT rule list
Jim Pingle
09:02 AM Bug #9080 (Closed): firewall_nat_1to1.php: PHP error with empty 1:1 NAT rule list
... Jim Pingle
09:23 AM pfSense Packages Bug #9079: High CPU usage of ntopng even during IDLE and no network traffic
It's not clear there is anything we can do at all here. This is most likely an issue in ntopng itself, not something ... Jim Pingle
09:22 AM pfSense Packages Bug #9079: High CPU usage of ntopng even during IDLE and no network traffic
TOP shows that the ntopng process is in the only one in nanslp (nanosleep) mode if this helps. Hannes W.
08:58 AM pfSense Packages Bug #9079 (Closed): High CPU usage of ntopng even during IDLE and no network traffic
With pfSense version 2.4.4 and the usage of ntopng package the CPU is constantly on a high load.
Reducing ntopng tas...
Hannes W.
09:21 AM Bug #9074: Alias URL lists only storing last-most list in config.
Submitted pull request:
https://github.com/pfsense/pfsense/pull/4002
Paul Bramhall
07:52 AM Bug #9059 (In Progress): Update Unbound to 1.8.1
Cherry picked a270651cc45b428b5f8167d1d533c50e5ee958c2 to devel. If it's OK on 2.4.5 we can consider picking it back ... Jim Pingle

10/29/2018

02:13 PM Feature #9078 (Resolved): Investigate adding knobs for explicit-exit-notify in OpenVPN
explicit-exit-notify looks like it can greatly speed up recovery time on OpenVPN process restarts and potentially HA ... Chris Linstruth
12:18 PM Revision c6b4e293: Revert "Build textproc/jq, asked by BBcan177"
This reverts commit 2e618c0d285a242b8cc8004f0907ddbb227ecfe9. Renato Botelho
09:13 AM Feature #9032: RADIUS MAC Authentication: display the login page when MAC auth failed
The fall back seems not to respect the setting *Use custom captive portal page* as it always shows the default login ... Jane Doe
07:59 AM Bug #9074: Alias URL lists only storing last-most list in config.
There still appeared to be some odd behaviour with the change I did above where it was not always appending the array... Paul Bramhall
06:29 AM Bug #9075 (Not a Bug): Firewall rules with aliases are not applied in upgraded 2.4.4
There is not enough detail here to reproduce or identify a problem. Aliases are working fine in lab and production se... Jim Pingle
04:06 AM Bug #9075 (Not a Bug): Firewall rules with aliases are not applied in upgraded 2.4.4
HI,
I have an upgraded pfsense from 2.4.3 to 2.4.4 and then all the firewall rules with aliases are not applied co...
Julio VIzcaino
06:25 AM Bug #9076 (Not a Bug): DHCP RENEW PROBLEM
This needs discussion on the forum. It's working fine for thousands and thousands of installs. If there is an issue h... Jim Pingle
04:44 AM Bug #9076 (Not a Bug): DHCP RENEW PROBLEM
Hello,
Since two weeks we have a problem on our DHCP Server with dhcp adress renew on our clients.
All 24 hours, ...
Aurelien Dufeu
06:06 AM pfSense Packages Feature #9077 (New): haproxy UI: Add seperator lines
When having lots of ACL rules and action rules it would be nice if it was possible to insert seperator lines with a n... Torben Hørup

10/28/2018

09:18 PM Bug #9056 (Resolved): DNS search domain omitted in some cases
Jim Pingle
08:43 PM Bug #9056: DNS search domain omitted in some cases
Looks good here. Thanks. Chris Linstruth
09:18 PM Bug #9055 (Resolved): IKEv2 EAP Identity vs client ID matching for per-client settings with local users
Jim Pingle
08:48 PM Bug #9055: IKEv2 EAP Identity vs client ID matching for per-client settings with local users
Works as expected. Thank you. Chris Linstruth
07:45 AM Bug #9074 (Resolved): Alias URL lists only storing last-most list in config.
When creating an Alias URL list under Firewall->Aliases->URLs, only the IP's from the last-most URL in the list is wh... Paul Bramhall

10/27/2018

01:35 PM Bug #9073: "private-domain" in custom options results in invalid config (syntax error)
Thanks, Jim! It didn't occur to me that the @server@ block could be specified twice. Can confirm the config now che... Rick White
01:21 PM Bug #9073 (Not a Bug): "private-domain" in custom options results in invalid config (syntax error)
With custom options it is up to the user to ensure the config is in the correct section of the config. For example in... Jim Pingle
01:21 PM Bug #9073: "private-domain" in custom options results in invalid config (syntax error)
Ahah, I think the actual issue is that *Custom options* are being after the @forward-zone@ directive, which means the... Rick White
01:16 PM Bug #9073 (Not a Bug): "private-domain" in custom options results in invalid config (syntax error)
Adding the following to the DNS Resolver *Custom options* field:... Rick White
08:18 AM Bug #9058 (Feedback): Kernel panic during L2TP retransmit
OK, we'll wait for some more feedback here to see what happens. Jim Pingle
05:46 AM Bug #9058: Kernel panic during L2TP retransmit
After a few more crashes with different error messages, I ran a memory test, which showed errors. RAM is replaced and... Bianco Veigel

10/26/2018

11:51 AM Bug #8937 (New): LAGG shows wrong ether address
From a quick look at utils.inc:get_interface_list() this would require the addition of some logic;
if $IFACE is me...
Anonymous
09:37 AM Bug #8937 (In Progress): LAGG shows wrong ether address
Anonymous
10:42 AM Bug #9072 (Resolved): RRD graph mouseover information shows up as Mb when unit size is set to MB
The dashboard traffic graph widget shows mouse over information in Mb when the unit size is set to MB Luka Rojnica
09:36 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
To make things even more complicated, in the workaround mentioned above, the routing actually changes back to the Tie... Mitch Claborn
09:11 AM Bug #9071 (Resolved): Package restore after fresh install can fail, claiming packages do not exist
Tested on a fresh SG-1000 and SG-3100 after a recovery install and then config restore. In both cases, no packages we... Jim Pingle
05:27 AM Bug #8954: hn0: driver does not support altq
> hyper-v 2016
> gen1 and gen2
Issue persistent in 2.4.5.development as well
Jon Gav

10/25/2018

07:40 PM Revision b77f0bf1: Initialize package arrays before use. Fixes #9067
(cherry picked from commit bfd3334b4bc9ae0d3c43f69e8305c83b0da3aa58) Jim Pingle
07:40 PM Revision bfd3334b: Initialize package arrays before use. Fixes #9067
Jim Pingle
07:00 PM Bug #9070 (Feedback): After performing in-place upgrade from 2.4.3-RELEASE-p1 to 2.4.4 DHCPV6 client fails to retireve a WAN address
Sounds like symptoms that others saw when using Hyper-V.
If you are using Hyper-V then this is a duplicate of #9019
Jim Pingle
06:15 PM Bug #9070 (Closed): After performing in-place upgrade from 2.4.3-RELEASE-p1 to 2.4.4 DHCPV6 client fails to retireve a WAN address
I upgraded my system a few days ago and realized last night that the hosts were no longer receiving IPV6 addresses. ... Tom Hebert
06:58 PM Bug #9069 (Duplicate): Config import not validated properly
Duplicate of #8994 which is already fixed for 2.4.4-p1. Jim Pingle
05:56 PM Bug #9069 (Duplicate): Config import not validated properly
I just imported a config file generated on another pfsense host onto a fresh install. Somehow that file ended up cont... Flole Systems
06:24 PM Revision 0fd2dd09: Add trailing slash to ECL check path for /config/. Fixes #9066
(cherry picked from commit c688c59b47a3ce138ffe094794d01f1e6fcc00df) Jim Pingle
06:24 PM Revision c688c59b: Add trailing slash to ECL check path for /config/. Fixes #9066
Jim Pingle
04:18 PM Bug #9068 (Rejected): Exported configuration contains string at the end that should not be there
I can't reproduce this here at all on 2.4.4 or 2.4.5 snapshots.
It may be specific to the combination of OS+Browse...
Jim Pingle
04:13 PM Bug #9068 (Rejected): Exported configuration contains string at the end that should not be there
When I export a configuration, everything is normal until the last line, which reads... Flole Systems
02:50 PM Bug #9067 (Feedback): PHP error when installing first package with empty installedpackages tag
Applied in changeset commit:bfd3334b4bc9ae0d3c43f69e8305c83b0da3aa58. Jim Pingle
02:40 PM Bug #9067 (Resolved): PHP error when installing first package with empty installedpackages tag
If the configuration contains only @<installedpackages></installedpackages>@ then installing a package will fail with... Jim Pingle
01:30 PM Bug #9066 (Feedback): ecl.php: Checking /config path is not working due to lack of trailing slash
Applied in changeset commit:c688c59b47a3ce138ffe094794d01f1e6fcc00df. Jim Pingle
01:19 PM Bug #9066 (Resolved): ecl.php: Checking /config path is not working due to lack of trailing slash
At source:src/etc/ecl.php#L59 the locations for the external config locator (ECL) script are defined, but @/config@ d... Jim Pingle
06:47 AM Bug #9065 (Rejected): Well known ports: order them by number instead of name
The problem with this change is that people don't who do not know the numbers will want to find them by name, and wit... Jim Pingle
05:21 AM Bug #9065 (Rejected): Well known ports: order them by number instead of name
As a sysadmin, I always know the port I'm handling, but a lot of times I don't remember the +exact+ name of the servi... Filippo Tessarotto

10/24/2018

01:09 PM Bug #9064: voucher to device binding
! ishtiaq ahmad
01:08 PM Bug #9064 (Not a Bug): voucher to device binding
dear all,
in version 2.4.4 we cant enforce one voucher per same device always. some naughty user switch from one to ...
ishtiaq ahmad
11:53 AM Feature #9063 (New): Allow dynamic DNS client entry to specify which Check IP service to use
Please update the dynamic DNS client feature to allow specification of the Check IP service to use at the individual ... Mitch Claborn
01:31 AM Bug #8758: filterdns stops working on a regular basis.
Dear All
i am affected with same problem
it happens every day approx.
i must kill filterdns service and restart ...
khaled osama

10/23/2018

06:19 PM Revision 20895301: Fix processing of the 'all' group. Fixes #9051
All the 'all' group to the list of groups at the end, rather than the
start. This way it will be considered no matter...
Jim Pingle
06:17 PM Revision 4de15854: Fix processing of the 'all' group. Fixes #9051
All the 'all' group to the list of groups at the end, rather than the
start. This way it will be considered no matter...
Jim Pingle
05:14 PM Revision c95a79d3: Validate and protect powerd option values. Fixes #9061
(cherry picked from commit 3be699295e5cb7be24cc5361700be1a8b759e26c) Jim Pingle
05:13 PM Revision 3be69929: Validate and protect powerd option values. Fixes #9061
Jim Pingle
01:25 PM Bug #9051 (Feedback): Privileges on 'all' group are not being honored
Applied in changeset commit:4de15854384e28004b0dc571dc8a40fda7eae694. Jim Pingle
01:07 PM Feature #9062 (Rejected): Add "email notification" when the WAN interface change its public IP
It would be helpful if an email is send when the WAN interface change its public IP.
Here is an example: https://www...
TCI User
12:20 PM Bug #9061 (Feedback): PowerD command parameter validation and escaping
Applied in changeset commit:3be699295e5cb7be24cc5361700be1a8b759e26c. Jim Pingle
11:46 AM Bug #9061 (Resolved): PowerD command parameter validation and escaping
The powerd parameters @powerd_ac_mode@, @powerd_battery_mode@, and @powerd_normal_mode@ are not validated against the... Jim Pingle
08:39 AM Feature #9060 (New): add rule name filtering field for firewall log viewer
It would be very helpful to have a field available in the firewall log filter to search on matched rule name (i.e. Ev... Ansley Barnes
08:30 AM Bug #9059 (Resolved): Update Unbound to 1.8.1
Unbound 1.8.1 has fixed a few memory leaks, notably one in DNS over TLS that causes unbound to consume all memory and... Jim Pingle
08:21 AM Bug #9058: Kernel panic during L2TP retransmit
Right now it happens at least once a day, but at random times. I'll check if the amount of traffic might be related. Bianco Veigel
08:09 AM Bug #9058: Kernel panic during L2TP retransmit
I saw a crash with a backtrace like that once on a test VM with an L2TP WAN but only one time, not repeatedly, so I c... Jim Pingle
06:41 AM Bug #9058 (Resolved): Kernel panic during L2TP retransmit
I'm using a Multilink L2TP WAN. After a fresh reinstall of 2.4.4 and completely new config (no import) it crashes reg... Bianco Veigel
01:06 AM Bug #8937: LAGG shows wrong ether address
Create a new LAGG with some interfaces and save it. Once thats done, edit that LAGG and on everything interface name ... Flole Systems

10/22/2018

11:48 PM Bug #9051: Privileges on 'all' group are not being honored
removed the 'all' from both files and got access again, also admin is disabled using different user as admin Michael Kellogg
10:51 PM Bug #9051: Privileges on 'all' group are not being honored
I just upgraded and got no page assigned
Michael Kellogg
07:32 PM Revision 7a16a38c: Use the fw domain for DNS search when no other choices exist. Fixes #9056
(cherry picked from commit 74a8a219d33c9b87ab4b6b4026d247f0f6bdcaa6) Jim Pingle
07:31 PM Revision 74a8a219: Use the fw domain for DNS search when no other choices exist. Fixes #9056
Jim Pingle
06:36 PM pfSense Docs Correction #9057 (Resolved): [feedback form] Missing info on advanced networking page
*Page*: https://docs.netgate.com/pfsense/en/latest/config/advanced-networking.html
*Feedback*: Missing info on the...
Jared Dillard
05:35 PM Revision aa733351: gateway monitoring, wait for apinger to terminate or remove its pid file when restarting it.
(cherry picked from commit 66491555711182d9176f6292fd58397c65e4b2af) PiBa-NL
05:35 PM Revision 8e823a93: generate a flag even if trying to perform RADIUS MAC authentication on a non-RADIUS server.
(cherry picked from commit 22e328743170b62b55d6e18b593c4005e8d6f892) A FL
05:35 PM Revision bb90e3c5: Implement login fallback for RADIUS MAC authentication
(cherry picked from commit 774ff51ba07f944a39fdc6859ec7d258b95315bf) A FL
05:29 PM Revision b950e991: Strictly define the EAP Identifier for custom local client entries. Fixes #9055
(cherry picked from commit 2d7ed31e3227566d0474929a3aed84509247f91e) Jim Pingle
05:28 PM Revision 2d7ed31e: Strictly define the EAP Identifier for custom local client entries. Fixes #9055
Jim Pingle
03:28 PM Revision 8be7aff9: Merge pull request #3987 from PiBa-NL/20180920-apinger-wait-for-terminate
Steve Beaver
03:22 PM Revision 768eccf9: Merge pull request #4000 from Augustin-FL/patch-cp-3
Steve Beaver
02:40 PM Bug #9056 (Feedback): DNS search domain omitted in some cases
Applied in changeset commit:74a8a219d33c9b87ab4b6b4026d247f0f6bdcaa6. Jim Pingle
02:31 PM Bug #9056 (Resolved): DNS search domain omitted in some cases
If a user has allowed DHCP override of DNS servers but there are no DCHP WANs, the search domain list will be empty.
...
Jim Pingle
12:44 PM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
If I set the Tier 1 gateway as "Mark Gateway as Down" then turn that setting back off, the routing will correct itsel... Mitch Claborn
10:58 AM Bug #9054 (Resolved): Gateway Group slow (or never) to switch back to Tier 1
See https://forum.netgate.com/topic/136852/2-4-4-gateway-group-slow-or-never-to-switch-back-to-tier-1. (No responses... Mitch Claborn
12:35 PM Bug #9055 (Feedback): IKEv2 EAP Identity vs client ID matching for per-client settings with local users
Applied in changeset commit:2d7ed31e3227566d0474929a3aed84509247f91e. Jim Pingle
12:32 PM Bug #9055: IKEv2 EAP Identity vs client ID matching for per-client settings with local users
If we determine that there is a use case for allowing the other method, we can setup GUI controls for it later as a s... Jim Pingle
12:28 PM Bug #9055 (Resolved): IKEv2 EAP Identity vs client ID matching for per-client settings with local users
With IKEv2, the EAP Identity does not necessarily match the @rightid@ supplied by the client. For most common use cas... Jim Pingle
10:36 AM Bug #8964: IPsec async cryptography advanced setting - TCP traffic not passing through
I'm seeing this bug occur on my SG-3100s when using one of the AES-GCM based algorithms for my IPSEC Phase2 with asyn... Paul Bucher
10:29 AM Bug #8921: dpinger without .pid files.?. 'pending' status
PR tested and applied. Thanks. Anonymous
10:28 AM Bug #8921 (Feedback): dpinger without .pid files.?. 'pending' status
Anonymous
10:26 AM Bug #8937 (Feedback): LAGG shows wrong ether address
Please provide some more details of this issue. It is not clear from the description what the problem is. Where do yo... Anonymous
10:23 AM Feature #9032 (Feedback): RADIUS MAC Authentication: display the login page when MAC auth failed
Anonymous

10/21/2018

09:26 PM Bug #8555: Selectively killing states on WAN failure
don't kill states when failover gateway is down:
https://github.com/pfsense/pfsense/pull/4159
Steven Brown
12:09 PM pfSense Packages Bug #9050: Antartica does not make a rule
I am not actively working on the previous release.
The devel version will be the next release version in a short p...
BBcan177 .
10:23 AM pfSense Packages Bug #8909: tinc package makes /rc.newwanip looping forever
I guess I found a workaround: define a static IP address into the interface, then enable it and use in firewall and o... Andrew Hotlab

10/20/2018

11:02 PM Bug #9053 (Resolved): Dynamic DNS will not allow Route 53 wildcard record
When configuring a dynamic DNS client to update Route 53 (AWS) records, the web form will not validate a hostname tha... Tim Gagnon
08:15 PM pfSense Packages Bug #9050: Antartica does not make a rule
How long does it take to make it to the main version? It's been months and multiple releases since it says it was fi... Stuart Wyatt
12:23 PM pfSense Packages Bug #9050: Antartica does not make a rule
This is fixed in the pfBlockerNG-devel version. BBcan177 .
12:30 PM Todo #9052 (Resolved): Update Font-Awesome
Font Awesome in pfSense is using version (4.5.0). v4.x has been marked as End-of-life:
https://github.com/pfsense/...
BBcan177 .
10:15 AM Bug #9051: Privileges on 'all' group are not being honored
Should be easy to replicate, I just added a new user to admins group.
In the attached config I had added "page-d...
Ronald Schellberg
09:16 AM Bug #9051 (In Progress): Privileges on 'all' group are not being honored
That should not have been caused by this but I'll test it some more.
This should have only _added_ privileges to t...
Jim Pingle
08:55 AM Bug #9051: Privileges on 'all' group are not being honored
Jim Pingle wrote:
> All users are a member of the "All Users" group (actual group name internally: @all@).
>
> Pr...
Ronald Schellberg

10/19/2018

01:40 PM Revision 65c71eb3: Consider the "all" group when determining privileges. Fixes #9051
(cherry picked from commit fe1afbb7549907e0d1cdfbf85d5f36d075a6a916) Jim Pingle
01:39 PM Revision fe1afbb7: Consider the "all" group when determining privileges. Fixes #9051
Jim Pingle
11:43 AM pfSense Packages Todo #9041: update ntopng 3.6.0
It's actually already at 3.6 on 2.4.5 snapshots, and trying to pick back changes proved to be a bit of a challenge. I... Jim Pingle
11:18 AM Feature #8946: Add field to show IA_PD to DHCP6 Server page
PR was closed. Awaiting new PR(s) Anonymous
08:50 AM Bug #9051 (Feedback): Privileges on 'all' group are not being honored
Applied in changeset commit:fe1afbb7549907e0d1cdfbf85d5f36d075a6a916. Jim Pingle
08:38 AM Bug #9051 (Resolved): Privileges on 'all' group are not being honored
All users are a member of the "All Users" group (actual group name internally: @all@).
Privileges can be added to ...
Jim Pingle
08:16 AM Bug #7905: OpenVPN Authentication Against Backend Stalls All Server Traffic
Unfortunately, with pfSense version 2.4.4, the fallback to an alternative RADIUS server is still not operational.
...
John Tikis

10/18/2018

03:15 PM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
Just because two bugs affect the same subsystem doesn't mean they are related, though. Limiters work fine for many pe... Jim Pingle
03:06 PM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
Yes, of course! I might not have been clear, I totally understand that these are bugs in two different areas of code.... Terence Kent
11:25 AM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
They are unrelated, the only thing they have in common is that they are both limiter issues. One is a GUI parsing pro... Jim Pingle
11:06 AM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
Ok, great - I'm glad you've seen it.
FWIW, I would vote for those two issues to go out together. While fixing the...
Terence Kent
02:53 PM Revision 0edf0420: Rewrite /etc/rc.kill_states to use pfSense module state functions. Fixes #8554
Eliminates inaccurate shell exec/grep/preg_match syntax issues.
(cherry picked from commit 5142c80abbaa7b2dd219c03ed...
Jim Pingle
02:52 PM Revision 5142c80a: Rewrite /etc/rc.kill_states to use pfSense module state functions. Fixes #8554
Eliminates inaccurate shell exec/grep/preg_match syntax issues. Jim Pingle
02:35 PM pfSense Packages Bug #9050 (Resolved): Antartica does not make a rule
If Antarctica entries with a count > 0 are added to the pfBlockerNG GeoIP, there won't be an Antarctica rule created.... Stuart Wyatt
11:30 AM Bug #8555: Selectively killing states on WAN failure
Well it still could be worth submitting the PR to get some other eyes on it.
Also, having it up on Github would ma...
→ luckman212
10:00 AM Bug #8554 (Feedback): /etc/rc.kill_states code not correctly parsing pfctl output
Applied in changeset commit:5142c80abbaa7b2dd219c03edd60c4f675d2fb62. Jim Pingle
09:54 AM Bug #8554: /etc/rc.kill_states code not correctly parsing pfctl output
I'd rather not change one funky regex matching pattern for another. I have a better fix. Push incoming. Jim Pingle
01:01 AM Bug #8554: /etc/rc.kill_states code not correctly parsing pfctl output
Did you ever submit a PR for this? → luckman212
07:47 AM Bug #9049 (Not a Bug): IPSec statuspage shows both connected and connecting tunnel
Since bugnumber 8117 has been served off as not a bug, and no further response is given I'd like to re-open this bug.... Ges Ture

10/17/2018

11:45 PM Bug #8555: Selectively killing states on WAN failure
Unfortunately, I never really had the opportunity to create a proper complete build or run this outside a virtual env... Steven Brown
10:44 PM Bug #8555: Selectively killing states on WAN failure
Steven, pretty impressive work you've done there. How have these patches been working for you? Have you gotten any ot... → luckman212
06:36 PM Bug #9048 (Not a Bug): Installer memsticks using GPT should always have partition count that is a multiple of 4
The memstick installers use GPT but they only include three partitions and not four. This can cause a problem when wr... Jim Pingle
01:51 PM Revision 5baf07c8: Simplify schedule validation
(cherry picked from commit bb7cabdb20e7bad06263d5b3888c71415d6861c1) Steve Beaver
01:50 PM Revision 619f9e51: Added #8976 Allow traffic graph settings to be saved
(cherry picked from commit dd8a6d75e7a7cadc9a182c0306e8d04799a63338) Stephen Jones
01:50 PM Revision 4bc2dab8: Disable display of Diagnostics->AutoConfigBackup menu item if config is restored from pfSense < 2.4.4
Fixed #8959
(cherry picked from commit 245bfa559b5d8ebcb13b21feceaa58257ee194da)
Steve Beaver
01:50 PM Revision 613fa52d: Add top buttons if table > 24 rows
(cherry picked from commit e7299fd8c5ad6998aab372dc40f033f1dcb8d605) Steve Beaver
01:50 PM Revision 96101eb4: Fix German translation error. Also fixed in Zanata
(cherry picked from commit 84dc4a557c911d0a53a861d66021ff7f65400e87) Steve Beaver
01:50 PM Revision 050599fa: Fixed #9002 - PPPoE Service Name may contain ':'
(cherry picked from commit dac4cd09699bdafa5bcf1cf7b699438e5f669b26) Steve Beaver
01:50 PM Revision bf6a27e4: Fix typo in error msg
(cherry picked from commit c921665902c0a0bccd2376437a1ab1118009f86f) Steve Beaver
01:50 PM Revision 1b1aef35: Default ACB schedule to every day at midnight
(cherry picked from commit ebbc9e97a62464650684033df7f9cd7c3d32e609) Steve Beaver
01:50 PM Revision 68cba33c: Fixes #8949 Looks like there was 2 variable names for the same variable shownetboot and netboot. It now just uses the variable name netboot
(cherry picked from commit e46ea2c60986c62371966025ab3068466217fefa) Stephen Jones
01:50 PM Revision b35a897b: Added scheduled config backup
Fixed: #8947
(cherry picked from commit a1aa91dec887ba929be08c993170803396a669b2)
Steve Beaver
01:20 PM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
I've seen it but it isn't directly relevant to this specific bug. This was only about the queues not showing. Jim Pingle
01:09 PM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
Hey Jim. Glad to see this issue is getting fixed - that's great!
However, I want to be sure you've seen #8973, whi...
Terence Kent
12:27 PM Bug #8974: system_advanced_admin.php: Inconsistent placement of ssh options and lack of initialization
Also relevant/related: commit:8038c4e807c88fda4e1bb5b37ac31c9dbb8395fe
Jim Pingle
12:25 PM Bug #9047 (Duplicate): SSH port is not being saved properly
This has already been fixed while addressing another issue, see #8974 Jim Pingle
12:22 PM Bug #9047 (Duplicate): SSH port is not being saved properly
Hi guys,
After upgrading from 2.4.3-RELEASE (amd64) to 2.4.4-RELEASE, I noticed that my config wasn't generated prop...
Manoel Carvalho
12:23 PM Revision 517a683f: Add filer pkg, which was merged a while back but not set to build.
(cherry picked from commit 6b15f2c16b2a5396855751edf2983bcc2d12520e) Jim Pingle
12:23 PM Revision 6b15f2c1: Add filer pkg, which was merged a while back but not set to build.
Jim Pingle
10:46 AM pfSense Packages Feature #8869: HAproxy should use RFC 7919 DH parameter files
Understood.
I now remember where I had stumbled upon this idea in the first place, it goes back to a few years bac...
Stéphane Lapie
08:56 AM pfSense Packages Feature #8869: HAproxy should use RFC 7919 DH parameter files
Accommodating SSL testers that have no concept of proper security procedures isn't something we should aspire to do. ... Jim Pingle
07:47 AM Bug #8859: VTI: Some third-party vendors require rightsubnet to have a mask for VTI, rather than address
If you did not need the patch, does adding the patch affect it negatively in any way? That is also an important quest... Jim Pingle
04:57 AM Bug #8859: VTI: Some third-party vendors require rightsubnet to have a mask for VTI, rather than address
Jim Pingle wrote:
> #1 Seems to be OK but could use more confirmation. Traffic from the firewall itself still leaves...
Braden McGrath
07:40 AM pfSense Packages Feature #7179 (Feedback): Package Filer into 2.3
I added it to the list and bumped the package version to trigger a rebuild. It's up now for 2.4.4 and will go up with... Jim Pingle
07:21 AM pfSense Packages Feature #7179: Package Filer into 2.3
Looks like it was never added to the port build list at https://github.com/pfsense/pfsense/blob/master/tools/conf/pfP... Jim Pingle
07:18 AM pfSense Packages Feature #7179: Package Filer into 2.3
Where is the Filer package?
"PR #277":https://github.com/pfsense/FreeBSD-ports/pull/277 says "Merged" but I don't se...
→ luckman212

10/16/2018

10:24 PM pfSense Packages Feature #8869: HAproxy should use RFC 7919 DH parameter files
I understand the intent behind the stock DH parameter files, however some SSL testers raise known DH parameters as so... Stéphane Lapie
08:16 PM pfSense Packages Feature #9046 (New): telegraf feature request
we want to monitor the ntp service in pfsense, Now I manully add lines into telegraf.conf then manually start it, it ... mrco chen
08:00 PM Revision df9aa538: Fix Limiter validation check, which allows old queues to display. Fixes #8956
The AQM defaults to droptail when empty, but empty was being rejected as
invalid even though it was handled in the co...
Jim Pingle
07:59 PM Revision cd3cde52: Fix Limiter validation check, which allows old queues to display. Fixes #8956
The AQM defaults to droptail when empty, but empty was being rejected as
invalid even though it was handled in the code.
Jim Pingle
03:19 PM Revision d7f7ab4f: Solve a package reinstall/start race condition. Fixes #9045
(cherry picked from commit 84963037949aaf5225ae664cfe9b4e3b037beee0) Jim Pingle
03:18 PM Revision 84963037: Solve a package reinstall/start race condition. Fixes #9045
Jim Pingle
03:10 PM Bug #8956 (Feedback): traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
Applied in changeset commit:cd3cde526a9215e914c2f420c7e9c74b059a2ad0. Jim Pingle
02:47 PM Bug #8964: IPsec async cryptography advanced setting - TCP traffic not passing through
System -> Cryptographic:
AES-NI and BSD Crypto Device (aesni, cryptodev)
IPSec -> Advanced Settings -> Asynchrono...
Clinton Cory
03:18 AM Bug #8964: IPsec async cryptography advanced setting - TCP traffic not passing through
@Jim I mean "AES-NI and BSD Crypro Device" Vladimir Lind
10:25 AM Bug #9045 (Feedback): Race condition in package reinstall/startup after restore can lead to no packages restored
Applied in changeset commit:84963037949aaf5225ae664cfe9b4e3b037beee0. Jim Pingle
10:12 AM Bug #9045 (Resolved): Race condition in package reinstall/startup after restore can lead to no packages restored
rc.bootup triggers a rc.package_reinstall_all in the background with a delay, to reinstall all packages in the config... Jim Pingle
10:10 AM Bug #9042 (Resolved): Web GUI does not recognise NVMe devices as SMART capable
Jim Pingle
08:00 AM pfSense Packages Feature #9008 (Resolved): Add Zabbix 4 (agent and proxy) packages
Jim Pingle
07:38 AM pfSense Packages Feature #9008: Add Zabbix 4 (agent and proxy) packages
This can be closed.
Thanks!
Danilo Baio
07:34 AM Bug #8070: IKEv2 IPSec tunnel under load crashes pfSense when AES-NI is enabled
It's entirely possible that the fixes referenced in the original description were only fully/completely integrated in... Jim Pingle
01:27 AM Bug #8070: IKEv2 IPSec tunnel under load crashes pfSense when AES-NI is enabled
Interestingly, it is seemingly working in 2.4.4-RELEASE. /var/etc/ipsec/ipsec.conf included for your entertainment:
...
Rachel Chen

10/15/2018

10:00 PM Bug #8964: IPsec async cryptography advanced setting - TCP traffic not passing through
@luke they’re not for sale yet
@clinton please be more specific
@vladimir please explain how you enabled aes-ni on ...
Jim Thompson
04:20 PM Bug #8964: IPsec async cryptography advanced setting - TCP traffic not passing through
Whoa, SG-1100 is out? Where do I get one? → luckman212
04:17 PM Bug #8964: IPsec async cryptography advanced setting - TCP traffic not passing through
I see the same issues on a SG-1100. Clinton Cory
07:21 PM Revision 82c85c97: Show nvme controllers in SMART list. Fixes #9042
(cherry picked from commit e738a4c9b2607ad3561a0fce89d903535ca71249) Jim Pingle
07:21 PM Revision e738a4c9: Show nvme controllers in SMART list. Fixes #9042
Jim Pingle
07:20 PM Revision 083e4291: Revert "Show nvme devices in SMART disk list. Fixes #9042"
This reverts commit bdb6021f79f222b2c7d732436800e96cb34ea973.
(cherry picked from commit dba7debb2e6be1ef469d99fa5e9...
Jim Pingle
07:20 PM Revision dba7debb: Revert "Show nvme devices in SMART disk list. Fixes #9042"
This reverts commit bdb6021f79f222b2c7d732436800e96cb34ea973. Jim Pingle
06:46 PM Revision bdb6021f: Show nvme devices in SMART disk list. Fixes #9042
Jim Pingle
06:46 PM Revision 5ae720be: Show nvme devices in SMART disk list. Fixes #9042
(cherry picked from commit 89b4d4f30576908e36d5c6b70701db2f5e7363e6) Jim Pingle
05:25 PM Revision f646afcf: Enable Zabbix 4 packages build
Renato Botelho
05:24 PM Revision 4c05dca3: Enable Zabbix 4 packages build
Renato Botelho
03:54 PM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
Please re-read https://redmine.pfsense.org/issues/8956#note-3 and gather the requested information. Jim Pingle
01:55 PM Bug #9042 (Feedback): Web GUI does not recognise NVMe devices as SMART capable
Applied in changeset commit:5ae720be09a8976834cc424ead5c720f5fa2e64e. Jim Pingle
09:37 AM Bug #9042: Web GUI does not recognise NVMe devices as SMART capable
This should be a one-line fix but I had a follow-up question about the devices (nvd vs nvme) since their examples wer... Jim Pingle

10/14/2018

07:21 PM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
I just wanted to add that I am experiencing an issue with my limiter as well after upgrading to 2.4.4, but im not sur... jake xanaro
09:34 AM Bug #9043 (Not a Bug): openvpn 2.4.3-p1 -> 2.4.4, failed
Not enough info here for a valid bug report.
Please post on the forum at https://forum.netgate.com/ -- There are s...
Jim Pingle
06:38 AM Bug #9043 (Not a Bug): openvpn 2.4.3-p1 -> 2.4.4, failed
hi
After the update has stopped working normally openvpn for Pfsense + mikrotik v6.43.2 (Protocol TCP and Device mod...
Ivan Zagorodko
09:00 AM pfSense Packages Feature #9044 (New): Add SoftEther
It would be nice if you can add SoftEther program. It supports OpenVPN and it has more functions than the simple Open... John Smith

10/13/2018

11:34 PM Bug #8959 (Resolved): Restoring a <2.4.4 config with legacy gold auto backup package re-adds the menu option under Diagnostics
On 2.4.5.a.20181012.2248, restoring a config with AutoConfigBackup installed does not result in a system with Diagnos... Anonymous
09:31 PM Bug #9004: Default gateway IPv4 set to a group fails after restart on 2.4.4
I thought I was going crazy, because I have this same configuration 2 wans (1 cable, 1 4G/LTE) in a gateway group. T... Travis McMurry
06:27 PM Bug #9042 (Resolved): Web GUI does not recognise NVMe devices as SMART capable
It looks like it's only looking for ad, ada or da devices:
https://github.com/pfsense/pfsense/blob/c0787ee92aeaa51ce...
Steve Wheeler
02:32 PM Bug #8973: Traffic not going to Limiter queues
> Samir Patel wrote
> ...Try Codel/Round-Robin. This seems to work and has been stable a couple of days now.
Than...
Terence Kent
01:28 PM Bug #8973: Traffic not going to Limiter queues
Samir Patel wrote:
> Terence Kent wrote:
> > At this point, I've just disabled the limiters / queues. It's better f...
Victor Preatoni
01:34 PM pfSense Packages Todo #9041 (Resolved): update ntopng 3.6.0
update ntoping to 3.6.0
and enable activity map
the latest version of pfsense seems dos not enable activity ...
mom aiaz
08:08 AM Bug #9040 (Not a Bug): Invalid status for OpenVPN Point-to-Point Links
Jim Pingle
07:03 AM Bug #9040: Invalid status for OpenVPN Point-to-Point Links
*Update*
- After trying on a fresh install on my VM, the issue seems to no longer be present.
Please disregard th...
James Webb
06:44 AM Bug #9040 (Not a Bug): Invalid status for OpenVPN Point-to-Point Links
*Background:*
If one defines multiple OpenVPN servers in a tun point-to-point mode (i.e. use a /30 subnet in the IPv...
James Webb

10/12/2018

08:46 PM Bug #8973: Traffic not going to Limiter queues
Terence Kent wrote:
> At this point, I've just disabled the limiters / queues. It's better for people to deal with t...
Samir Patel
12:49 PM Bug #8973: Traffic not going to Limiter queues
A quick data point to confirm what Victor and Samir observed:
* I run two pfsense boxes at different locations. Th...
Terence Kent
01:17 AM Bug #8973: Traffic not going to Limiter queues
Victor Preatoni wrote:
> I got that issue a few times too, syslog flooded, and then I had to manually reboot as pfSe...
Samir Patel
06:29 PM Bug #9039 (Rejected): radvd (IPv6) is broken on systems with a USB ethernet interface
Bug 8429 addressed the regression that was introduced in 2.4.3 causing an error message such as "ioctl(SIOCGIFMEDIA) ... TJ Synkral
01:58 PM Revision c0787ee9: Build squid 4.x
Renato Botelho
10:46 AM Todo #9026 (Resolved): PTI checkbox wording can be confusing, should give a little more detail and show current PTI status
Jim Pingle
08:52 AM Feature #9038 (New): Live view of any log file
Is it possible to make an option where you can see the log files of PfSense in the webgui scrolling like a tail on li... IT SIM-CI
05:09 AM Bug #9037: Unbound not logging to syslog after reboot
Restarting syslogd from Status -> Services in the web UI also causes unbound to stop logging. Anonymous
02:58 AM Bug #9037 (New): Unbound not logging to syslog after reboot
On my current installation (2.4.4-RELEASE (amd64)) unbound does not log to syslog after a reboot until unbound is res... Anonymous

10/11/2018

06:49 PM Todo #9026: PTI checkbox wording can be confusing, should give a little more detail and show current PTI status
Tested on 2.4.5.a.20181011.0014, text for *Kernel PTI* now reads:... Anonymous
11:34 AM pfSense Packages Feature #8769: Allow FreeRADIUS users to change their own Passwords and Pins
No, because there isn't a generic way to change a RADIUS password like that. It depends on the RADIUS server and its ... Jim Pingle
11:21 AM pfSense Packages Feature #8769: Allow FreeRADIUS users to change their own Passwords and Pins
Isn't this something that could be created as an add-on and not rely completely on the back end radius package? NCATS LAB
11:30 AM Bug #9036: The bypasslan feature should be configurable for any interface.
It is a duplicate of issue #5826 which covers the same request. Jim Pingle
11:20 AM Bug #9036: The bypasslan feature should be configurable for any interface.
I see this was changed to Duplicate
Can we change it to feature request?
NCATS LAB
09:24 AM Bug #9036: The bypasslan feature should be configurable for any interface.
Thank-you, it is not easy to find the correct/applicable entries in the forum.
I am not attempting dialogue so much ...
NCATS LAB
08:53 AM Bug #9036 (Duplicate): The bypasslan feature should be configurable for any interface.
Duplicate of #5826
Please post questions "on the forum":https://forum.netgate.com before opening issues, this isn'...
Jim Pingle
08:49 AM Bug #9036 (Duplicate): The bypasslan feature should be configurable for any interface.
In StrongSwan, the bypasslan feature is configurable for any interface.
However, in pfsense we are limited to only t...
NCATS LAB
11:18 AM Bug #9034: Firewall Rules Interface
I see this was changed to Not a Bug.
Can we change it to feature request?
NCATS LAB
08:56 AM Bug #9034: Firewall Rules Interface
We will have to agree to disagree.
We find it less convenient that the interface toggles between two methods of di...
NCATS LAB
08:43 AM Bug #9034 (Not a Bug): Firewall Rules Interface
It's done deliberately. Tabs are more convenient for short lists of interfaces. With longer lists of interfaces, drop... Jim Pingle
08:41 AM Bug #9034 (Not a Bug): Firewall Rules Interface
Request for feature change.
Why do the firewall rules list toggle between a URL list and a drop down? Why not just ...
NCATS LAB
08:42 AM Bug #9035 (New): Inactive Interfaces are Hidden in Firewall Rules
Hiding the inactive interfaces makes it impossible to prestage configurations.
Please do not hide inactive interface...
NCATS LAB
07:45 AM Bug #9033 (Resolved): bogons list outdated
This should be OK now, the public server wasn't picking up the latest copy of the content but we fixed the glitch.
...
Jim Pingle

10/10/2018

05:11 PM Revision 55f30cc8: Fixes to ssh agent forwarding setting
(cherry picked from commit 8cc841364132b4fcf24bb314e8f746b01619d54d) Jim Pingle
05:11 PM Revision 8cc84136: Fixes to ssh agent forwarding setting
Jim Pingle
05:05 PM Bug #9033 (Resolved): bogons list outdated
Hey all,
I've recently been allocated 103.123.164.0/22
it's on https://files.pfsense.org/lists/fullbogons-ipv4.txt
...
Paul Willard
05:04 PM Revision 2f5aef4e: ssh settings upgrade fixes
(cherry picked from commit 72b7b9a20e43e644035e44bd28b13f4e4bd775a5) Jim Pingle
05:04 PM Revision 72b7b9a2: ssh settings upgrade fixes
Jim Pingle
04:19 PM Revision b1862963: Restore the RADIUS NAS ID option to Captive Portal. Fixes #8998
Keeps the default of using CaptivePortal-<zonename> when not set,
otherwise uses the value supplied by the user as wi...
Jim Pingle
04:18 PM Revision b1cc8f31: Restore the RADIUS NAS ID option to Captive Portal. Fixes #8998
Keeps the default of using CaptivePortal-<zonename> when not set,
otherwise uses the value supplied by the user as wi...
Jim Pingle
01:49 PM Revision 7ea27240: $str to $fqdn
Marco Pannetto
01:47 PM Revision 2f002c9b: Compatibility requested
Marco Pannetto
01:17 PM Bug #8791: Default IPv6 rules do not allow some devices to perform router or neighbor discovery
This fixed IPv6 on my Android phone (Moto G4). Previously the Internet connection test would always fail after about ... Corey Boyle
11:44 AM Bug #8973: Traffic not going to Limiter queues
Samir Patel wrote:
> Had to switch back to Taildrop/FIFO, though the limiters are no longer possible to monitor.
> ...
Victor Preatoni
11:20 AM Bug #8998 (Feedback): All Captive Portal zones send only "CaptivePortal" as NAS Identifier
Applied in changeset commit:b1cc8f3143f7253bb3acdcdf8c18f9effaf3bce5. Jim Pingle
10:26 AM Revision 22e32874: generate a flag even if trying to perform RADIUS MAC authentication on a non-RADIUS server.
A FL
10:26 AM Revision 774ff51b: Implement login fallback for RADIUS MAC authentication
A FL
05:23 AM Feature #9032: RADIUS MAC Authentication: display the login page when MAC auth failed
Pull request : https://github.com/pfsense/pfsense/pull/4000
Forum thread: https://forum.netgate.com/topic/136138/af...
A FL
05:12 AM Feature #9032 (Resolved): RADIUS MAC Authentication: display the login page when MAC auth failed
Since 2.4.4 the behavior of Radius MAC authentication changed.
In 2.4.3 user was redirected to the login page whe...
A FL
01:45 AM Bug #9024: Ping packet loss under load when using limiters
I can confirm this bug. My testing seemed to show that the behaviour was the same no matter which scheduler I assign... Steven Brown
01:10 AM Bug #8938: Installation of a package that depends on php72 on a version of pfSense older than 2.4.4-RELEASE breaks the pfSense install
Thanks, Eduard, I will try it later this day. Dmitriy K

10/09/2018

11:54 PM Bug #8973: Traffic not going to Limiter queues
Can see that our traffic shaper is nonfunctional now as of 2.4.4 in terms of per-host dynamic bandwidth shaping.
W...
Samir Patel
10:37 PM Bug #8973: Traffic not going to Limiter queues
Had to switch back to Taildrop/FIFO, though the limiters are no longer possible to monitor.
With QFQ, getting sudd...
Samir Patel
01:43 AM Bug #8973: Traffic not going to Limiter queues
Seeing same as all the aforementioned comments. Taildrop and FIFO do work, but don't show under Diag > Limiter Info. ... Samir Patel
08:41 PM Bug #9000: Haproxy does not send ipv6 traffic to backend after updating to Pfsense 2.4.4
You should post on the Spanish language category of the forum -- https://forum.netgate.com/category/11/espa%C3%B1ol
...
Jim Pingle
07:03 PM Bug #9000: Haproxy does not send ipv6 traffic to backend after updating to Pfsense 2.4.4
Jim Pingle wrote:
> Judging by this person's other reported issues, they have some general config/environment proble...
Anonymous
12:28 PM Bug #9000 (Not a Bug): Haproxy does not send ipv6 traffic to backend after updating to Pfsense 2.4.4
Judging by this person's other reported issues, they have some general config/environment problem wholly unrelated to... Jim Pingle
12:25 PM Bug #9000: Haproxy does not send ipv6 traffic to backend after updating to Pfsense 2.4.4
Works for me.. at least with current version:... Pi Ba
06:18 PM Revision 14966896: Include zone name in Nas-Identifier
(cherry picked from commit df99d3bf44dc0a254be305a25b8459f4cc5fe9a9) A FL
06:18 PM Revision 4b2edd69: Merge pull request #3997 from Augustin-FL/patch-cp-2
Renato Botelho
06:02 PM Revision 63da30ff: Only display "you are connected" if :
- Logout popup is disabled and no custom logout page is set
- Logout popup is enabled and logout_id is missing
(cher...
A FL
06:02 PM Revision e5408404: Merge pull request #3996 from Augustin-FL/cp-logout-patch-1
Renato Botelho
06:01 PM Revision 176361d8: Review fix.
(cherry picked from commit 8b6aae09e9f4607fc27066dff7a8f58c568f61f9) Sorin Sbarnea
06:01 PM Revision e4dc9b6f: Review fixes.
(cherry picked from commit 0aa2f5f07ba64c3122b5f01656de3e7b0a673492) Sorin Sbarnea
06:01 PM Revision 7b5e4508: Enable setting AllowAgentForwarding value
Fixes #8590
Signed-off-by: Sorin Sbarnea <ssbarnea@redhat.com>
(cherry picked from commit 1d835d945349d3c7b65c881559...
Sorin Sbarnea
06:01 PM Revision df509dcd: Merge pull request #3993 from ssbarnea/master_ssh_forward
Renato Botelho
05:58 PM Revision e29802c7: Add Zabbix4 config options
(cherry picked from commit 75444abd277a4a2afad3b5c52156a2c14153c508) Danilo Baio
05:58 PM Revision e0d0b0c9: Merge pull request #dbaio:zabbix4 from dbaio/zabbix4
Renato Botelho
05:10 PM Revision f08369ec: change after review
Vito Piserchia
03:43 PM pfSense Packages Bug #9031 (Resolved): Suricata fails to start with interface with /31 mask
I have discovered that Suricata will not start in blocking mode when an interface has a /31 subnet mask when using an... Aaron Morris
03:24 PM Feature #9030 (Resolved): Allow TLS Key Direction with OpenVPN
Provide the user the possibility to define the direction for the TLS key in the Open VPN configuration
A pull requ...
Vito Piserchia
01:48 PM Bug #9029 (Resolved): Proxy authentication is not working for HTTPS
When a user enters proxy details on system_advanced_misc.php it should trigger the firewall to use the proxy for thin... Jim Pingle
01:17 PM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
I think we should null-coalesce to "taildrop" for the AQM field to solve this issue, as that would be the default AQM... Matt _
02:11 AM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
I reinstall 2.4.4 from the scratch did everything no changes now using 2.3.5 again until problems solved because i am... sib iqb
12:13 AM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
Happened to me as well... really screwed here. Cannot see previous queues in the GUI (under Limiters) and cannot appl... Samir Patel
01:16 PM Bug #8998 (New): All Captive Portal zones send only "CaptivePortal" as NAS Identifier
I'm OK with the PR as a new default but I still think we should allow the user to override the NAS ID as was possible... Jim Pingle
01:03 PM Bug #8998 (Feedback): All Captive Portal zones send only "CaptivePortal" as NAS Identifier
PR merged Renato Botelho
01:05 PM Bug #8590: sshd does not allow agent forwarding
Applied in changeset commit:1d835d945349d3c7b65c88155948e607bcbfdf76. Anonymous
01:04 PM Bug #8590 (Feedback): sshd does not allow agent forwarding
PR merged Renato Botelho
01:03 PM Bug #9010 (Feedback): Captive Portal Unable to logout
PR merged Renato Botelho
12:44 PM Revision 66ac4720: Enable missing options for haproxy17
Renato Botelho
12:44 PM Revision b39ab5dc: Enable missing options for haproxy17
Renato Botelho
11:43 AM Feature #4821: PPPoE WANs do not take full advantage of NIC driver queues for receiving traffic
Adding the tunable: net.isr.dispatch=deferred fixed it for me to reach the full rated speed of my link.
Read the F...
L H
09:34 AM Revision cef01bcb: Update text
Vito Piserchia
09:27 AM Revision 8698f918: Added tlsauth keydir options to openvpn client and server
Vito Piserchia
08:58 AM Bug #8938: Installation of a package that depends on php72 on a version of pfSense older than 2.4.4-RELEASE breaks the pfSense install
Dmitriy K wrote:
> I wonder why 2.4.3 wasnt included in the exclusion list? Unfortunately, now my home router is rui...
Eduard Rozenberg
07:49 AM Bug #8938: Installation of a package that depends on php72 on a version of pfSense older than 2.4.4-RELEASE breaks the pfSense install
Dmitriy K wrote:
> I wonder why 2.4.3 wasnt included in the exclusion list? Unfortunately, now my home router is rui...
Eduard Rozenberg
08:15 AM Bug #8915 (Resolved): After updating to 2.4.4-rc an empty crash report is shown
Those logs are expected, they are from PEAR and various other parts of PHP being upgraded. As long as the empty repor... Jim Pingle
07:58 AM pfSense Packages Bug #9027: HAProxy: Unknown keyword lua-load
Should be fixed now, thanks for reporting. Pi Ba
06:49 AM pfSense Packages Bug #9027 (Resolved): HAProxy: Unknown keyword lua-load
After upgrading pfSense from 2.4.3_1 to 2.4.4 our haproxy didn't started anymore.
The error we got was `Unknown ke...
Karl Fritsche
07:40 AM Bug #9028 (Duplicate): Acme pkg upgrade caused pfSense to try upgrade 2.4.3 -> 2.4.4, failed
Duplicate of #8938 Jim Pingle
07:38 AM Bug #9028 (Duplicate): Acme pkg upgrade caused pfSense to try upgrade 2.4.3 -> 2.4.4, failed
I clicked on the update button next to the Acme package on the dashboard. This appears to have caused pfSense to try ... Eduard Rozenberg

10/08/2018

06:02 PM Bug #9024: Ping packet loss under load when using limiters
The conf attached to the example https://forum.netgate.com/topic/112527/playing-with-fq_codel-in-2-4/570 shows that t... Josh Chilcott
04:49 PM Bug #8915: After updating to 2.4.4-rc an empty crash report is shown
Tried to replicate getting PHP crush report on SG-3100:
from version 2.4.3_p1 to 2.4.4 - RELEASE / no crush repo...
Danilo Zrenjanin
03:39 PM Revision 5449b0c7: Add help.php entry for AWS VPC wizard.
(cherry picked from commit 0123cb3202c19fd8ad288545720e3b5e6e56a0f6) Jim Pingle
03:39 PM Revision 0123cb32: Add help.php entry for AWS VPC wizard.
Jim Pingle
01:56 PM Bug #8994: Two RRDDATA Sections in Restored Config Breaks Unit
It should be removed by the restore as its last act, since the data is taken out of config.xml and converted back int... Jim Pingle
01:47 PM Bug #8994: Two RRDDATA Sections in Restored Config Breaks Unit
There was no rrd section in the resulting configuration at all. Chris Linstruth
12:50 PM Bug #8994 (Resolved): Two RRDDATA Sections in Restored Config Breaks Unit
Did you look far enough back in time on the graphs to see data from the date before the backup was taken?
I took a...
Jim Pingle
01:33 PM Revision f4bc3bce: Wording changes for PTI disable option. Fixes #9026
(cherry picked from commit 2ba7026de2c08450fa40d5694f44cbe46a2262e2) Jim Pingle
01:33 PM Revision 2ba7026d: Wording changes for PTI disable option. Fixes #9026
Jim Pingle
01:09 PM Feature #9016 (Rejected): Ability to create vpn user groups
On 2.4.4 with IKEv2/EAP you can use multiple address pools based on the user name to effectively accomplish this. The... Jim Pingle
09:40 AM Todo #9026 (Feedback): PTI checkbox wording can be confusing, should give a little more detail and show current PTI status
Applied in changeset commit:2ba7026de2c08450fa40d5694f44cbe46a2262e2. Jim Pingle
08:31 AM Todo #9026 (Resolved): PTI checkbox wording can be confusing, should give a little more detail and show current PTI status
Now that there are "Intel CPUs in the wild unaffected by Meltdown":https://github.com/freebsd/freebsd/commit/9c0b8085... Jim Pingle
05:15 AM Bug #9023: is_fqdn() validation
Ulterior information on this patch:
As per php.net/manual/en/filter.filters.validate.php: FILTER_VALIDATE_DOMAIN
...
Nano Caiordo
01:00 AM pfSense Packages Bug #9025 (New): SquidGard + Target categories
Hello,
An error occurs after applying the changes to SquidGard when:
Removing an unwanted target category from "T...
Issa Jacaman

10/07/2018

02:44 PM Bug #8914: Gateway switch events cause a huge amount of log spew
Could you please check if you are also experiencing latency spikes on LAN Interface during a reconnect (run a ping to... Flole Systems
02:03 PM Bug #9024: Ping packet loss under load when using limiters
ok, so we just have a configuration guideline then: "Always put all traffic through the limiter". Do you have a conf ... Dave taht
01:50 PM Bug #9024: Ping packet loss under load when using limiters
I saw this when only TCP/UDP was being put into the limiter. As soon as I changed it to "all traffic" the loss went ... Anonymous
01:05 PM Bug #9024 (Closed): Ping packet loss under load when using limiters
I think https://forum.netgate.com/topic/112527/playing-with-fq_codel-in-2-4/595 we have confirmed an issue still exis... Dave taht
11:11 AM Bug #8998: All Captive Portal zones send only "CaptivePortal" as NAS Identifier
It would be better for all installations to set the field for the nas-identifier back to the previous version. Otherw... Hostmaster BI
11:01 AM Revision b887348c: Properly detect valid trailing dots
Count dots, detect a trailing one and remove it for counting. Must have at least 2 dots. Marco Pannetto
10:46 AM Bug #8970 (Assigned): Queues Menu item ends with ":"
I tested on 2.4.5.a.20181006.1421 and I still see ":" for Status/Queue menu in German translation (see in attach scre... Azamat Khakimyanov
10:20 AM Revision 895708c5: Improved domain validation
Marco Pannetto
10:14 AM Feature #8943 (Resolved): Additions to wake on lan section
Tested on 2.4.5.a.20181006.1421: after adding 25 device in the list, additional "Add" and "Wake All Devices" buttons ... Azamat Khakimyanov
05:21 AM Bug #9023 (Resolved): is_fqdn() validation
Hello,
current validation doesn't follow any RFC guideline and it's pretty much broken....
Nano Caiordo
12:50 AM Bug #8973: Traffic not going to Limiter queues
using limiters with queues works fine with codel and fq_codel its just that we r not able to see it in limiter info a... Bipin Chandra

10/06/2018

09:07 PM Bug #9022 (Not a Bug): Policy Routing an Exception to an IPsec Tunnel Drops Reply Traffic
Not a bug. You can't policy route around IPsec in tunnel mode. The stack will drop replies because they didn't come v... Jim Pingle
08:53 PM Bug #9022: Policy Routing an Exception to an IPsec Tunnel Drops Reply Traffic
-If the IPsec tunnel is disabled on site B, pings instantly start flowing. Enable and reconnect it, they stop again.-... Chris Linstruth
08:51 PM Bug #9022 (Not a Bug): Policy Routing an Exception to an IPsec Tunnel Drops Reply Traffic
Site A
Tunnel Local 172.25.234.0/24 Remote 192.168.223.0/24
Site B
Tunnel Local 192.168.223.0/24 Remote 172.25.2...
Chris Linstruth
02:24 PM pfSense Packages Bug #9020: Impossible to register ACME wildcard certificate regardless documentation
Jim Pingle wrote:
> You have some kind of configuration error. I tried it again exactly as stated on the page and it...
Sorin Sbarnea
01:08 PM pfSense Packages Bug #9020 (Not a Bug): Impossible to register ACME wildcard certificate regardless documentation
You have some kind of configuration error. I tried it again exactly as stated on the page and it works. Jim Pingle
09:59 AM pfSense Packages Bug #9020 (Not a Bug): Impossible to register ACME wildcard certificate regardless documentation
Documentation at https://www.netgate.com/docs/pfsense/certificates/acme-wildcard.html states what needs to be done to... Sorin Sbarnea
02:21 PM Bug #7609: NTP Status not parsing all NTP Access Restrictions preventing status display when it is actually allowed
I would also add to not confuse or mix both issue. One was due PHP reading ACLs permissions but no setting them up fo... Nano Caiordo
01:27 PM Bug #9021 (Closed): FreeBSD 11.2 fails to boot on Celeron J1900
Did not see anything in recent issues covering this. Apologize in advance if duplicate.
On some systems, FreeBSD ...
Elvis Impersonator
01:07 PM Bug #8973: Traffic not going to Limiter queues
Tried to set a very hard limit on my DownloadLimiter and seems to be shaping properly. Tested with testmy.net Victor Preatoni
12:43 PM pfSense Packages Todo #8682 (Resolved): ACME Account Key registration gives no indication of success or failure, assumes success
This is only about the icon on the button on the key registration page, and it is working properly now. Jim Pingle
09:54 AM pfSense Packages Todo #8682: ACME Account Key registration gives no indication of success or failure, assumes success
This is so true, the UI always gives the "green" response regardless what catastrophic failure occurred, confusing us... Sorin Sbarnea
07:44 AM Bug #8859: VTI: Some third-party vendors require rightsubnet to have a mask for VTI, rather than address
#1 Seems to be OK but could use more confirmation. Traffic from the firewall itself still leaves via WAN as expected.... Jim Pingle
07:39 AM Bug #9019 (Resolved): Hyper-V hn NICs drop UDP6 traffic when transmit checksums are enabled
Due to a problem with FreeBSD 11.2, Hyper-V NICs can't send IPv6 UDP traffic when transmit checksums are enabled.
...
Jim Pingle
07:35 AM Bug #9017 (Not a Bug): Policy based Routing is not working
Policy routing is working fine here. Most likely you have a problem with your configuration or rules. Please post on ... Jim Pingle
07:31 AM pfSense Packages Bug #8989 (Resolved): [Freeradius] not starting radiusd -X | Errors reading /usr/local/etc/raddb/dictionary: dict_init: /usr/local/etc/raddb/dictionary[6] invalid entry
Jim Pingle
03:12 AM pfSense Packages Bug #8989: [Freeradius] not starting radiusd -X | Errors reading /usr/local/etc/raddb/dictionary: dict_init: /usr/local/etc/raddb/dictionary[6] invalid entry
Seems good to me. It can be marked as resolved A FL
07:30 AM Bug #8927 (Resolved): PFsense 2.4.4 FreeRadius and Captive Portal Quota Problems
Jim Pingle
03:30 AM Bug #8927: PFsense 2.4.4 FreeRadius and Captive Portal Quota Problems
Seems good to me now. It can be marked as resolved A FL
07:30 AM Bug #9018 (Rejected): swap_pager_getswapspace(): failed
Something is running your system out of RAM. There is not enough detail here to say what, if anything, is to blame.
...
Jim Pingle
05:34 AM Bug #9018 (Rejected): swap_pager_getswapspace(): failed
dns resolver filed , when i locked to console i found this message
swap_pager_getswapspace(1): failed
swap_page...
mom aiaz
07:10 AM Revision df99d3bf: Include zone name in Nas-Identifier
A FL
06:59 AM Revision c857583b: Only display "you are connected" if :
- Logout popup is disabled and no custom logout page is set
- Logout popup is enabled and logout_id is missing
A FL
06:12 AM Bug #8954: hn0: driver does not support altq
This bug was also before, see isue #7869
https://redmine.pfsense.org/issues/7869#change-38548
Nadav Rak
05:26 AM Bug #8954: hn0: driver does not support altq
Having exactly the same issue. Fresh install of pfSense under Hyper-V on 2012R2. Dave Pone
06:09 AM Bug #7869: Hyper-v vm traffic shaper error: hn0: driver does not support altq
I haven't upgraded yet. I think you should open a new bug report. Nadav Rak
03:09 AM Bug #8998: All Captive Portal zones send only "CaptivePortal" as NAS Identifier
The reason this field was removed was to standardize how RADIUS authentication was done in each pfSense module. OpenV... A FL
02:04 AM Bug #9010: Captive Portal Unable to logout
This bug only affects the logout popup and not custom logout pages. I committed a fix: https://github.com/pfsense/pfs... A FL

10/05/2018

10:14 PM Bug #9017 (Not a Bug): Policy based Routing is not working
I have following setup on my firewall.
2 internet gateways
WGW1 and WGW2
2 Vlans
Vlan 10 and Vlan 20
Created ...
Manny Janjua
08:36 PM Bug #7609: NTP Status not parsing all NTP Access Restrictions preventing status display when it is actually allowed
As of ntp-4.2.6p5, it seems to require 'restrict -4 default' or to use 'restrict localhost' in ACL, what worked for m... Nano Caiordo
07:00 PM Feature #9016 (Rejected): Ability to create vpn user groups
With a variety of other firewall and vpn solutions, the user is given the ability to create groups of users and gover... Dan Tentler
06:35 PM Bug #9015: Default gateway doesn't switch as expected
After further testing this appeared to be functioning as expected. Chris Linstruth
06:06 PM Bug #9015 (Closed): Default gateway doesn't switch as expected
Anonymous
05:19 PM Bug #9015 (Closed): Default gateway doesn't switch as expected
After selecting Gateway Group (WANGW2 tier1 - WANGW1 tier2) under *System/Routing/Gateways* - *Default gateway sectio... Danilo Zrenjanin
05:36 PM Bug #8914: Gateway switch events cause a huge amount of log spew
Tried to replicate the issue in 2.4.4-RELEASE.
Under logs, I was getting only "Keep current gateway, its already ...
Danilo Zrenjanin
04:08 PM Bug #8994: Two RRDDATA Sections in Restored Config Breaks Unit
Tested restoring the original problematic config.xml. It did restore successfully but there was no rrddata in the res... Chris Linstruth
03:35 PM Revision dd8a6d75: Added #8976 Allow traffic graph settings to be saved
Stephen Jones
02:34 PM Bug #9014 (Not a Bug): Unable to uninstall any Package via System -> Package Manager
Can't duplicate this here. Packages install and uninstall fine. Please post on the forum to discuss and diagnose the ... Jim Pingle
02:12 PM Bug #9014 (Not a Bug): Unable to uninstall any Package via System -> Package Manager
Trying to Uninstall any package via in the Package Manager hangs at "Please wait while the update system initializes" Peter Reinhardt
01:46 PM Bug #8452 (Closed): PPPoE :: Interfaces > WAN: [PPPoE Configuration] Service name :: colon not allowed (invalid character)
Anonymous
01:40 PM Bug #8452 (Duplicate): PPPoE :: Interfaces > WAN: [PPPoE Configuration] Service name :: colon not allowed (invalid character)
Jim Pingle
01:29 PM Bug #8452: PPPoE :: Interfaces > WAN: [PPPoE Configuration] Service name :: colon not allowed (invalid character)
This issue can be closed as this has been resolved. Please see bug 9002. Thank you. Bouke Henstra
01:17 PM Feature #8976 (Resolved): Status -> Traffic Graph, provide SAVE button for graph settings.
Renato Botelho
12:40 PM Feature #8976: Status -> Traffic Graph, provide SAVE button for graph settings.
Very Cool! I just tried it out and it works great!
Thank you so much for implementing this feature, I really appre...
jake xanaro
12:20 PM Feature #8976 (Feedback): Status -> Traffic Graph, provide SAVE button for graph settings.
Changes added. Commit hash: dd8a6d75e7a7cadc9a182c0306e8d04799a63338
It should now be able to save your settings to ...
Anonymous
12:43 PM pfSense Packages Bug #9013 (Resolved): pfSense Crash: AVAHI_RCFILE undefined constant
This was fixed days ago. Update to the latest version of that package. Jim Pingle
12:24 PM pfSense Packages Bug #9013 (Resolved): pfSense Crash: AVAHI_RCFILE undefined constant
[04-Oct-2018 04:31:18 America/New_York] PHP Warning: Use of undefined constant AVAHI_RCFILE - assumed 'AVAHI_RCFILE'... P L
12:11 PM Bug #8933 (Resolved): diagnostics -> backup/restore -> reinstall packages hangs
Works now Jim Pingle
11:25 AM pfSense Packages Bug #9012 (New): Captive Portal authentication in Squid Proxy Server does not work
Version pfsense 2.4.4-RELEASE (amd64)
I have configured Authentication Method to "Captive Portal" in Squid Proxy Ser...
Kevin Chou
10:26 AM Bug #8978: vidconsole is invalid for efi booted systems
Jim Pingle
08:39 AM Bug #8859: VTI: Some third-party vendors require rightsubnet to have a mask for VTI, rather than address
The attached patch adds @0.0.0.0/0@ to @rightsubnet@ and @leftsubnet@ which may make some third party devices happy, ... Jim Pingle
07:51 AM Bug #9009 (Resolved): Cannot create Schedule
Jim Pingle
12:09 AM Bug #9009: Cannot create Schedule
pat lechriss wrote:
> Hello, when attempting to add a shedule i always get this php errors. Thx
>
>
> Crash rep...
pat lechriss
07:49 AM Bug #9011 (Not a Bug): Snort not showing in menu
There is no bug here that I can reproduce. I install snort, it's in the menu.
If there is a problem, it is specifi...
Jim Pingle
02:38 AM Bug #9011 (Not a Bug): Snort not showing in menu
Hi
I have an HA setup and on the secondary netgate XG-2758 the snort menu button is not showing after installation...
Tino Zidore
05:46 AM Bug #9006 (Resolved): Using umlauts in client specific overrides common names field causes restore of old config backup
Renato Botelho
12:01 AM Bug #9006: Using umlauts in client specific overrides common names field causes restore of old config backup
verified. Works. thank you! Stefan Bauer
05:29 AM Bug #8998: All Captive Portal zones send only "CaptivePortal" as NAS Identifier
We also need to get a unique NASID. Please fix this bug. Any solution will suit. WiFi SYS
04:02 AM Bug #9010: Captive Portal Unable to logout
Ming-Chang Cheng wrote:
> Version pfsense 2.4.4-RELEASE (amd64)
> I have configured captive portal with radius serv...
Inder P. MEEL
01:51 AM Bug #9010 (Resolved): Captive Portal Unable to logout
Version pfsense 2.4.4-RELEASE (amd64)
I have configured captive portal with radius server. Enabled "Logout popup win...
Ming-Chang Cheng

10/04/2018

08:58 PM Bug #8954: hn0: driver does not support altq
Windows 10 Pro w/latest updates + Hyper-V.
2.4.3 was/is flawless. Upgraded to 2.4.4 and got this error and can't use...
Jon Gav
08:46 PM Revision 650d95d1: Init schedules before use. Fixes #9009
(cherry picked from commit 4c3669ea8a9acf4657cd84e0ae22fb8809302756) Jim Pingle
08:46 PM Revision 4c3669ea: Init schedules before use. Fixes #9009
Jim Pingle
04:22 PM Revision aa418087: Clean up test for CDATA tags and add common_name. Fixes #9006
(cherry picked from commit 7a97d81d81afa7ea86c8ad79bff8e203bc9457a4) Jim Pingle
04:22 PM Revision 7a97d81d: Clean up test for CDATA tags and add common_name. Fixes #9006
Jim Pingle
03:50 PM Bug #9009 (Feedback): Cannot create Schedule
Applied in changeset commit:4c3669ea8a9acf4657cd84e0ae22fb8809302756. Jim Pingle
02:29 PM Bug #9009 (Resolved): Cannot create Schedule
Hello, when attempting to add a shedule i always get this php errors. Thx
Crash report begins. Anonymous machin...
pat lechriss
03:47 PM Revision 8b6aae09: Review fix.
Sorin Sbarnea
03:45 PM Revision 0aa2f5f0: Review fixes.
Sorin Sbarnea
03:03 PM Revision e4125720: Unify and improve crash report checking. Fixes #8915
(cherry picked from commit 6e150fc0d022d231c7dc243ba68f4784f58973d5) Jim Pingle
03:03 PM Revision 6e150fc0: Unify and improve crash report checking. Fixes #8915
Jim Pingle
02:28 PM Bug #8999: Nat rules do not work in pfsense 2.4.4 on hypervisor xen
Chris Linstruth wrote:
> Right. And NAT works just fine on 2.4.4 on AWS. Please take this discussion to the pfSense ...
Anonymous
02:11 PM Feature #8976: Status -> Traffic Graph, provide SAVE button for graph settings.
Anonymous
10:27 AM Feature #8976 (Assigned): Status -> Traffic Graph, provide SAVE button for graph settings.
A possible temporary workaround if you haven't tried it already. There is a traffic graphs widget that allows for sav... Anonymous
01:33 PM Bug #8938: Installation of a package that depends on php72 on a version of pfSense older than 2.4.4-RELEASE breaks the pfSense install
I wonder why 2.4.3 wasnt included in the exclusion list? Unfortunately, now my home router is ruined because of updat... Dmitriy K
01:22 PM Revision 245bfa55: Disable display of Diagnostics->AutoConfigBackup menu item if config is restored from pfSense < 2.4.4
Fixed #8959 Steve Beaver
01:02 PM Revision e7299fd8: Add top buttons if table > 24 rows
Steve Beaver
12:51 PM Revision 1d835d94: Enable setting AllowAgentForwarding value
Fixes #8590
Signed-off-by: Sorin Sbarnea <ssbarnea@redhat.com>
Sorin Sbarnea
12:40 PM Revision 84dc4a55: Fix German translation error. Also fixed in Zanata
Steve Beaver
12:24 PM Revision dac4cd09: Fixed #9002 - PPPoE Service Name may contain ':'
Steve Beaver
12:20 PM Revision 75444abd: Add Zabbix4 config options
Danilo Baio
11:51 AM pfSense Packages Feature #9008: Add Zabbix 4 (agent and proxy) packages
https://github.com/pfsense/pfsense/pull/3995
https://github.com/pfsense/FreeBSD-ports/pull/580
Danilo Baio
11:44 AM pfSense Packages Feature #9008 (Resolved): Add Zabbix 4 (agent and proxy) packages

What's new in Zabbix 4.0.0:
https://www.zabbix.com/documentation/4.0/manual/introduction/whatsnew400
Danilo Baio
11:25 AM Bug #9006 (Feedback): Using umlauts in client specific overrides common names field causes restore of old config backup
Applied in changeset commit:7a97d81d81afa7ea86c8ad79bff8e203bc9457a4. Jim Pingle
11:10 AM Bug #9006 (In Progress): Using umlauts in client specific overrides common names field causes restore of old config backup
Jim Pingle
10:49 AM Bug #9006 (Resolved): Using umlauts in client specific overrides common names field causes restore of old config backup
Clicking VPN -> OpenVPN -> Servers
selecting: CSC Overrides
add new client and set as Common Name a word with u...
Stefan Bauer
10:45 AM Feature #9005: Allow to define allowed x509 client certs by having CN in openvpn server (tls-verify)
Not a known issue I'm aware of but probably not difficult to solve in a future release. Open a new issue with the spe... Jim Pingle
10:43 AM Feature #9005: Allow to define allowed x509 client certs by having CN in openvpn server (tls-verify)
Too bad. Pfsense has problems with common names containing umlauts (ö ä ü) this way. Is this a known problem and work... Stefan Bauer
10:11 AM Feature #9005: Allow to define allowed x509 client certs by having CN in openvpn server (tls-verify)
Sir, you're awesome! This is exactly what i was looking for! ;) You deserve a cookie!
thank you very much!
Stefan Bauer
10:08 AM Feature #9005: Allow to define allowed x509 client certs by having CN in openvpn server (tls-verify)
You can still do that by making an override named @DEFAULT@ with blocking checked, and then define overrides for the ... Jim Pingle
10:03 AM Feature #9005: Allow to define allowed x509 client certs by having CN in openvpn server (tls-verify)
Your overwrite idea is generally good, but a blacklisting makes no sense in this case. Only whitelisting is secure. W... Stefan Bauer
10:01 AM Feature #9005 (Rejected): Allow to define allowed x509 client certs by having CN in openvpn server (tls-verify)
You can already do this with overrides.
**VPN > OpenVPN**, **Client Specific Overrides** tab. Add a new entry with...
Jim Pingle
09:56 AM Feature #9005 (Rejected): Allow to define allowed x509 client certs by having CN in openvpn server (tls-verify)
We're having enterprise internal CA and imported CA into pfsense. Having a single CA allows all certs that are not re... Stefan Bauer
10:10 AM Bug #8915 (Feedback): After updating to 2.4.4-rc an empty crash report is shown
Applied in changeset commit:6e150fc0d022d231c7dc243ba68f4784f58973d5. Jim Pingle
10:06 AM Bug #8915: After updating to 2.4.4-rc an empty crash report is shown
I just pushed a change that should hopefully take care of this, under the assumption that some mismatch in how index.... Jim Pingle
07:42 AM Bug #8915 (In Progress): After updating to 2.4.4-rc an empty crash report is shown
Jim Pingle
08:54 AM Bug #9004 (Resolved): Default gateway IPv4 set to a group fails after restart on 2.4.4
We set the default gateway IPv4 to be a group, called WAN_Failover. That group consists of WAN1 Fiber at tier 1 and ... Daniel Williams
08:25 AM Bug #8959: Restoring a <2.4.4 config with legacy gold auto backup package re-adds the menu option under Diagnostics
Applied in changeset commit:245bfa559b5d8ebcb13b21feceaa58257ee194da. Anonymous
08:24 AM Bug #8959 (Feedback): Restoring a <2.4.4 config with legacy gold auto backup package re-adds the menu option under Diagnostics
Diagnostics->AutoConfigBackup menu item suppressed Anonymous
08:18 AM Bug #9002 (Resolved): [Interfaces :: WAN :: PPPoE] The service name contains invalid characters
Anonymous
08:16 AM Bug #9002: [Interfaces :: WAN :: PPPoE] The service name contains invalid characters
Steve Beaver wrote:
> Service name may now contain ':' (and other non-alphanumerics)
I just edited the file on my...
Bouke Henstra
07:30 AM Bug #9002: [Interfaces :: WAN :: PPPoE] The service name contains invalid characters
Applied in changeset commit:dac4cd09699bdafa5bcf1cf7b699438e5f669b26. Anonymous
07:27 AM Bug #9002 (Feedback): [Interfaces :: WAN :: PPPoE] The service name contains invalid characters
Service name may now contain ':' (and other non-alphanumerics) Anonymous
06:49 AM Bug #9002: [Interfaces :: WAN :: PPPoE] The service name contains invalid characters
Anonymous
05:43 AM Bug #9002 (Resolved): [Interfaces :: WAN :: PPPoE] The service name contains invalid characters
I am able to add a colon in the "service name" when I configure "PPPoE" using the "Setup Wizard".
I am not able to...
Bouke Henstra
08:05 AM Feature #8943 (Feedback): Additions to wake on lan section
Top buttons are added if the table is > 24 rows
Items 2) and 3) may be addressed in a later release.
Anonymous
07:41 AM Bug #8970 (Feedback): Queues Menu item ends with ":"
Error was in de_DE translation file. Fixed there and in Zanata Anonymous
07:37 AM Bug #8970 (In Progress): Queues Menu item ends with ":"
Anonymous
07:34 AM Bug #8970 (Feedback): Queues Menu item ends with ":"
Anonymous
07:35 AM Bug #8973: Traffic not going to Limiter queues
Far more likely is that it is working properly but just not showing the traffic in the queues in the diagnostic outpu... Jim Pingle
07:32 AM Bug #8995 (Feedback): MTU Trouble with Orange is back
Renato Botelho
06:41 AM Bug #8995: MTU Trouble with Orange is back
mpd5-5.8_8 imported Renato Botelho
06:51 AM pfSense Packages Feature #9003 (Resolved): Add 'Copy Running to Saved' option to the raw config
Would be possible to add these buttons to the raw config page as the Quagga package does, i'm slowly moving over to u... Ben Hughes
01:11 AM Bug #8998: All Captive Portal zones send only "CaptivePortal" as NAS Identifier
Another weight for the first Option: If i Restore a Backup from an old Version (also in case of update) the field is ... Hostmaster BI

10/03/2018

10:24 PM Bug #8999: Nat rules do not work in pfsense 2.4.4 on hypervisor xen
Right. And NAT works just fine on 2.4.4 on AWS. Please take this discussion to the pfSense forum at https://forum.net... Chris Linstruth
09:58 PM Bug #8999: Nat rules do not work in pfsense 2.4.4 on hypervisor xen
Chris Linstruth wrote:
> My entire test VM lab is currently XenServer 6.5. Nothing there changed from 2.4.3_1 to 2.4...
Anonymous
03:24 PM Bug #8999: Nat rules do not work in pfsense 2.4.4 on hypervisor xen
My entire test VM lab is currently XenServer 6.5. Nothing there changed from 2.4.3_1 to 2.4.4 through the entire 2.4.... Chris Linstruth
02:58 PM Bug #8999: Nat rules do not work in pfsense 2.4.4 on hypervisor xen
just think for a moment that it may be the first report. in larger communities i had to make the first report before,... Anonymous
02:17 PM Bug #8999: Nat rules do not work in pfsense 2.4.4 on hypervisor xen
You need to post on the forum and discuss the issue in depth there before jumping to a conclusion that it's a bug and... Jim Pingle
01:59 PM Bug #8999: Nat rules do not work in pfsense 2.4.4 on hypervisor xen
Jim Pingle wrote:
> There is not enough data here to suggest it's actually a problem in pfSense. Please post on the ...
Anonymous
10:24 AM Bug #8999 (Not a Bug): Nat rules do not work in pfsense 2.4.4 on hypervisor xen
There is not enough data here to suggest it's actually a problem in pfSense. Please post on the forum and discuss the... Jim Pingle
10:00 AM Bug #8999 (Not a Bug): Nat rules do not work in pfsense 2.4.4 on hypervisor xen
After upgrading from pfsense 2.4.3_1 to 2.4.4, nat rules in the firewall do not allow packets to pass through.
npt w...
Anonymous
09:24 PM Bug #8973: Traffic not going to Limiter queues
This is weird, but if configuring Limiters with CoDel AQM and QFQ Scheduler, it works. Problems exists with default A... Victor Preatoni
09:06 PM Revision af145b11: Avoid creating or parsing a second empty rrddata tag. Fixes #8994
(cherry picked from commit 9386784480f27d6b04ebf013f691522130a7f013) Jim Pingle
09:04 PM Revision 93867844: Avoid creating or parsing a second empty rrddata tag. Fixes #8994
Jim Pingle
08:20 PM Revision 0fe8d0c7: Fix erroneous hostname error for Custom IPv6. Fixes #8977
(cherry picked from commit 45ff6b8f1d574b3786d25286abc4978427675974) Jim Pingle
08:20 PM Revision 45ff6b8f: Fix erroneous hostname error for Custom IPv6. Fixes #8977
Jim Pingle
08:09 PM Revision 366761ab: Change the method used by status.php to mask sensitive info.
Also add a few new tags to be masked. See Factory #1170
(cherry picked from commit 9858a361b81daa9465e61a93c205bfd98...
Jim Pingle
08:09 PM Revision 9858a361: Change the method used by status.php to mask sensitive info.
Also add a few new tags to be masked. See Factory #1170 Jim Pingle
06:11 PM Bug #8977: Dynamic DNS - Custom (V6) - Throws Error "php-fpm: /services_dyndns_edit.php: phpDynDNS: (ERROR!) No Hostname Provided."
I can provide some feedback, that I manually edited the file in the same manner as the patch on the same day I submit... Rick Coats
03:25 PM Bug #8977 (Feedback): Dynamic DNS - Custom (V6) - Throws Error "php-fpm: /services_dyndns_edit.php: phpDynDNS: (ERROR!) No Hostname Provided."
Applied in changeset commit:45ff6b8f1d574b3786d25286abc4978427675974. Jim Pingle
03:20 PM Bug #8977 (In Progress): Dynamic DNS - Custom (V6) - Throws Error "php-fpm: /services_dyndns_edit.php: phpDynDNS: (ERROR!) No Hostname Provided."
Jim Pingle
04:10 PM Bug #8994 (Feedback): Two RRDDATA Sections in Restored Config Breaks Unit
Applied in changeset commit:9386784480f27d6b04ebf013f691522130a7f013. Jim Pingle
04:06 PM Bug #8994: Two RRDDATA Sections in Restored Config Breaks Unit
The rrddata case is special because of the way the backup process injects the data into the config before serving the... Jim Pingle
12:01 AM Bug #8994: Two RRDDATA Sections in Restored Config Breaks Unit
I don't think this is limited to <rrddata>, any duplicate tag in the config will break imports, I've confirmed with <... Paighton Bisconer
02:34 PM Bug #8995: MTU Trouble with Orange is back
France Orange OK :)
pppoe2: flags=88d1<UP,POINTOPOINT,RUNNING,NOARP,SIMPLEX,MULTICAST> metric 0 mtu 1492
inet 81.2...
xavier Lemaire
11:52 AM Bug #8995: MTU Trouble with Orange is back
Eugene Grosbein - 2 hours ago
Thank you, these logs were very useful. Here is one more patch chunk missing from pr...
xavier Lemaire
05:35 AM Bug #8995: MTU Trouble with Orange is back
pfSense 2.4.4 uses mpd5-5.8_7. You can check that running `pkg info mpd5` on console. The only differences from FreeB... Renato Botelho
12:37 AM Bug #8995 (Resolved): MTU Trouble with Orange is back
As discuss here https://sourceforge.net/p/mpd/bugs/62/?page=1 I have MTU trouble with the last 2.4.4.
Eugene is aski...
xavier Lemaire
02:18 PM pfSense Packages Bug #8997 (Resolved): squidGuard Times does not accept more than one value
Confirmed fixed by other forum users who hit the same issue: https://forum.netgate.com/topic/136288/squidguard-and-mu... Jim Pingle
10:16 AM pfSense Packages Bug #8997 (Feedback): squidGuard Times does not accept more than one value
Fix pushed in squidGuard pkg version 1.16.18_1 which will be up shortly. Jim Pingle
08:49 AM pfSense Packages Bug #8997: squidGuard Times does not accept more than one value
Probably something similar to what I fixed yesterday in ACLs. I'll take a look. Jim Pingle
08:17 AM pfSense Packages Bug #8997 (Resolved): squidGuard Times does not accept more than one value
squidGuard Times does not accept more than one value. (PFSense 2.4.4, squid 0.4.44_5, squidGuard 1.16.18)
On the...
Leonardo Simonato
11:12 AM Bug #8954: hn0: driver does not support altq
Dmitry Ivanov wrote:
> hyper-v 2016
> gen1 and gen2
same here, using windows server 2016 on pfsense 2.4.4
Gustavo Mello
10:21 AM Feature #9001 (Resolved): Add checkbox to disable SSL peer verification for SMTP notifications
Some mail servers do not use a certificate that can be validated by the current code (e.g. custom self-signed CA or c... Jim Pingle
10:06 AM Bug #9000 (Not a Bug): Haproxy does not send ipv6 traffic to backend after updating to Pfsense 2.4.4
After the update, the accesses from ipv6 addresses do not work in any case. Before the update worked perfectly.
Ac...
Anonymous
09:46 AM pfSense Packages Bug #8945: SquidGuard ACL blacklists
I had to make a clean install, but it is working for me as well ! Thanks a lot for your support guys Andres Noriega
07:26 AM pfSense Packages Bug #8945 (Resolved): SquidGuard ACL blacklists
Jim Pingle
01:16 AM pfSense Packages Bug #8945: SquidGuard ACL blacklists
Works again. Thank you Marcel Beerli
12:33 AM pfSense Packages Bug #8945: SquidGuard ACL blacklists
Great Thanks a lot. It works fine in my pfsense Issa Jacaman
09:21 AM Bug #8998 (Resolved): All Captive Portal zones send only "CaptivePortal" as NAS Identifier
Before 2.4.4, each Captive Portal zone had a configurable NAS Identifier. With multiple zones, each instance could us... Jim Pingle
08:00 AM pfSense Packages Bug #8996 (Bogus): pfBlockerNG not like CloudFlare DNS
Jim Pingle
07:57 AM pfSense Packages Bug #8996: pfBlockerNG not like CloudFlare DNS
Sorry - issue already resolved in devel version. DRago_Angel [InV@DER]
04:21 AM pfSense Packages Bug #8996 (Bogus): pfBlockerNG not like CloudFlare DNS
Hi all, pfBlockerNG use IP 1.1.1.1 is list of IPs is NULL, so any time list is null CloudFlare DNS can be banned, fil... DRago_Angel [InV@DER]
07:08 AM Bug #8034: PHP crashes when trying to modify or add NAT rules in pfSense v.2.4.1
I got exactly the same error inside the crash reporter, including the max memory size even if my pfsense machine has ... Sorin Sbarnea
05:31 AM Bug #8935: IGMP Proxy not starting with PPPoE IF
New version merged to 2.4.4 branch Renato Botelho
 

Also available in: Atom