Activity
From 10/18/2018 to 11/16/2018
11/16/2018
-
09:00 PM Bug #9071: Package restore after fresh install can fail, claiming packages do not exist
- Cannot reproduce on oldest or newest available 2.4.x snapshots. Looks like the issue is no longer present.
-
07:50 PM Bug #8512: PPPoE reconnect fails after interface flap
- I think those topics are related.
https://forum.netgate.com/topic/137790/pppoe-client-goes-down-after-any-other-inte... -
07:29 PM Bug #9086 (Resolved): Local Database authentication is failing in other languages
- Replicated in 2.4.4.
Configured CP for auth against local database and added a test user. Changed system language to... -
07:19 PM Bug #9083 (Resolved): Config upgrade issue with empty IPsec P1
- Tested on 2.4.4, was able to reproduce the bad behavior. Tested on 2.4.5.a.20181116.1325 and the behavior could not b...
-
06:19 AM Bug #9083: Config upgrade issue with empty IPsec P1
- On 2.4.5-DEVELOPMENT (amd64) built on Wed Oct 03 17:24:18 EDT 2018 edited config.xml - cut out content between <phase...
-
07:08 PM Bug #9051 (Resolved): Privileges on 'all' group are not being honored
- Tested on 2.4.5.a.20181116.1325
New user with no privileges receives "No page assigned to user"
After adding "W... -
05:53 PM Feature #9062 (Rejected): Add "email notification" when the WAN interface change its public IP
- If you want that, setup dynamic DNS, and it can find the actual public address and notify when it updates.
Otherwi... -
12:55 PM Feature #9062: Add "email notification" when the WAN interface change its public IP
- I am sorry. It was my mistake that I did not describe the request properly.
Some Internet Service Providers are gi... -
03:28 AM Feature #9062: Add "email notification" when the WAN interface change its public IP
- TCI User wrote:
> It would be helpful if an email is send when the WAN interface change its public IP.
> Here is an... -
11:01 AM Bug #9100 (Resolved): CA/Cert valid end dates after 2038 are blank on ARM
-
11:01 AM Bug #9100: CA/Cert valid end dates after 2038 are blank on ARM
- Certificate and CA created with lifetime 7300 which did not properly show the end date in 2.4.4, showed the date fine...
-
10:37 AM Bug #9009: Cannot create Schedule
- Can you create a system patch for this?
-
09:30 AM Bug #8980 (Resolved): Disabling hardware checksums does not disable IPv6 transmit checksum
- Disabling hardware checksums did not disable IPv6 transmit checksum on 2.4.4-RELEASE.
After upgrading to:... -
07:49 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
- HI! After some tests noticed that problem appear only when my "Gateway Group" set as Default gateway
If set WAN1 or ... -
06:38 AM Bug #9128 (Resolved): Descriptive text on rules is incorrect when drag-to-reorder is disabled
- Confirmed on 2.4.4.
Tested:
2.4.5-DEVELOPMENT (amd64)
built on Sat Nov 10 16:12:27 EST 2018
Disabled rule dr... -
06:33 AM Feature #9129 (Duplicate): Notifications Choices
- Duplicate of #4128
-
03:31 AM Feature #9129 (Duplicate): Notifications Choices
- Hey guys
I (and a lot of guys outside the internet) prefer a possibility to have choices in the notifications. Like...
11/15/2018
-
06:48 PM Bug #9121: PHP array reference Cleanup
- Tested on 2.4.5.a.20181114.1947, hit the following php error with a DNS forwarder domain override in place:...
-
10:22 AM Bug #9121 (Resolved): PHP array reference Cleanup
- There have been a number of PHP errors on 2.4.4 as a result of uninitialized arrays being used with references. I've ...
-
03:26 PM Feature #4821 (Closed): PPPoE WANs do not take full advantage of NIC driver queues for receiving traffic
- Added info to the docs about using the sysctl tunable to work around this. There doesn't appear to be anything more w...
-
12:33 PM Feature #9104 (Resolved): Add a FAT32 partition to memstick installer images
-
12:31 PM Feature #9104: Add a FAT32 partition to memstick installer images
- Tested on 2.4.5.a.20181114.2257, works as expected.
-
11:39 AM Bug #9128 (Resolved): Descriptive text on rules is incorrect when drag-to-reorder is disabled
- PR: https://github.com/pfsense/pfsense/pull/3990
Changes header to remove the "Drag to reorder" text when that fea... -
10:50 AM Bug #9123 (Feedback): Adding/configuring vlan on ixl-devices causes aq_add_macvlan err -53, aq_error 14
- The actual vlan addition/configuring process is triggering error "aq_add_macvlan err -53, aq_error 14" on ixl-devices...
-
10:34 AM Feature #9122 (Duplicate): Custom (failover) lagg interface order (UI)
- In latest ui it is not possbile to reorder interfaces for defining a failover-lagg-interface.
FreeBSD uses the first... -
08:52 AM Bug #9086 (Feedback): Local Database authentication is failing in other languages
- I believe this only affects captive portal logins. We were not able to replicate it any other way. Testing that now....
-
08:13 AM Bug #9102 (Resolved): PHP7: Error on restoring a config with packages
- Tested against:
2.4.5-DEVELOPMENT (amd64)
built on Wed Nov 14 19:48:37 EST 2018
No longer seeing that error on ... -
08:00 AM Bug #8465 (In Progress): Lost default gateway after recover from failover with CARP VIP and HA
-
08:00 AM Bug #9029 (Feedback): Proxy authentication is not working for HTTPS
- Imported patch from https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=220468 to fix libfetch
-
07:31 AM Bug #9120: dhcrelay crush with error Unsupported device type 24 for "lo0" but listen another ethernet adapter
- !!
-
07:29 AM Bug #9120 (Rejected): dhcrelay crush with error Unsupported device type 24 for "lo0" but listen another ethernet adapter
- There isn't enough information here to form a valid bug report. Please post on the forum at https://forum.netgate.com...
-
07:29 AM Bug #9120: dhcrelay crush with error Unsupported device type 24 for "lo0" but listen another ethernet adapter
- pfsense 2.4.4-RELEASE (amd64)
-
07:26 AM Bug #9120 (Rejected): dhcrelay crush with error Unsupported device type 24 for "lo0" but listen another ethernet adapter
- Nov 15 15:16:24 dhcpd For info, please visit https://www.isc.org/software/dhcp/
Nov 15 15:16:24 dhcpd All righ... -
06:54 AM Feature #9032 (Resolved): RADIUS MAC Authentication: display the login page when MAC auth failed
-
06:46 AM Feature #9032 (Closed): RADIUS MAC Authentication: display the login page when MAC auth failed
-
06:49 AM Bug #8956 (Resolved): traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
-
06:48 AM Bug #8995 (Resolved): MTU Trouble with Orange is back
-
06:42 AM Bug #9081 (Closed): signed long rollover in "Log file size (Bytes)" can cause self-inflicted DoS
-
06:39 AM Bug #9080 (Closed): firewall_nat_1to1.php: PHP error with empty 1:1 NAT rule list
-
05:20 AM Bug #9119 (Resolved): PHP error from easyrule with no aliases in the config
-
05:14 AM Bug #9119: PHP error from easyrule with no aliases in the config
- 2.4.5-DEVELOPMENT (amd64)
built on Wed Nov 14 23:01:04 EST 2018
On this snap - OK. -
05:01 AM Bug #9119: PHP error from easyrule with no aliases in the config
- That snapshot is from before the fix was committed. Try again on the next snapshot, or gitsync.
-
01:17 AM Bug #9119: PHP error from easyrule with no aliases in the config
- Getting error on 2.4.5-DEVELOPMENT (amd64) built on Wed Nov 14 10:25:41 EST 2018 FreeBSD 11.2-RELEASE-p4:
[2.4.... -
05:08 AM Bug #9071: Package restore after fresh install can fail, claiming packages do not exist
- Nothing special about the setup. The packages are listed in the output in the problem description.
In this case it... -
05:01 AM Bug #9109 (Resolved): interfaces_qinq_edit.php: PHP error when editing QinQ entries
-
01:22 AM Bug #9109: interfaces_qinq_edit.php: PHP error when editing QinQ entries
- Created, edited, assigned QinQ interface - without errors.
11/14/2018
-
05:04 PM Revision 5e0665da: Init various arrays in easyrule before use with references. Fixes #9119
- (cherry picked from commit b55d94e80eeed57e39d33c643bf00be6565c1938)
-
05:04 PM Revision b55d94e8: Init various arrays in easyrule before use with references. Fixes #9119
-
04:25 PM Bug #9071: Package restore after fresh install can fail, claiming packages do not exist
- I did a fresh 2.4.4 recovery install on SG-3100. After restoring config file with installed packages all worked as ex...
-
05:20 AM Bug #9071 (Feedback): Package restore after fresh install can fail, claiming packages do not exist
- Applied in changeset commit:4be5ed9f144a6d93499fdee6e2a50d0edbed8a98.
-
01:54 PM Revision 592bec81: Remove obsolete OLSRD code. Implements #9117
-
11:14 AM Revision db8a42e5: Fix #9071: Make sure pkg metadata is updated when repo config changes
-
11:14 AM Revision 15303d64: Remove unused variable
-
11:14 AM Revision 25e8ca83: Simplify logic to remove packages section from backup
-
11:13 AM Revision 4be5ed9f: Fix #9071: Make sure pkg metadata is updated when repo config changes
-
11:10 AM Bug #9119 (Feedback): PHP error from easyrule with no aliases in the config
- Applied in changeset commit:b55d94e80eeed57e39d33c643bf00be6565c1938.
-
11:03 AM Bug #9119 (Resolved): PHP error from easyrule with no aliases in the config
- When the aliases section of config.xml is empty, easyrule fails with a PHP error:...
-
10:33 AM Revision 220063c4: Remove unused variable
-
10:29 AM Revision 79955411: Simplify logic to remove packages section from backup
-
10:13 AM Revision 83a6f504: Redirect Blocked MAC without requiring credentials if Blocked MAC URL has been entered.
- Redmine #9114
-
08:41 AM pfSense Packages Bug #9118 (Feedback): stunnel does not ensure a newline exists between certificate components
- Fixed in stunnel pkg version 5.47
-
08:39 AM pfSense Packages Bug #9118 (Resolved): stunnel does not ensure a newline exists between certificate components
- stunnel wants the private key, certificate, etc all inside a single file. However, it does not ensure that a newline ...
-
08:00 AM Todo #9117 (Feedback): Clean up old obsolete OLSRD code
- Applied in changeset commit:592bec817f152a7536572a675079776138827cc8.
-
07:52 AM Todo #9117 (Resolved): Clean up old obsolete OLSRD code
- The OLSRD package was removed long ago (not converted to 2.3) and there is still some code around the base system tha...
-
07:45 AM Bug #9114: Captive Portal Blocked MAC Address Redirect URL not working
>
> The reason why this behavior has been updated is that it was quite strange to display an error message before...-
03:59 AM Bug #9114: Captive Portal Blocked MAC Address Redirect URL not working
- Forum link: https://forum.netgate.com/topic/137627/blocked-mac-address-redirect-url-not-working
Well,
It is tr... -
07:12 AM Bug #9116 (Resolved): IPsec VTI routes not applied at boot time when gateway monitoring is disabled
-
02:41 AM Bug #9116: IPsec VTI routes not applied at boot time when gateway monitoring is disabled
- Jim Pingle wrote:
> Applied in changeset commit:ed104a182a95f0ce4e6df76a8c3f0698ff7ce092.
Fix works fine! Tnx! -
05:21 AM Bug #9029 (In Progress): Proxy authentication is not working for HTTPS
11/13/2018
-
10:00 PM Revision 9887b24e: Always configure VTI routes when setting up the interface. Fixes #9116
- (cherry picked from commit ed104a182a95f0ce4e6df76a8c3f0698ff7ce092)
-
09:59 PM Revision ed104a18: Always configure VTI routes when setting up the interface. Fixes #9116
-
07:01 PM Feature #7618: Add support for user-supplied Host-Uniq tag and handle PADM messages in Netgraph PPPoE
- I believe it was accepted.
-
06:24 PM Feature #4821: PPPoE WANs do not take full advantage of NIC driver queues for receiving traffic
- Testing net.isr.dispatch on the NetGate SG-4860 on a 1 Gbps PPPoE connection (each result is averaged across 10 runs)...
-
04:05 PM Bug #9116 (Feedback): IPsec VTI routes not applied at boot time when gateway monitoring is disabled
- Applied in changeset commit:ed104a182a95f0ce4e6df76a8c3f0698ff7ce092.
-
03:59 PM Bug #9116 (Resolved): IPsec VTI routes not applied at boot time when gateway monitoring is disabled
- With gateway monitoring enabled, an interface event kicks off a restart of other scripts which apply the routing and ...
-
01:20 PM Bug #9115 (Resolved): A large number of VLANs causes PHP issues when making an interface change
- I generated a configuration with 250 VLANs (assigned, enabled, with DHCP active) based on a user complaint of problem...
-
07:23 AM Bug #9113: pfsense to google cloud (VTI problem)
- The issue was not properly defined and we need to discuss the issue to find out more about it before jumping straight...
-
07:17 AM Bug #9113: pfsense to google cloud (VTI problem)
- Jim Pingle wrote:
> The only problem here is that your static routes are not present at boot time.
Hi Jim Pingle... -
07:08 AM Bug #9113 (Rejected): pfsense to google cloud (VTI problem)
- It doesn't sound like that has anything at all to do with Google, so the description/subject may be completely inaccu...
-
05:12 AM Bug #9113 (Rejected): pfsense to google cloud (VTI problem)
- Hi,
I created routed/VTI site-to-site vpn from my pfsense box to google cloud (https://cloud.google.com/vpn/docs/h... -
06:41 AM Bug #9114 (Resolved): Captive Portal Blocked MAC Address Redirect URL not working
- Prior to version 2.4.4-RELEASE, devices listed in Captive Portal "MACs" section would never see a login prompt, and d...
-
06:39 AM Bug #9112 (Rejected): hosts corrupted
- That is almost certainly a hardware/disk issue. Most likely the filesystem is corrupt and needs fsck run a few times ...
-
03:16 AM Bug #9112 (Rejected): hosts corrupted
- pfSens 2.4.4
the first 0x2000 bytes of /etc/hosts are filled with Zero!
This happens every couple of weeks.
000... -
05:44 AM Bug #9071 (In Progress): Package restore after fresh install can fail, claiming packages do not exist
11/12/2018
-
07:26 PM Revision 7ae4aa71: Remove outdated 'Gold' reference from README.md
- (cherry picked from commit 360737f6345e376f2de6d2810a1f345a018480e5)
-
07:25 PM Revision 360737f6: Remove outdated 'Gold' reference from README.md
-
07:25 PM Revision 4c1b5d43: Add README.txt for issue #9104
- (cherry picked from commit eb6a022efaa19ce146990e0e4a57e421ddbad8bb)
-
07:25 PM Revision eb6a022e: Add README.txt for issue #9104
-
05:04 PM Revision 5a78cccc: Fix previous regex. Issue #9106
- (cherry picked from commit 16b78f3879bdf658274caf750c9360ec97bb8f77)
-
05:04 PM Revision 16b78f38: Fix previous regex. Issue #9106
-
04:55 PM Revision 57ccb98c: Replace '.' in radius name for strongSwan. Fixes #9106
- (cherry picked from commit cc955fe63ad44b5aac66721e54965d9bc13e990c)
-
04:55 PM Revision cc955fe6: Replace '.' in radius name for strongSwan. Fixes #9106
-
02:37 PM Revision 345ff312: Initialize QinQ arrays before use. Fixes #9109
- (cherry picked from commit 439d9beba0213c96281d8ff6b09ccb8136b1a0aa)
-
02:37 PM Revision 439d9beb: Initialize QinQ arrays before use. Fixes #9109
-
02:27 PM Feature #9111 (Resolved): Add IPsec VTI interface MTU support
- Currently, IPsec VTI interfaces have no special handling for MTU. It is possible to nudge it manually after the syste...
-
01:42 PM Bug #8489 (Feedback): DHCPv6 Client Failure to Initialize with "Do not wait for RA"
- So this is working OK now?
If so, we can close it out, or mark it as a duplicate of #9019 if the root cause was id... -
01:41 PM Bug #8235: The browser must support cookies to login
- Does the same thing happen with an incognito/private mode browser session that has never visited that firewall before...
-
11:53 AM Bug #8235: The browser must support cookies to login
- Scott Phillips wrote:
> I updated pfsense to use secure socket that utilizes port 443 to login as the adminstrator. ... -
11:59 AM Feature #9104 (Feedback): Add a FAT32 partition to memstick installer images
- I've added LICENSE files inside the 36Mb FAT32 partition and changed code to be able to restore a /config.xml of /con...
-
11:05 AM Bug #9106 (Feedback): strongSwan 5.7.1 will not start on some 2.4.4/2.4.5 systems, log shows "charon has quit: integrity test of libstrongswan failed"
- Applied in changeset commit:cc955fe63ad44b5aac66721e54965d9bc13e990c.
-
10:59 AM Bug #9106: strongSwan 5.7.1 will not start on some 2.4.4/2.4.5 systems, log shows "charon has quit: integrity test of libstrongswan failed"
- FYI: The error did not show up in the GUI or logs, but when running @ipsec start@ from the command line, the followin...
-
10:24 AM Bug #9106 (In Progress): strongSwan 5.7.1 will not start on some 2.4.4/2.4.5 systems, log shows "charon has quit: integrity test of libstrongswan failed"
- At least in one case this is due to charon failing to parse a RADIUS server name containing a period. Apparently this...
-
09:24 AM Feature #9110 (Duplicate): Allow custom UDP State timeout setting in Firewall rule
- I request that we finally do the change necessary to fix #1635, that way it would be possible to set a custom state t...
-
08:45 AM Bug #9109 (Feedback): interfaces_qinq_edit.php: PHP error when editing QinQ entries
- Applied in changeset commit:439d9beba0213c96281d8ff6b09ccb8136b1a0aa.
-
08:36 AM Bug #9109 (Resolved): interfaces_qinq_edit.php: PHP error when editing QinQ entries
- When editing QinQ entries on interfaces_qinq_edit.php, a PHP error can occur:...
-
04:50 AM pfSense Packages Bug #8607 (Feedback): Suricata package fails to prune suricata.log
- PR has been merged
-
04:44 AM Bug #9019 (Resolved): Hyper-V hn NICs drop UDP6 traffic when transmit checksums are enabled
11/11/2018
-
06:53 PM pfSense Packages Bug #9108: OpenVPN client without "explicit-exit-notify" does not trigger client-disconnect portion of /usr/local/sbin/openvpn.attributes.sh
- Sorry, forgot the pre tags:...
-
05:48 PM pfSense Packages Bug #9108 (Closed): OpenVPN client without "explicit-exit-notify" does not trigger client-disconnect portion of /usr/local/sbin/openvpn.attributes.sh
- In relation to Feature Request #9805, to avoid overriding the default client-connect/client-disconnect script I reloc...
-
01:55 PM pfSense Packages Bug #8607: Suricata package fails to prune suricata.log
- This problem is addressed by the pull request https://github.com/pfsense/FreeBSD-ports/pull/592 that updates the GUI ...
-
10:13 AM Bug #8489: DHCPv6 Client Failure to Initialize with "Do not wait for RA"
- Matt _ wrote:
> For the original issue,
>
> [...]
>
> seems to fix this, as well as disabling any checksum off... -
10:07 AM Bug #9019: Hyper-V hn NICs drop UDP6 traffic when transmit checksums are enabled
- Renato Botelho wrote:
> FreeBSD r339863 was cherry-picked to RELENG_2_4_4
I updated to the latest snapshot as of ...
11/10/2018
-
05:03 PM Bug #9004: Default gateway IPv4 set to a group fails after restart on 2.4.4
- Daniel Williams wrote:
> This is repeatable.
+1, i have had the same.
Also
https://www.netgate.com/blog/pfsen... -
04:02 AM Bug #7972: Captive portals do not synchronize voucher data in both directions
Renato wrote:
> When voucher is used, disconnected or expired, sync it in both
> directions using HA main infor...
11/09/2018
-
09:12 PM Bug #9105 (Resolved): WebGUI option toggles that need nginx restart are not triggering when disabled
-
09:12 PM Bug #9105: WebGUI option toggles that need nginx restart are not triggering when disabled
- Tested on 2.4.5.a.20181109.1326, works as expected.
-
01:42 PM Bug #9107 (Closed): New AutoConfigBackup - Cannot Access Settings When Not Connected to Internet
- I have a router I had an issue with. I am moving it over to new hardware, because the old hardware does not support ...
-
12:45 PM Bug #9106 (Resolved): strongSwan 5.7.1 will not start on some 2.4.4/2.4.5 systems, log shows "charon has quit: integrity test of libstrongswan failed"
- Some users on 2.4.4 and 2.4.5 snapshots with strongSwan 5.7.1 have found that IPsec is not working.
strongSwan will ... -
10:57 AM Revision dfbf0d5f: Fix #9102: Suppress stream_select() undesired warnings
-
10:56 AM Revision e1a6074d: Fix #9102: Suppress stream_select() undesired warnings
-
09:34 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
- Also i noticed in my case helps when restart openvpn client.
After restart OpenVPN, vpn and other traffic switch bac... -
09:26 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
- Did you try restart service dpinger? In my case this helps switch back to WAN1
-
09:22 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
- Set to trigger level "Packet Loss or High Latency"
I will set trigger level "Member Down" and let you know on monday... -
08:10 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
- @VasylSemenchuk Are your gateway groups set to trigger level "Packet Loss or High Latency" or "Member Down"? Does it ...
-
06:36 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
- The same problem on all my devices (20 devices) after upgrading
-
08:09 AM Bug #9049: IPSec statuspage shows both connected and connecting tunnel
- Ges Ture wrote:
> Since bugnumber 8117 has been served off as not a bug, and no further response is given I'd like t... -
07:28 AM Bug #8001 (Feedback): Invalid FQDN in alias causes alias table to fail *silently*
- Should be fixed by the new filterdns (see #8758 too).
If you have issues, please let us know.
-
07:26 AM Bug #7143 (Feedback): filterdns is triggering every 16 seconds for hosts even when the DNS record has not changed
- Fixed in the new filterdns.
-
07:25 AM Bug #8758 (Feedback): filterdns stops working on a regular basis.
- This issue was one of fixes included in the new filterdns (version 2.0).
If you still have issues, please let us k... -
05:05 AM Bug #9102 (Feedback): PHP7: Error on restoring a config with packages
- Applied in changeset commit:e1a6074dc8918d756a73efc8cf251318b735f000.
-
04:56 AM Bug #9102 (In Progress): PHP7: Error on restoring a config with packages
-
04:57 AM Feature #9104 (In Progress): Add a FAT32 partition to memstick installer images
11/08/2018
-
06:01 PM Revision 98716a68: Fix change detection of GUI web server toggles. Fixes #9105
- (cherry picked from commit 8207fac69158ad4a56deab4a4b4f6f4c3c361b81)
-
06:01 PM Revision 8207fac6: Fix change detection of GUI web server toggles. Fixes #9105
-
02:32 PM Bug #9102: PHP7: Error on restoring a config with packages
-
01:41 PM pfSense Packages Bug #9082 (Resolved): freeradius eap-tls CA validation trying to use fields that may not exist
-
01:30 PM pfSense Packages Bug #9082: freeradius eap-tls CA validation trying to use fields that may not exist
- can confirm. it is working.
-
09:39 AM pfSense Packages Bug #9082 (Feedback): freeradius eap-tls CA validation trying to use fields that may not exist
- Fixed in pkg version 0.15.7
-
09:33 AM pfSense Packages Bug #9082 (In Progress): freeradius eap-tls CA validation trying to use fields that may not exist
- Looks like the config shouldn't put a trailing @/@ on the subject.
Though the more I think about it, I wonder why ... -
08:49 AM pfSense Packages Bug #9082: freeradius eap-tls CA validation trying to use fields that may not exist
it's in the right order :
Auth: tls: Certificate issuer (/C=FR/ST=Ain/L=Jassans-Riottier/O=pfvpn/emailAddress=...-
12:58 PM Feature #8284: Add duplicate option next to OpenVPN servers and clients
- Ivor Kreso wrote:
> It would be very convenient to have a "duplicate" icon next to OpenVPN servers and clients list.... -
12:10 PM Bug #9105 (Feedback): WebGUI option toggles that need nginx restart are not triggering when disabled
- Applied in changeset commit:8207fac69158ad4a56deab4a4b4f6f4c3c361b81.
-
12:00 PM Bug #9105 (Resolved): WebGUI option toggles that need nginx restart are not triggering when disabled
- Some of the option GUI toggles like the WebGUI redirect are supposed to trigger a restart of nginx when they change. ...
-
11:41 AM Bug #9067 (Resolved): PHP error when installing first package with empty installedpackages tag
-
11:21 AM Bug #9067: PHP error when installing first package with empty installedpackages tag
- I've upgraded to:
2.4.5-DEVELOPMENT (ARM)
built on Wed Nov 07 16:23:36 EST 2018
FreeBSD 11.2-RELEASE-p4
Conf... -
10:48 AM pfSense Packages Todo #9041: update ntopng 3.6.0
- ntopng appears to have removed all of that code. It went from enable-flow-activity to enable-flow-scripts to enable-u...
-
10:28 AM pfSense Packages Todo #9041: update ntopng 3.6.0
- Jim Pingle wrote:
> The activity map is not relevant to this ticket, only the version, which appears to be OK.
>
... -
10:17 AM pfSense Packages Todo #9041 (Resolved): update ntopng 3.6.0
- The activity map is not relevant to this ticket, only the version, which appears to be OK.
FYI: ntopng disabled th... -
12:55 AM pfSense Packages Todo #9041: update ntopng 3.6.0
- On 2.4.5-DEVELOPMENT (arm) built on Mon Nov 05 15:36:37 EST 2018 FreeBSD 11.2-RELEASE-p4:
I don't see activity map o... -
09:57 AM Feature #9104 (Resolved): Add a FAT32 partition to memstick installer images
- Adding a FAT32 partition on the installer image, as we have on ARM recovery images currently, means:
* We can drop... -
08:48 AM Bug #9099 (Resolved): system_certmanager.php: Empty cert tag can lead to PHP error
-
05:47 AM Bug #9010 (Resolved): Captive Portal Unable to logout
-
05:37 AM Bug #9010: Captive Portal Unable to logout
- Seems good to me. This issue be marked as resolved.
-
05:36 AM Feature #9032: RADIUS MAC Authentication: display the login page when MAC auth failed
- Jane Doe wrote:
> The fall back seems not to respect the setting *Use custom captive portal page* as it always shows... -
04:49 AM Bug #9048 (Not a Bug): Installer memsticks using GPT should always have partition count that is a multiple of 4
- This but only applies to installer image, not to installed system. Our memstick installer image uses MBR since May, w...
-
04:21 AM Bug #9048 (In Progress): Installer memsticks using GPT should always have partition count that is a multiple of 4
-
03:40 AM Bug #9086 (Resolved): Local Database authentication is failing in other languages
11/07/2018
-
11:51 PM Bug #9099: system_certmanager.php: Empty cert tag can lead to PHP error
- On 2.4.5-DEVELOPMENT (arm) Mon Nov 05 15:36:37 EST 2018 FreeBSD 11.2-RELEASE-p4:
Created a test cert, then opened... -
11:34 PM Bug #9086: Local Database authentication is failing in other languages
- On 3100 2.4.5-DEVELOPMENT (arm) сделан Mon Nov 05 15:36:37 EST 2018 changed language to Russian, then logged out and ...
-
08:38 PM Bug #8465: Lost default gateway after recover from failover with CARP VIP and HA
- I'm having the exact same issue with 2.4.4. Using IPs outside the WAN-VIP subnet on the WAN interfaces forces the d...
-
08:37 PM Revision 17dfb092: Add 0.0.0.0/0 to VTI left/rightsubnets. Fixes #8859
- No negative feedback from testing, time for a wider push.
This helps with third party devices that require 0.0.0.0/0... -
08:36 PM Revision 5c4aa94a: Add 0.0.0.0/0 to VTI left/rightsubnets. Fixes #8859
- No negative feedback from testing, time for a wider push.
This helps with third party devices that require 0.0.0.0/0... -
08:31 PM Revision 0b76ff3b: Add checkbox to disable SMTP SSL cert verification. Implements #9001
- The default action is to validate the certificate. If the user knows the
server does not have a valid certificate (e.... -
08:30 PM Revision 7da466e1: Add checkbox to disable SMTP SSL cert verification. Implements #9001
- The default action is to validate the certificate. If the user knows the
server does not have a valid certificate (e.... -
04:22 PM pfSense Packages Bug #9082: freeradius eap-tls CA validation trying to use fields that may not exist
- Seems like the order in which cert fields are presented is also an issue. Still getting error despite matching exactl...
-
03:00 PM pfSense Packages Bug #9082 (Feedback): freeradius eap-tls CA validation trying to use fields that may not exist
- Fixed in pkg version 0.15.6.
Fields left blank will not be added to the subject to validate.
If someone was rel... -
02:45 PM Bug #8859 (Feedback): VTI: Some third-party vendors require rightsubnet to have a mask for VTI, rather than address
- Applied in changeset commit:5c4aa94a90256b13b19209f11e4c75b2d0e85ece.
-
02:40 PM Feature #9001 (Feedback): Add checkbox to disable SSL peer verification for SMTP notifications
- Applied in changeset commit:7da466e1c4b6873b9fb80e862faf8f799a6d4531.
-
12:56 PM Bug #8961 (Duplicate): IPSEC issues with Asynchronous Cryptography
- Duplicate of #8964 (it came later, but has more detail and comments with additional info)
-
12:27 PM Bug #9059 (Resolved): Update Unbound to 1.8.1
- This was picked back to 2.4.4 last week. Looks good, no complaints or errors encountered.
-
10:23 AM Bug #9094: MBT console settings are not forced to video console
- Looks like that might be something in FreeBSD but needs more research. It doesn't seem to matter if @console="efi,com...
-
07:21 AM pfSense Docs Correction #9103 (Rejected): Feedback on Routing — Routing Public IP Addresses
- In that case, it is NOT a routed setup, so the document is not relevant to what the user is doing.
-
07:11 AM pfSense Docs Correction #9103 (Rejected): Feedback on Routing — Routing Public IP Addresses
- *Page:* https://www.netgate.com/docs/pfsense/book/routing/routing-public-ip-addresses.html
*Feedback:*
If the u...
11/06/2018
-
06:20 PM Revision 84b70d69: If the cert date is negative, use DateTime instead of date. Fixes #9100
- (cherry picked from commit 3fec247042a91642a22a8761d3c8a1f9df119817)
-
06:19 PM Revision 3fec2470: If the cert date is negative, use DateTime instead of date. Fixes #9100
-
05:48 PM Revision e5e2ea27: Prevent CRL from using too large a lifetime on ARM. Fixes #9098
- (cherry picked from commit 9aa8f6a864905c0e3738c337a51f0772b0c5eb93)
-
05:47 PM Revision 9aa8f6a8: Prevent CRL from using too large a lifetime on ARM. Fixes #9098
-
04:38 PM Revision 04e1a5d3: Improve handling of empty cert tags. Fixes #9099
- (cherry picked from commit ca4456b95c53e89cf6b428a999ae15367b753073)
-
04:38 PM Revision ca4456b9: Improve handling of empty cert tags. Fixes #9099
-
02:37 PM Bug #9102 (Resolved): PHP7: Error on restoring a config with packages
- Tested against:
2.4.5-DEVELOPMENT (amd64)
built on Tue Nov 06 11:45:54 EST 2018
After restoring a config with p... -
02:12 PM Bug #9095 (Resolved): PHP error when saving logs with empty syslog tag
- Tested against:
2.4.5-DEVELOPMENT (amd64)
built on Tue Nov 06 11:45:54 EST 2018
Repeated above steps. Log setti... -
02:03 PM Bug #9101 (New): Traffic Graphs/Dashboard Slows Downloads Being Performed by the Same Firefox Browser
- Based on a forum post I performed some testing.
If I started a download in Firefox then used the same Firefox brow... -
01:46 PM Bug #9094 (Assigned): MBT console settings are not forced to video console
- The console order appears to be correctly forced:...
-
01:14 PM Bug #8978 (Resolved): vidconsole is invalid for efi booted systems
- Tested against:
2.4.5-DEVELOPMENT (amd64)
built on Tue Nov 06 11:45:54 EST 2018
With serial console enabled loa... -
12:25 PM Bug #9100 (Feedback): CA/Cert valid end dates after 2038 are blank on ARM
- Applied in changeset commit:3fec247042a91642a22a8761d3c8a1f9df119817.
-
11:50 AM Bug #9100 (Resolved): CA/Cert valid end dates after 2038 are blank on ARM
- In the CA and Cert lists, if an entry has a valid end date after the UNIX timestamp signed 32-bit int rollover time i...
-
12:00 PM Bug #9098 (Feedback): Default CRL lifetime of 9999 rolls over at 2038 on ARM
- Applied in changeset commit:9aa8f6a864905c0e3738c337a51f0772b0c5eb93.
-
11:50 AM Bug #9098: Default CRL lifetime of 9999 rolls over at 2038 on ARM
- CA and Certs get the correct/expected end date in the data, but the GUI doesn't show the dates. Moved that to #9100
-
11:42 AM Bug #9019 (Feedback): Hyper-V hn NICs drop UDP6 traffic when transmit checksums are enabled
- FreeBSD r339863 was cherry-picked to RELENG_2_4_4
-
11:22 AM pfSense Packages Bug #8607: Suricata package fails to prune suricata.log
- I also got hit by this now when trying to open suricata.log. The crashing suricata.log file was 103MB. Suricata.log o...
-
10:45 AM Bug #9099 (Feedback): system_certmanager.php: Empty cert tag can lead to PHP error
- Applied in changeset commit:ca4456b95c53e89cf6b428a999ae15367b753073.
-
10:37 AM Bug #9099 (Resolved): system_certmanager.php: Empty cert tag can lead to PHP error
- If the config.xml contains an empty certificate (@<cert></cert>@) it leads to a PHP error when attempting to add a ne...
-
08:56 AM pfSense Packages Bug #8491 (Resolved): ACME: DNS-Luadns not working
-
08:51 AM pfSense Packages Bug #8491: ACME: DNS-Luadns not working
- Problem is solved.
-
08:36 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
- With the Gateway Group set to "Packet Loss or High Latency" this problem definitely shows up much more often.
-
04:10 AM Bug #9058: Kernel panic during L2TP retransmit
- This seems to be an upstream bug in FreeBSD mpd5 - today I got the same crash on my L2TP Server (FreeBSD 11.2-RELEASE...
11/05/2018
-
08:48 PM Bug #8590 (Resolved): sshd does not allow agent forwarding
- Verified that the checkbox toggles the AllowAgentForwarding in sshd_config and that agent forwarding is both enabled ...
-
08:11 PM Revision 64c98886: Prevent log size from being too large, which breaks clog. Fixes #9081
- (cherry picked from commit 8bd36425b4bc46e5bbcc940a4d20bfbb2a0011ba)
-
08:11 PM Revision 8bd36425: Prevent log size from being too large, which breaks clog. Fixes #9081
-
07:58 PM Revision 5dea6c81: Prevent PHP error when saving log config. Fixes #9095
- (cherry picked from commit 4c4e294b0f1523827fa21066521674a435c8f670)
-
07:57 PM Revision 4c4e294b: Prevent PHP error when saving log config. Fixes #9095
-
06:51 PM Revision 7f40e4a9: Make MBT prefer video console. Fixes #9094
- Avoids foot-shooting by restoring a config with serial enabled.
(cherry picked from commit 5e5df38fcd3116c4d0f3fc716... -
06:51 PM Revision 2887721c: Use EFI console when needed. Fixes #8978
- (cherry picked from commit 2f73f2f9eca656c2de5b836f4d0292186147e788)
-
06:31 PM Revision 5e5df38f: Make MBT prefer video console. Fixes #9094
- Avoids foot-shooting by restoring a config with serial enabled.
-
06:30 PM Revision 2f73f2f9: Use EFI console when needed. Fixes #8978
-
03:22 PM Bug #9098 (Resolved): Default CRL lifetime of 9999 rolls over at 2038 on ARM
- The default lifetime on a CRL is 9999 days, which currently puts it expiring in 2046. On ARM, this seems to lead to a...
-
02:50 PM Bug #9081: signed long rollover in "Log file size (Bytes)" can cause self-inflicted DoS
- That'll do. I mean, other than actually fixing clog. But that is a whole other ball of wax and just another reason ...
-
02:20 PM Bug #9081 (Feedback): signed long rollover in "Log file size (Bytes)" can cause self-inflicted DoS
- Applied in changeset commit:8bd36425b4bc46e5bbcc940a4d20bfbb2a0011ba.
-
02:36 PM Bug #9097 (Resolved): ECL can't locate config.xml unless device is MBR-partitioned
- Follow-on to #9089, but this one needs to be fixed in code, IMHO:
* GPT devices show up as da1p1, not da1s1, so ca... -
02:20 PM Bug #9095 (Feedback): PHP error when saving logs with empty syslog tag
- Applied in changeset commit:4c4e294b0f1523827fa21066521674a435c8f670.
-
01:55 PM Bug #9095 (Resolved): PHP error when saving logs with empty syslog tag
- If config.xml contains no log settings, but has an empty syslog section (@<syslog></syslog>@) this can lead to a PHP ...
-
02:17 PM Feature #9096 (Resolved): Login Page: Make pfSense Login Page Tab Name More Unique
- Currently, the tab name (i.e., the name that appears in the tab in Google Chrome and other browsers) for pfSense's Lo...
-
01:17 PM pfSense Docs Correction #9089 (Resolved): ECL can't locate config.xml unless USB device is partitioned
- Fixed.
-
01:00 PM Bug #9094 (Feedback): MBT console settings are not forced to video console
- Applied in changeset commit:5e5df38fcd3116c4d0f3fc71622643e962f982a8.
-
10:06 AM Bug #9094 (Assigned): MBT console settings are not forced to video console
- We have code in source:src/etc/inc/pfsense-utils.inc#L1226 that checks for the MBT models and sets @$hdmi_only@ but t...
-
01:00 PM Bug #8978 (Feedback): vidconsole is invalid for efi booted systems
- Applied in changeset commit:2f73f2f9eca656c2de5b836f4d0292186147e788.
-
11:34 AM Bug #8980 (Feedback): Disabling hardware checksums does not disable IPv6 transmit checksum
- Fixed in php-pfSense-module 0.65
-
07:15 AM Bug #9093 (Not a Bug): Blank Parent Interfaces while creating LAGG
- If all of your interfaces are assigned, none are free to be added to a lagg. This is normal and not a bug. Post on th...
-
06:07 AM Bug #9093 (Not a Bug): Blank Parent Interfaces while creating LAGG
- Hi Team,
I am using 2.4.4 physical and 2.4.3 on a VM, while creating a new LAGG I see that the Parent Interfaces s... -
04:23 AM Todo #8898 (Resolved): Update strongswan to 5.7.1
11/04/2018
-
03:16 PM Feature #9092 (Resolved): Option to set interval of forced Dynamic DNS updates
- I use dy.fi dynamic DNS service. It requires refreshing the IP every 7 days (even if it does not change) or it is rel...
-
03:07 PM Feature #9091 (Resolved): Chelsio TOE support using the ``t4_tom`` module
- Please add t4_tom.ko to the kernel so Chelsio cards TOE functionality can be enabled as discussed on this forum post ...
11/03/2018
- 11:31 PM Revision 2dd0ba04: Update src/usr/local/www/vendor/d3/d3.min.js
- Restored d3.min.js
-
06:29 PM Bug #9066 (Resolved): ecl.php: Checking /config path is not working due to lack of trailing slash
- Tested on pfSense-CE-memstick-ADI-2.4.5-DEVELOPMENT-amd64-20181103-0458, works as expected (config.xml in /config/ on...
-
08:13 AM Bug #9090 (Duplicate): Traffic graph widget mouse over always shows b/s even when the value is in B/s
- The other issue is still open. This is not necessary.
-
02:19 AM Bug #9090 (Duplicate): Traffic graph widget mouse over always shows b/s even when the value is in B/s
- As the description, the mouse over display is always shown as b/s regardless on the bits/Bytes setting.
Same as Bug ... -
02:04 AM Bug #8377: Traffic graph widget mouse over always shows b/s even when the value is in B/s
- Bug still present on 2.4.4
11/02/2018
-
04:39 PM pfSense Docs Correction #9089 (Resolved): ECL can't locate config.xml unless USB device is partitioned
- The glob() pattern in source:src/etc/ecl.php#L40 's get_disk_slices() implicitly limits the function to finding confi...
-
04:23 PM Bug #9061 (Resolved): PowerD command parameter validation and escaping
-
04:23 PM Bug #9061: PowerD command parameter validation and escaping
- Could recreate the behavior on 2.4.4. On 2.4.5.a.20181102.0213, could not reproduce the behavior, received ...
-
03:31 PM Feature #9088: Indication of package upgrades in dashboard widget “System Information”
- Jim Pingle wrote:
> There is a packages widget that checks for package updates. It won't be added to the main system... -
03:24 PM Feature #9088 (Rejected): Indication of package upgrades in dashboard widget “System Information”
- There is a packages widget that checks for package updates. It won't be added to the main system information widget.
... -
03:23 PM Feature #9088 (Rejected): Indication of package upgrades in dashboard widget “System Information”
- It would be very helpful if the ”System Information” widget could indicate if packages need to be updated. Currently ...
-
03:09 PM Todo #8898: Update strongswan to 5.7.1
- On 2.4.5.a.20181102.0213, strongswan version is 5.7.1.
-
03:06 PM Todo #9026: PTI checkbox wording can be confusing, should give a little more detail and show current PTI status
- Corey Boyle wrote:
> Why even have the option to disable PTI?
The user may have a use case where the original pro... -
03:05 PM Todo #9026: PTI checkbox wording can be confusing, should give a little more detail and show current PTI status
- Why even have the option to disable PTI?
-
03:05 PM Bug #8864 (Resolved): SSH Guard Sensitivity/Whitelist on 2.4.4
-
03:04 PM Bug #8864: SSH Guard Sensitivity/Whitelist on 2.4.4
- On 2.4.5.a.20181102.0213, works as expected. Address(es) added to the whitelist are not subject to SSH Guard detection.
-
12:50 PM Bug #7869: Hyper-v vm traffic shaper error: hn0: driver does not support altq
- altq regressed to broken in hyper-v in 2.4.4, but this is fixed already per this bug report:
https://redmine.pfsense... -
12:29 PM Bug #8954: hn0: driver does not support altq
- In case anyone has already upgraded to 2.4.4 and wants to workaround the issue without waiting for a patch or downgra...
-
11:26 AM Bug #8954 (Resolved): hn0: driver does not support altq
-
11:14 AM Bug #8954: hn0: driver does not support altq
- The fix Renato pushed yesterday has fixed the issue! Traffic shaper starts up no problem now.
Looks like the firs... -
10:47 AM Feature #8946: Add field to show IA_PD to DHCP6 Server page
- Set it to Future until a new patch is submitted
-
10:26 AM Bug #9086 (Feedback): Local Database authentication is failing in other languages
11/01/2018
-
11:51 PM Bug #9087 (New): Traffic Graph Widget Legend Not Updating
- This issue was first posted to the Netgate Forums, but no solution was posted.
The traffic graph widget shows a le... -
08:45 PM Revision 307ee672: Fix 9086: Remove gettext() from all 'Local Databases' strings
-
08:45 PM Revision 296c16bd: Fix 9086: Remove gettext() from all 'Local Databases' strings
-
08:42 PM Revision a7b0d338: Update translation files
-
08:42 PM Revision 58bf585e: Regenerate pot
-
08:41 PM Revision d5b70264: Update translation files
-
08:41 PM Revision 840494c0: Regenerate pot
-
04:05 PM Bug #8954 (Feedback): hn0: driver does not support altq
- I pushed a fix on FreeBSD-src. Please try next round of 2.4.5 snapshots
-
03:06 PM Bug #8954: hn0: driver does not support altq
- I've created a new "System Tunable" with : hw.hn.use_if_start with value of 1 Then rebooted the VM.
Output of s... -
12:01 PM Bug #8954: hn0: driver does not support altq
- Ben T wrote:
> On psense 2.4.4 running as vm gen2 on windows 10 build 1803 Hyper-V, the output of the command: (scre... -
10:51 AM Bug #8954: hn0: driver does not support altq
- On psense 2.4.4 running as vm gen2 on windows 10 build 1803 Hyper-V, the output of the command: (screenshot also atta...
-
09:45 AM Bug #8954 (In Progress): hn0: driver does not support altq
-
09:21 AM Bug #8954: hn0: driver does not support altq
- Jon Gav wrote:
> > hyper-v 2016
> > gen1 and gen2
>
> Issue persistent in 2.4.5.development as well
can you p... -
03:45 PM Bug #9086 (Resolved): Local Database authentication is failing in other languages
- A user reported this problem on a pt_BR group. After changing language it stopped working. I noted it is storing tran...
-
08:44 AM Bug #9064: voucher to device binding
- Jim Pingle wrote:
> If you add a pass-through MAC, the time on the voucher is irrelevant. Don't set it that long.
... -
08:35 AM Bug #9064: voucher to device binding
- If you add a pass-through MAC, the time on the voucher is irrelevant. Don't set it that long.
-
08:06 AM Bug #9064: voucher to device binding
- Jim Pingle wrote:
> If the voucher adds a pass-thru MAC, then you could also make the voucher only last 1 minute. Sm... -
08:03 AM Bug #9064: voucher to device binding
- A FL wrote:
> This is actually not a bug.
>
> If the MAC address of the previous computer has been added as pass-... -
07:06 AM Bug #9064: voucher to device binding
- If the voucher adds a pass-thru MAC, then you could also make the voucher only last 1 minute. Smaller window for abus...
-
05:08 AM Bug #9064: voucher to device binding
- This is actually not a bug.
If the MAC address of the previous computer has been added as pass-through, "Disable c... -
08:07 AM pfSense Packages Todo #9041: update ntopng 3.6.0
- json-c upgrade was not necessary since we don't have plans to import a new quarterly to 2.4.4 branch.
-
08:07 AM pfSense Packages Todo #9041 (Feedback): update ntopng 3.6.0
-
07:36 AM Todo #8898 (Feedback): Update strongswan to 5.7.1
- Both 5.7.0 and 5.7.1 commits were cherry-picked to 2.4.4 branch
-
07:09 AM Bug #9058: Kernel panic during L2TP retransmit
- yes it's always the same (except the hex addresses)...
-
07:07 AM Bug #9058 (New): Kernel panic during L2TP retransmit
- OK, and is the backtrace in the crash report always the same?
I have not seen a recurrence of this on my local set... -
04:18 AM Bug #9058: Kernel panic during L2TP retransmit
- Thanks for waiting. My pfsense crashed two times in the last two days. From the monitoring (telegraf, 300s interval) ...
- 05:17 AM Revision 125ae17e: Update src/usr/local/www/vendor/d3/d3.min.js
- make sure to only pass valid options when supported by the browser
- 04:33 AM Revision 36742b46: Removed js warnings
10/31/2018
-
09:13 PM pfSense Packages Feature #9085 (New): OpenVPN connect/disconnect scripts
- I'm running pfSense 2.4.4 and the Windows openVPN 2.4.6 client.
I was trying to get the openVPN server to log *use... - 05:07 PM Revision e65a15e4: Add help text to sshguard whitelist
- Reduce delete button size
Change label text to "Add address"
(cherry picked from commit 5514e368421171482e3e5b945f4c... -
04:59 PM Revision 1f7ea9ce: Skip empty IPsec P1 during upgrade to 17.5. Fixes #9083
- (cherry picked from commit 024e5de242661219bb8a62f183b1601cec44aa3c)
-
04:59 PM Revision 024e5de2: Skip empty IPsec P1 during upgrade to 17.5. Fixes #9083
- 02:34 PM Revision 5514e368: Add help text to sshguard whitelist
- Reduce delete button size
Change label text to "Add address" -
12:19 PM Revision 087a1f6b: Fix #8864: Let users modify sshguard parameters and whitelist
-
12:19 PM Revision ef4a242c: Fix #8864: Let users modify sshguard parameters and whitelist
-
12:10 PM Bug #9083 (Feedback): Config upgrade issue with empty IPsec P1
- Applied in changeset commit:024e5de242661219bb8a62f183b1601cec44aa3c.
-
09:02 AM Bug #9083 (Resolved): Config upgrade issue with empty IPsec P1
- An older configuration will fail to upgrade with an incomplete or empty IPsec Phase 1 section:...
-
11:27 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
- The Gateway Group was set as Trigger Level: Packet Loss or High Latency. I changed that to "Member Down" and now the...
-
11:09 AM Bug #9084 (Duplicate): PHP crash after deleting NAT 1:1 rule
- Duplicate of #9080 which is already fixed in the repo.
-
10:45 AM Bug #9084 (Duplicate): PHP crash after deleting NAT 1:1 rule
- There was only one rule on the NAT 1:1 list. After deleting it the the crash occurred. This happened several times an...
-
07:25 AM Bug #8864 (Feedback): SSH Guard Sensitivity/Whitelist on 2.4.4
- Applied in changeset commit:ef4a242c0df1b69b3348997165afc8555471202c.
10/30/2018
-
10:15 PM pfSense Packages Bug #9082 (Resolved): freeradius eap-tls CA validation trying to use fields that may not exist
- This issue is reproduced in this thread: https://forum.netgate.com/topic/137168/freeradius-ca-validation-broken-2-4-5...
-
02:24 PM Revision f989b4f6: Array initialization in NAT pages. Fixes #9080
- (cherry picked from commit 42ad3b8b51e12b9e4c89b94e2a191495318f42dc)
-
02:24 PM Revision 42ad3b8b: Array initialization in NAT pages. Fixes #9080
- 02:18 PM Revision f5c56bf8: Fix issue where Alias URL lists are not correctly stored
-
10:16 AM Bug #9081: signed long rollover in "Log file size (Bytes)" can cause self-inflicted DoS
- That certainly sounds fun. I'll have a look.
-
10:14 AM Bug #9081 (Closed): signed long rollover in "Log file size (Bytes)" can cause self-inflicted DoS
- Values between 2147483648 and 4294967295 and cause fire-y disk-full death at the hands of @clog -i -s@
-
09:30 AM Bug #9080 (Feedback): firewall_nat_1to1.php: PHP error with empty 1:1 NAT rule list
- Applied in changeset commit:42ad3b8b51e12b9e4c89b94e2a191495318f42dc.
-
09:02 AM Bug #9080 (In Progress): firewall_nat_1to1.php: PHP error with empty 1:1 NAT rule list
-
09:02 AM Bug #9080 (Closed): firewall_nat_1to1.php: PHP error with empty 1:1 NAT rule list
- ...
-
09:23 AM pfSense Packages Bug #9079: High CPU usage of ntopng even during IDLE and no network traffic
- It's not clear there is anything we can do at all here. This is most likely an issue in ntopng itself, not something ...
-
09:22 AM pfSense Packages Bug #9079: High CPU usage of ntopng even during IDLE and no network traffic
- TOP shows that the ntopng process is in the only one in nanslp (nanosleep) mode if this helps.
-
08:58 AM pfSense Packages Bug #9079 (Closed): High CPU usage of ntopng even during IDLE and no network traffic
- With pfSense version 2.4.4 and the usage of ntopng package the CPU is constantly on a high load.
Reducing ntopng tas... -
09:21 AM Bug #9074: Alias URL lists only storing last-most list in config.
- Submitted pull request:
https://github.com/pfsense/pfsense/pull/4002 -
07:52 AM Bug #9059 (In Progress): Update Unbound to 1.8.1
- Cherry picked a270651cc45b428b5f8167d1d533c50e5ee958c2 to devel. If it's OK on 2.4.5 we can consider picking it back ...
10/29/2018
-
02:13 PM Feature #9078 (Resolved): Investigate adding knobs for explicit-exit-notify in OpenVPN
- explicit-exit-notify looks like it can greatly speed up recovery time on OpenVPN process restarts and potentially HA ...
-
12:18 PM Revision c6b4e293: Revert "Build textproc/jq, asked by BBcan177"
- This reverts commit 2e618c0d285a242b8cc8004f0907ddbb227ecfe9.
-
09:13 AM Feature #9032: RADIUS MAC Authentication: display the login page when MAC auth failed
- The fall back seems not to respect the setting *Use custom captive portal page* as it always shows the default login ...
-
07:59 AM Bug #9074: Alias URL lists only storing last-most list in config.
- There still appeared to be some odd behaviour with the change I did above where it was not always appending the array...
-
06:29 AM Bug #9075 (Not a Bug): Firewall rules with aliases are not applied in upgraded 2.4.4
- There is not enough detail here to reproduce or identify a problem. Aliases are working fine in lab and production se...
-
04:06 AM Bug #9075 (Not a Bug): Firewall rules with aliases are not applied in upgraded 2.4.4
- HI,
I have an upgraded pfsense from 2.4.3 to 2.4.4 and then all the firewall rules with aliases are not applied co... -
06:25 AM Bug #9076 (Not a Bug): DHCP RENEW PROBLEM
- This needs discussion on the forum. It's working fine for thousands and thousands of installs. If there is an issue h...
-
04:44 AM Bug #9076 (Not a Bug): DHCP RENEW PROBLEM
- Hello,
Since two weeks we have a problem on our DHCP Server with dhcp adress renew on our clients.
All 24 hours, ... -
06:06 AM pfSense Packages Feature #9077 (New): haproxy UI: Add seperator lines
- When having lots of ACL rules and action rules it would be nice if it was possible to insert seperator lines with a n...
10/28/2018
-
09:18 PM Bug #9056 (Resolved): DNS search domain omitted in some cases
-
08:43 PM Bug #9056: DNS search domain omitted in some cases
- Looks good here. Thanks.
-
09:18 PM Bug #9055 (Resolved): IKEv2 EAP Identity vs client ID matching for per-client settings with local users
-
08:48 PM Bug #9055: IKEv2 EAP Identity vs client ID matching for per-client settings with local users
- Works as expected. Thank you.
-
07:45 AM Bug #9074 (Resolved): Alias URL lists only storing last-most list in config.
- When creating an Alias URL list under Firewall->Aliases->URLs, only the IP's from the last-most URL in the list is wh...
10/27/2018
-
01:35 PM Bug #9073: "private-domain" in custom options results in invalid config (syntax error)
- Thanks, Jim! It didn't occur to me that the @server@ block could be specified twice. Can confirm the config now che...
-
01:21 PM Bug #9073 (Not a Bug): "private-domain" in custom options results in invalid config (syntax error)
- With custom options it is up to the user to ensure the config is in the correct section of the config. For example in...
-
01:21 PM Bug #9073: "private-domain" in custom options results in invalid config (syntax error)
- Ahah, I think the actual issue is that *Custom options* are being after the @forward-zone@ directive, which means the...
-
01:16 PM Bug #9073 (Not a Bug): "private-domain" in custom options results in invalid config (syntax error)
- Adding the following to the DNS Resolver *Custom options* field:...
-
08:18 AM Bug #9058 (Feedback): Kernel panic during L2TP retransmit
- OK, we'll wait for some more feedback here to see what happens.
-
05:46 AM Bug #9058: Kernel panic during L2TP retransmit
- After a few more crashes with different error messages, I ran a memory test, which showed errors. RAM is replaced and...
10/26/2018
-
11:51 AM Bug #8937 (New): LAGG shows wrong ether address
- From a quick look at utils.inc:get_interface_list() this would require the addition of some logic;
if $IFACE is me... -
09:37 AM Bug #8937 (In Progress): LAGG shows wrong ether address
-
10:42 AM Bug #9072 (Resolved): RRD graph mouseover information shows up as Mb when unit size is set to MB
- The dashboard traffic graph widget shows mouse over information in Mb when the unit size is set to MB
-
09:36 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
- To make things even more complicated, in the workaround mentioned above, the routing actually changes back to the Tie...
-
09:11 AM Bug #9071 (Resolved): Package restore after fresh install can fail, claiming packages do not exist
- Tested on a fresh SG-1000 and SG-3100 after a recovery install and then config restore. In both cases, no packages we...
-
05:27 AM Bug #8954: hn0: driver does not support altq
- > hyper-v 2016
> gen1 and gen2
Issue persistent in 2.4.5.development as well
10/25/2018
-
07:40 PM Revision b77f0bf1: Initialize package arrays before use. Fixes #9067
- (cherry picked from commit bfd3334b4bc9ae0d3c43f69e8305c83b0da3aa58)
-
07:40 PM Revision bfd3334b: Initialize package arrays before use. Fixes #9067
-
07:00 PM Bug #9070 (Feedback): After performing in-place upgrade from 2.4.3-RELEASE-p1 to 2.4.4 DHCPV6 client fails to retireve a WAN address
- Sounds like symptoms that others saw when using Hyper-V.
If you are using Hyper-V then this is a duplicate of #9019 -
06:15 PM Bug #9070 (Closed): After performing in-place upgrade from 2.4.3-RELEASE-p1 to 2.4.4 DHCPV6 client fails to retireve a WAN address
- I upgraded my system a few days ago and realized last night that the hosts were no longer receiving IPV6 addresses. ...
-
06:58 PM Bug #9069 (Duplicate): Config import not validated properly
- Duplicate of #8994 which is already fixed for 2.4.4-p1.
-
05:56 PM Bug #9069 (Duplicate): Config import not validated properly
- I just imported a config file generated on another pfsense host onto a fresh install. Somehow that file ended up cont...
-
06:24 PM Revision 0fd2dd09: Add trailing slash to ECL check path for /config/. Fixes #9066
- (cherry picked from commit c688c59b47a3ce138ffe094794d01f1e6fcc00df)
-
06:24 PM Revision c688c59b: Add trailing slash to ECL check path for /config/. Fixes #9066
-
04:18 PM Bug #9068 (Rejected): Exported configuration contains string at the end that should not be there
- I can't reproduce this here at all on 2.4.4 or 2.4.5 snapshots.
It may be specific to the combination of OS+Browse... -
04:13 PM Bug #9068 (Rejected): Exported configuration contains string at the end that should not be there
- When I export a configuration, everything is normal until the last line, which reads...
-
02:50 PM Bug #9067 (Feedback): PHP error when installing first package with empty installedpackages tag
- Applied in changeset commit:bfd3334b4bc9ae0d3c43f69e8305c83b0da3aa58.
-
02:40 PM Bug #9067 (Resolved): PHP error when installing first package with empty installedpackages tag
- If the configuration contains only @<installedpackages></installedpackages>@ then installing a package will fail with...
-
01:30 PM Bug #9066 (Feedback): ecl.php: Checking /config path is not working due to lack of trailing slash
- Applied in changeset commit:c688c59b47a3ce138ffe094794d01f1e6fcc00df.
-
01:19 PM Bug #9066 (Resolved): ecl.php: Checking /config path is not working due to lack of trailing slash
- At source:src/etc/ecl.php#L59 the locations for the external config locator (ECL) script are defined, but @/config@ d...
-
06:47 AM Bug #9065 (Rejected): Well known ports: order them by number instead of name
- The problem with this change is that people don't who do not know the numbers will want to find them by name, and wit...
-
05:21 AM Bug #9065 (Rejected): Well known ports: order them by number instead of name
- As a sysadmin, I always know the port I'm handling, but a lot of times I don't remember the +exact+ name of the servi...
10/24/2018
-
01:09 PM Bug #9064: voucher to device binding
- !
-
01:08 PM Bug #9064 (Not a Bug): voucher to device binding
- dear all,
in version 2.4.4 we cant enforce one voucher per same device always. some naughty user switch from one to ... -
11:53 AM Feature #9063 (New): Allow dynamic DNS client entry to specify which Check IP service to use
- Please update the dynamic DNS client feature to allow specification of the Check IP service to use at the individual ...
-
01:31 AM Bug #8758: filterdns stops working on a regular basis.
- Dear All
i am affected with same problem
it happens every day approx.
i must kill filterdns service and restart ...
10/23/2018
-
06:19 PM Revision 20895301: Fix processing of the 'all' group. Fixes #9051
- All the 'all' group to the list of groups at the end, rather than the
start. This way it will be considered no matter... -
06:17 PM Revision 4de15854: Fix processing of the 'all' group. Fixes #9051
- All the 'all' group to the list of groups at the end, rather than the
start. This way it will be considered no matter... -
05:14 PM Revision c95a79d3: Validate and protect powerd option values. Fixes #9061
- (cherry picked from commit 3be699295e5cb7be24cc5361700be1a8b759e26c)
-
05:13 PM Revision 3be69929: Validate and protect powerd option values. Fixes #9061
-
01:25 PM Bug #9051 (Feedback): Privileges on 'all' group are not being honored
- Applied in changeset commit:4de15854384e28004b0dc571dc8a40fda7eae694.
-
01:07 PM Feature #9062 (Rejected): Add "email notification" when the WAN interface change its public IP
- It would be helpful if an email is send when the WAN interface change its public IP.
Here is an example: https://www... -
12:20 PM Bug #9061 (Feedback): PowerD command parameter validation and escaping
- Applied in changeset commit:3be699295e5cb7be24cc5361700be1a8b759e26c.
-
11:46 AM Bug #9061 (Resolved): PowerD command parameter validation and escaping
- The powerd parameters @powerd_ac_mode@, @powerd_battery_mode@, and @powerd_normal_mode@ are not validated against the...
-
08:39 AM Feature #9060 (New): add rule name filtering field for firewall log viewer
- It would be very helpful to have a field available in the firewall log filter to search on matched rule name (i.e. Ev...
-
08:30 AM Bug #9059 (Resolved): Update Unbound to 1.8.1
- Unbound 1.8.1 has fixed a few memory leaks, notably one in DNS over TLS that causes unbound to consume all memory and...
-
08:21 AM Bug #9058: Kernel panic during L2TP retransmit
- Right now it happens at least once a day, but at random times. I'll check if the amount of traffic might be related.
-
08:09 AM Bug #9058: Kernel panic during L2TP retransmit
- I saw a crash with a backtrace like that once on a test VM with an L2TP WAN but only one time, not repeatedly, so I c...
-
06:41 AM Bug #9058 (Resolved): Kernel panic during L2TP retransmit
- I'm using a Multilink L2TP WAN. After a fresh reinstall of 2.4.4 and completely new config (no import) it crashes reg...
-
01:06 AM Bug #8937: LAGG shows wrong ether address
- Create a new LAGG with some interfaces and save it. Once thats done, edit that LAGG and on everything interface name ...
10/22/2018
-
11:48 PM Bug #9051: Privileges on 'all' group are not being honored
- removed the 'all' from both files and got access again, also admin is disabled using different user as admin
-
10:51 PM Bug #9051: Privileges on 'all' group are not being honored
- I just upgraded and got no page assigned
-
07:32 PM Revision 7a16a38c: Use the fw domain for DNS search when no other choices exist. Fixes #9056
- (cherry picked from commit 74a8a219d33c9b87ab4b6b4026d247f0f6bdcaa6)
-
07:31 PM Revision 74a8a219: Use the fw domain for DNS search when no other choices exist. Fixes #9056
-
06:36 PM pfSense Docs Correction #9057 (Resolved): [feedback form] Missing info on advanced networking page
- *Page*: https://docs.netgate.com/pfsense/en/latest/config/advanced-networking.html
*Feedback*: Missing info on the... - 05:35 PM Revision aa733351: gateway monitoring, wait for apinger to terminate or remove its pid file when restarting it.
- (cherry picked from commit 66491555711182d9176f6292fd58397c65e4b2af)
-
05:35 PM Revision 8e823a93: generate a flag even if trying to perform RADIUS MAC authentication on a non-RADIUS server.
- (cherry picked from commit 22e328743170b62b55d6e18b593c4005e8d6f892)
-
05:35 PM Revision bb90e3c5: Implement login fallback for RADIUS MAC authentication
- (cherry picked from commit 774ff51ba07f944a39fdc6859ec7d258b95315bf)
-
05:29 PM Revision b950e991: Strictly define the EAP Identifier for custom local client entries. Fixes #9055
- (cherry picked from commit 2d7ed31e3227566d0474929a3aed84509247f91e)
-
05:28 PM Revision 2d7ed31e: Strictly define the EAP Identifier for custom local client entries. Fixes #9055
- 03:28 PM Revision 8be7aff9: Merge pull request #3987 from PiBa-NL/20180920-apinger-wait-for-terminate
- 03:22 PM Revision 768eccf9: Merge pull request #4000 from Augustin-FL/patch-cp-3
-
02:40 PM Bug #9056 (Feedback): DNS search domain omitted in some cases
- Applied in changeset commit:74a8a219d33c9b87ab4b6b4026d247f0f6bdcaa6.
-
02:31 PM Bug #9056 (Resolved): DNS search domain omitted in some cases
- If a user has allowed DHCP override of DNS servers but there are no DCHP WANs, the search domain list will be empty.
... -
12:44 PM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
- If I set the Tier 1 gateway as "Mark Gateway as Down" then turn that setting back off, the routing will correct itsel...
-
10:58 AM Bug #9054 (Resolved): Gateway Group slow (or never) to switch back to Tier 1
- See https://forum.netgate.com/topic/136852/2-4-4-gateway-group-slow-or-never-to-switch-back-to-tier-1. (No responses...
-
12:35 PM Bug #9055 (Feedback): IKEv2 EAP Identity vs client ID matching for per-client settings with local users
- Applied in changeset commit:2d7ed31e3227566d0474929a3aed84509247f91e.
-
12:32 PM Bug #9055: IKEv2 EAP Identity vs client ID matching for per-client settings with local users
- If we determine that there is a use case for allowing the other method, we can setup GUI controls for it later as a s...
-
12:28 PM Bug #9055 (Resolved): IKEv2 EAP Identity vs client ID matching for per-client settings with local users
- With IKEv2, the EAP Identity does not necessarily match the @rightid@ supplied by the client. For most common use cas...
-
10:36 AM Bug #8964: IPsec async cryptography advanced setting - TCP traffic not passing through
- I'm seeing this bug occur on my SG-3100s when using one of the AES-GCM based algorithms for my IPSEC Phase2 with asyn...
-
10:29 AM Bug #8921: dpinger without .pid files.?. 'pending' status
- PR tested and applied. Thanks.
-
10:28 AM Bug #8921 (Feedback): dpinger without .pid files.?. 'pending' status
-
10:26 AM Bug #8937 (Feedback): LAGG shows wrong ether address
- Please provide some more details of this issue. It is not clear from the description what the problem is. Where do yo...
-
10:23 AM Feature #9032 (Feedback): RADIUS MAC Authentication: display the login page when MAC auth failed
10/21/2018
-
09:26 PM Bug #8555: Selectively killing states on WAN failure
- don't kill states when failover gateway is down:
https://github.com/pfsense/pfsense/pull/4159 -
12:09 PM pfSense Packages Bug #9050: Antartica does not make a rule
- I am not actively working on the previous release.
The devel version will be the next release version in a short p... -
10:23 AM pfSense Packages Bug #8909: tinc package makes /rc.newwanip looping forever
- I guess I found a workaround: define a static IP address into the interface, then enable it and use in firewall and o...
10/20/2018
-
11:02 PM Bug #9053 (Resolved): Dynamic DNS will not allow Route 53 wildcard record
- When configuring a dynamic DNS client to update Route 53 (AWS) records, the web form will not validate a hostname tha...
-
08:15 PM pfSense Packages Bug #9050: Antartica does not make a rule
- How long does it take to make it to the main version? It's been months and multiple releases since it says it was fi...
-
12:23 PM pfSense Packages Bug #9050: Antartica does not make a rule
- This is fixed in the pfBlockerNG-devel version.
-
12:30 PM Todo #9052 (Resolved): Update Font-Awesome
- Font Awesome in pfSense is using version (4.5.0). v4.x has been marked as End-of-life:
https://github.com/pfsense/... -
10:15 AM Bug #9051: Privileges on 'all' group are not being honored
- Should be easy to replicate, I just added a new user to admins group.
In the attached config I had added "page-d... -
09:16 AM Bug #9051 (In Progress): Privileges on 'all' group are not being honored
- That should not have been caused by this but I'll test it some more.
This should have only _added_ privileges to t... -
08:55 AM Bug #9051: Privileges on 'all' group are not being honored
- Jim Pingle wrote:
> All users are a member of the "All Users" group (actual group name internally: @all@).
>
> Pr...
10/19/2018
-
01:40 PM Revision 65c71eb3: Consider the "all" group when determining privileges. Fixes #9051
- (cherry picked from commit fe1afbb7549907e0d1cdfbf85d5f36d075a6a916)
-
01:39 PM Revision fe1afbb7: Consider the "all" group when determining privileges. Fixes #9051
-
11:43 AM pfSense Packages Todo #9041: update ntopng 3.6.0
- It's actually already at 3.6 on 2.4.5 snapshots, and trying to pick back changes proved to be a bit of a challenge. I...
-
11:18 AM Feature #8946: Add field to show IA_PD to DHCP6 Server page
- PR was closed. Awaiting new PR(s)
-
08:50 AM Bug #9051 (Feedback): Privileges on 'all' group are not being honored
- Applied in changeset commit:fe1afbb7549907e0d1cdfbf85d5f36d075a6a916.
-
08:38 AM Bug #9051 (Resolved): Privileges on 'all' group are not being honored
- All users are a member of the "All Users" group (actual group name internally: @all@).
Privileges can be added to ... -
08:16 AM Bug #7905: OpenVPN Authentication Against Backend Stalls All Server Traffic
- Unfortunately, with pfSense version 2.4.4, the fallback to an alternative RADIUS server is still not operational.
...
10/18/2018
-
03:15 PM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
- Just because two bugs affect the same subsystem doesn't mean they are related, though. Limiters work fine for many pe...
-
03:06 PM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
- Yes, of course! I might not have been clear, I totally understand that these are bugs in two different areas of code....
-
11:25 AM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
- They are unrelated, the only thing they have in common is that they are both limiter issues. One is a GUI parsing pro...
-
11:06 AM Bug #8956: traffic shaper after upgrade to 2.4.4 not showing queue under each limiter
- Ok, great - I'm glad you've seen it.
FWIW, I would vote for those two issues to go out together. While fixing the... -
02:53 PM Revision 0edf0420: Rewrite /etc/rc.kill_states to use pfSense module state functions. Fixes #8554
- Eliminates inaccurate shell exec/grep/preg_match syntax issues.
(cherry picked from commit 5142c80abbaa7b2dd219c03ed... -
02:52 PM Revision 5142c80a: Rewrite /etc/rc.kill_states to use pfSense module state functions. Fixes #8554
- Eliminates inaccurate shell exec/grep/preg_match syntax issues.
-
02:35 PM pfSense Packages Bug #9050 (Resolved): Antartica does not make a rule
- If Antarctica entries with a count > 0 are added to the pfBlockerNG GeoIP, there won't be an Antarctica rule created....
-
11:30 AM Bug #8555: Selectively killing states on WAN failure
- Well it still could be worth submitting the PR to get some other eyes on it.
Also, having it up on Github would ma... -
10:00 AM Bug #8554 (Feedback): /etc/rc.kill_states code not correctly parsing pfctl output
- Applied in changeset commit:5142c80abbaa7b2dd219c03edd60c4f675d2fb62.
-
09:54 AM Bug #8554: /etc/rc.kill_states code not correctly parsing pfctl output
- I'd rather not change one funky regex matching pattern for another. I have a better fix. Push incoming.
-
01:01 AM Bug #8554: /etc/rc.kill_states code not correctly parsing pfctl output
- Did you ever submit a PR for this?
-
07:47 AM Bug #9049 (Not a Bug): IPSec statuspage shows both connected and connecting tunnel
- Since bugnumber 8117 has been served off as not a bug, and no further response is given I'd like to re-open this bug....
Also available in: Atom