Activity
From 01/06/2019 to 02/04/2019
02/04/2019
-
09:45 PM Revision d6601c8f: Also trim if() statement
-
02:18 PM Feature #7618: Add support for user-supplied Host-Uniq tag and handle PADM messages in Netgraph PPPoE
- I've created a pull request -to my own branch for tests, when stable I'll pull the request- to pfSense master.
Li... -
07:20 AM Bug #6896 (Not a Bug): unbound root.key file corruption possibly related to full file system
-
06:03 AM Bug #9148 (Feedback): PPPoE over a VLAN fails to reconnect.
- This should be fixed in 2.4.4p2
-
05:39 AM Feature #1831: Captive portal IPv6 support
- Flole Systems wrote:
> Unfortunately that site is down. However, I've done some additional research and it seems lik... -
05:12 AM Bug #6579: IPv6 CARP VIPs lost upon config sync where they include non-significant zeros
- I have just experienced an interesting mutation of the issue. My IPv6 CARP virtual address was ending with zero: fddf...
02/03/2019
-
05:08 PM Feature #9304: DNS Rebind Protection should be configurable, defaults should be more sensible
- The problem I ran into with the stock configuration is that there's absolutely no way to disable DNS rebind protectio...
-
04:57 PM Feature #9304: DNS Rebind Protection should be configurable, defaults should be more sensible
- The default is fine as-is, it is the most secure assumption and safest.
There are documented ways to make exceptio... -
04:53 PM Feature #9304 (Resolved): DNS Rebind Protection should be configurable, defaults should be more sensible
- h2. Problem
The DNS rebind protection approach currently being used by pfSense is too heavy handed. It indiscrimi... -
07:19 AM Bug #9303: HA sync : disabling captive portal HA sync does remove all zones on slave
- fix : https://github.com/pfsense/pfsense/commit/3d382f50c3a25230e7166e9877a0d88c7e62c24b.diff
(if you want to apply ... -
07:13 AM Bug #9303 (Resolved): HA sync : disabling captive portal HA sync does remove all zones on slave
- Issue #8808 has been fixed in 2.4.4, however the fix induced another problem : unselecting "captive portal" in HA syn...
02/02/2019
-
04:30 AM Feature #9302: radvd always advertises DNS servers and Domain Search List regardless of M or O flag
- An example radvd configuration can be found here:
[http://sophiedogg.com/radvd-and-dhcpd6-server-configuration-for-d... -
04:27 AM Feature #9302 (Resolved): radvd always advertises DNS servers and Domain Search List regardless of M or O flag
- In "Managed" or "Stateless DHCP" mode, DNS servers and Domain Search List should be requested from DHCPv6 Server.
...
02/01/2019
-
06:44 PM pfSense Packages Bug #8780 (Resolved): Apcupsd PHP errors in 2.4.4 snapshot
- Got it. Tested on 2.4.5.a.20190201.0810 with apcupsd version 0.3.91_4, no issues.
-
06:39 PM Bug #8633: thousands PHP undef gwname /etc/inc/gwlib.inc line 1210
- What are the steps to reproduce this issue?
-
06:34 PM pfSense Packages Bug #8651 (Resolved): another php error (broke stable pfBng)
- Not able to reproduce this behavior on 2.4.5.a.20190201.0810 with pfBlockerNG 2.1.4_16.
-
06:21 PM Bug #9275 (Resolved): ip tools link not working
-
06:03 PM Bug #9275: ip tools link not working
- Tested on 2.4.5.a.20190201.0810. Links have been removed.
-
06:20 PM Bug #9239 (Resolved): WebGUI: Diagnostics > Packet Capture will try to display any size of pcap file.
-
06:20 PM Bug #9239: WebGUI: Diagnostics > Packet Capture will try to display any size of pcap file.
- On 2.4.5.a.20190201.0810, tested with an iperf3 traffic stream running over WAN with a simultaneous packet capture on...
-
02:23 PM pfSense Docs Correction #9301 (Resolved): Broken link to HashTab in Verifying Downloaded Image section of Writing OS Image to Media
- It was also broken in the pfSense docs. Fixed both.
-
01:52 PM pfSense Docs Correction #9301 (Resolved): Broken link to HashTab in Verifying Downloaded Image section of Writing OS Image to Media
- At https://www.netgate.com/docs/reference/create-flash-media.html#verify-the-downloaded-image the link to HashTab sho...
-
11:29 AM Bug #9123: Adding/configuring vlan on ixl-devices causes aq_add_macvlan err -53, aq_error 14
- I have tested the FreeBSD Version 11.1, 11.2 and 12.0 on the Hardware and got following results.
+FreeBSD 11.1 (Fr... -
10:22 AM Feature #1831: Captive portal IPv6 support
- Unfortunately that site is down. However, I've done some additional research and it seems like others simply use stri...
-
08:43 AM pfSense Packages Bug #9211: GeoIP broken in pfSense-pkg-ntopng-0.8.13_3
- New ntopng 3.8 (December 2018) release supports the GeoIP2 library
* Adds the new libmaxminddb geolocation library
01/31/2019
-
12:06 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
- I believe my issues may be related to this. We updated to 2.4.4 p2 on Jan 9, but only in the past few days have seen ...
-
05:32 AM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
- I have now prepared a minimal example:
As you can see fqdn1 is missing the entry for one.one.one.one
Please FIX -
09:42 AM pfSense Packages Feature #9300 (Rejected): ACME package: last time updated
- Did you mean something else besides "Last Updated"? "Last Renewed" would always be the same as "Last Updated".
Unl... -
12:37 AM pfSense Packages Feature #9300: ACME package: last time updated
- Not to be a naysayer, but isn't that a little redundant? Acme knows LE is 90 days and if run manually before Day 60 ...
-
12:09 AM Bug #7609: NTP Status not parsing all NTP Access Restrictions preventing status display when it is actually allowed
- As of 2.4.4-p2 issue as described in the original post still exists and has not been resolved.
There are a couple ...
01/30/2019
-
10:13 PM pfSense Packages Feature #9300 (Rejected): ACME package: last time updated
- It’s low priority but nice to have.
Please expose in addition to ‘Last renewed’ time stamp “Last updated” on the t... -
10:09 PM pfSense Packages Feature #9299 (New): ACME package : Automate add/remove firewall rule for port forwarding
Currently if user wants to fordward port 80 (for stand alone method for example) to a different port and also not ...-
02:41 PM Bug #9298 (Not a Bug): php error: utime failed
- I reported this last year, Issue #8707 and gave up on a fix.
Updated last night to 1.28.19 build, hoping maybe the... -
01:05 PM Feature #9297 (Resolved): Graph for hardware temperature readings
- It would very nice to be able to see a history of available temperature readings even if that was just whatever CPU t...
-
12:22 PM Bug #9296 (Resolved): Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
- If you are using FQDN-Aliases each FQDN can only be used once, if
you use the alias twice, the generated tables are... -
10:59 AM Revision c07f1c26: Revert "Switch the 2.4.5 CE images to the new 2.4.5 development branch."
- This reverts commit 2735541ea6fa553673d90e75f7e821497723fb23.
-
10:36 AM pfSense Packages Feature #8232: different ssl options based on the sni name
- Hey Pi Ba
I got the same Problem. When will the Fix be upstreamd to the "Main Channel" of pfs?
Greetings
Cedric
01/29/2019
-
07:23 PM Revision 5c4fef46: Add validation and encoding to various firewall advanced values. Issue #9294
- (cherry picked from commit 62baf0777924b2c21c832db3c0040988e7451c61)
-
07:23 PM Revision 9712ce4e: Encode shaper queue name before printing. Issue #9294
- Validation is already present and prevents bad values from being
entered.
(cherry picked from commit 1072b9333c47df5... -
07:23 PM Revision 7e9de4b1: Input validation and encoding of IGMP proxy addresses. Issue #9294
- (cherry picked from commit 261916e5d3f833a58d5cef1afdadc7495ec2c74b)
-
07:23 PM Revision ca0234c3: Validate NTP GPS type, encode output. Issue #9294
- (cherry picked from commit 938988609c306fcd44e25a053745c4b8332eeeb5)
-
07:23 PM Revision f39d3332: Encode traceroute error message. Issue #9294
- (cherry picked from commit 57ccd08bf7ee05b9a00750a1fd9cf8f148e0c9ac)
-
07:23 PM Revision 587c2d55: Validate submitted interfaces. Issue #9294
- (cherry picked from commit 5cc7d21dc08be6c65a2bf7f8f4481dc13f4ae115)
-
07:23 PM Revision 10b06be5: Fix input validation of webguiproto. Issue #9294
- (cherry picked from commit 56888f24ca2715e678a1324633a08d3a611b4136)
-
07:15 PM Revision 62baf077: Add validation and encoding to various firewall advanced values. Issue #9294
-
05:40 PM Revision 1072b933: Encode shaper queue name before printing. Issue #9294
- Validation is already present and prevents bad values from being
entered. -
05:04 PM Revision 261916e5: Input validation and encoding of IGMP proxy addresses. Issue #9294
-
04:48 PM Revision 93898860: Validate NTP GPS type, encode output. Issue #9294
-
04:15 PM Revision 57ccd08b: Encode traceroute error message. Issue #9294
-
04:11 PM Revision 5cc7d21d: Validate submitted interfaces. Issue #9294
-
04:05 PM Feature #9293: Custom message text for the login screen
- Hi Joshua,
Yes, that was just an example of a similar requirement. This requirement can be found for "web servers":h... -
12:02 PM Feature #9293: Custom message text for the login screen
- Hi,
You are sure it is required for WebGUI ?
Because in the document you link it is only for "console login prom... -
06:18 AM Feature #9293 (Resolved): Custom message text for the login screen
- While trying to deploy in govt environments, they have security guidelines (STIGs) we're required to follow. Some, as...
-
03:47 PM Revision 56888f24: Fix input validation of webguiproto. Issue #9294
-
01:24 PM Bug #9294: XSS issues on multiple pages
- * XSS1 - Reproduced during redirect when changing protocols, added validation for the input and redirect
* XSS2 - Un... -
09:03 AM Bug #9294 (Resolved): XSS issues on multiple pages
- A list of 30 XSS issues was posted publicly without following responsible disclosure practices, they all need tested/...
-
11:51 AM Bug #9295 (New): IPv6 PD does not work with PPPOE (Server & Client)
- Hi,
as encountering DHCPv6 with Prefix delegation does not work together with PPPOE Server vice versa it is not p... -
05:02 AM Bug #9123: Adding/configuring vlan on ixl-devices causes aq_add_macvlan err -53, aq_error 14
- Same problem here.
Hardware: Dell PowerEdge 330 with Intel(R) 10GbE 2P X710 Adapter
Done so far:
* installati... -
04:09 AM Feature #7244: Publish pfsense as a Vagrant Basebox
- I'm looking into implementing this one, because I need an easy way to launch pfsense instances for running automatic ...
01/28/2019
-
11:55 PM Revision 2735541e: Switch the 2.4.5 CE images to the new 2.4.5 development branch.
- Start to pave the way to 2.5.
-
06:18 PM Revision e5b43cf8: type cast traffic graph inputs to fix #9072
-
03:10 PM Bug #9072: RRD graph mouseover information shows up as Mb when unit size is set to MB
- Thanks for digging into the problem and for testing the fix!
-
03:09 PM Bug #9072 (Resolved): RRD graph mouseover information shows up as Mb when unit size is set to MB
-
12:34 PM Bug #9072: RRD graph mouseover information shows up as Mb when unit size is set to MB
- It Works! ;)
tested on :
2.4.4-RELEASE-p2 (amd64)
built on Wed Dec 12 07:40:18 EST 2018
FreeBSD 11.2-RELEASE-p6 -
12:25 PM Bug #9072: RRD graph mouseover information shows up as Mb when unit size is set to MB
- Applied in changeset commit:e5b43cf8b86586486d951ab1da35b6c45ad6edf6.
-
12:24 PM Bug #9072 (Feedback): RRD graph mouseover information shows up as Mb when unit size is set to MB
-
12:24 PM Bug #9072: RRD graph mouseover information shows up as Mb when unit size is set to MB
- It looks like it was introduced in this commit (not that the code before it was perfect): https://github.com/pfsense/...
-
07:49 AM Feature #9290 (Resolved): Need a way to suppress status output display in /status.php
-
12:14 AM Revision dcc887a3: RADVD: In "managed" or "stateless_dhcp" mode, don't use default values for DNS servers etc (these should come from DHCPv6)
01/27/2019
-
07:20 PM Feature #9290: Need a way to suppress status output display in /status.php
- This all looks great. Tested everything I think. Works.
-
08:26 AM Bug #9292 (Resolved): Default route as indicated by "(Default)" does not match the actual default route on the OS.
- Default route as indicated by "(Default)" does not match the actual default route on the OS.
Fix: https://github.c... -
12:52 AM Bug #8991: Codel limiter generating error in system log and console
- Per below two forum posts by dummynet creator configuring Codel AQM and fq_codel scheduler, as shown in Youtube video...
01/26/2019
-
08:02 PM Bug #8554: /etc/rc.kill_states code not correctly parsing pfctl output
- I'm running 2.4.4_2 and it still seems to be an issue. Are those actions logged somewhere so I can take a look please?
-
09:56 AM Bug #9276 (Resolved): DNS troubleshooting tool incorrectly reporting "ai." as an invalid hostname
-
12:02 AM Bug #9276: DNS troubleshooting tool incorrectly reporting "ai." as an invalid hostname
- On 2.4.5-DEVELOPMENT (arm)
built on Fri Jan 25 05:46:46 EST 2019
Entered "ai.: in Diagnostics=>DNS Lookup an... -
09:46 AM Feature #9290: Need a way to suppress status output display in /status.php
- That snapshot was before this commit. The newest snapshot should have it, if you update and try it again, it should w...
-
12:16 AM Feature #9290: Need a way to suppress status output display in /status.php
- On 2.4.5-DEVELOPMENT (arm)
built on Fri Jan 25 05:46:46 EST 2019 - SG3100
When I issue this command I get html ...
01/25/2019
-
04:08 PM Bug #6876: Firewall alias issue after adding a wrong alias
- Tested on:
2.4.4-RELEASE-p2 (arm)
built on Wed Dec 12 14:40:29 EST 2018
FreeBSD 11.2-RELEASE-p6
Followed instru... -
04:04 PM Revision 140655f7: status.php optimizations. Implements #9290
- * Rewrites the command output so it is first written to files, then read through line-by-line to PHP. Should be much ...
-
04:04 PM Revision 6c17da07: status.php optimizations. Implements #9290
- * Rewrites the command output so it is first written to files, then read through line-by-line to PHP. Should be much ...
-
01:54 PM Feature #9288: SSHGuard add pfSense signature in standard
- FYI
Kevin Zheng from sshguard bitbucker wrote :
> I’d be happy to include this signature in SSHGuard if the rule ... -
11:56 AM pfSense Packages Bug #9050: Antartica does not make a rule
- What should I track to see when it is released?
-
10:28 AM Bug #9004: Default gateway IPv4 set to a group fails after restart on 2.4.4
- jonathan's fix works.
Thank you very much! -
10:07 AM Feature #9290 (Feedback): Need a way to suppress status output display in /status.php
- Implemented this and some other changes.
* Rewrites the command output so it is first written to files, then read ... -
07:40 AM Bug #9239: WebGUI: Diagnostics > Packet Capture will try to display any size of pcap file.
- tested on 2.4.5-DEVELOPMENT (arm)
built on Fri Jan 25 05:46:46 EST 2019
Invoked a lot of traffic while running...
01/24/2019
-
08:46 PM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
- I have also noticed this issue on my home pfSense. I was able to reproduce it reliably with a VM and it appears to h...
-
12:40 PM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
- James Howel wrote:
> It appears that if pfSense has NEVER been connected to the internet, the way it behaves with th... -
10:26 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
- Maverick Phillips wrote:
> Hello,
>
> One of my two firewalls has developed this issue - I can confirm disabling ... -
04:57 PM Feature #4632: Support for Multipath TCP (MPTCP)
- +1 here
this is a great added value for pfsense ! -
04:25 PM Bug #9291: Schedule icon missing
- Ok copy thx
-
04:05 PM Bug #9291 (Not a Bug): Schedule icon missing
- Unless you are viewing the web page between 3:15-3:30 AM, that icon will not show because the schedule is not active....
-
03:47 PM Bug #9291 (Not a Bug): Schedule icon missing
- See attached.
Fine print says <icon >"Indicates that the schedule is currently active."
But there is no icon on... -
02:17 PM Bug #9072: RRD graph mouseover information shows up as Mb when unit size is set to MB
- i can confirm
the problem comes when you change from bytes to bits and then bits to bytes.
one temporary workaro... -
12:45 PM Bug #9072: RRD graph mouseover information shows up as Mb when unit size is set to MB
- Discussion about it here and validation
https://forum.netgate.com/topic/139922/solved-dashboard-traffic-not-consiste... -
06:24 AM Bug #8758: filterdns stops working on a regular basis.
- Just ran into this on 2.4.4-p2 with a not updating alias table:
[2.4.4-RELEASE][root@fw2]/root: ps aux | grep filt... -
12:56 AM pfSense Packages Bug #9050: Antartica does not make a rule
- I answered this in my post above... Its already fixed in Devel. I am hoping to get devel released next month and that...
01/23/2019
-
07:13 PM Revision 683a0581: Don't use DISTFILES_CACHE
-
07:13 PM Revision 81041332: Don't use DISTFILES_CACHE
-
05:57 PM Revision 97bca189: Remove unnecessary ports from dependency list
-
05:57 PM Revision fa6f675e: Remove unnecessary ports from dependency list
-
02:18 PM Feature #9290 (Resolved): Need a way to suppress status output display in /status.php
- Many times on a large system a status output cannot be taken because displaying things like a large state table can e...
-
01:22 PM Feature #336: Option to create lagg under assign interfaces
- +1 Very important feature!
-
09:30 AM pfSense Packages Feature #9250 (Resolved): Adjust download buttons and labels in OpenVPN Client Export
- Tested:...
-
04:52 AM pfSense Packages Feature #9289 (New): Snort enable react
- I like to use the "config enable_react" parameter to show a http site on blocked ips. The SNORT package dont't know t...
01/22/2019
- 07:56 PM Revision a0541b29: use disablepingcheck as option name
-
06:26 PM Feature #9288 (New): SSHGuard add pfSense signature in standard
- Hi,
I discuss with sshguard team about possibility to add the pfSense signature in standard, as it is ever done by... - 04:21 PM Revision 7847e55f: add an option to the DHCP server to disable the ping check feature
-
03:37 PM Bug #9281 (Resolved): ZFS encrypted+mirrored swap may not be activated on 2.4.4-p2
- Thanks for testing!
-
03:11 PM Bug #9281: ZFS encrypted+mirrored swap may not be activated on 2.4.4-p2
- Jim Pingle wrote:
> ZFS encrypted+mirrored swap may not be activated on 2.4.4-p2, the new swap device location code ... -
08:55 AM Bug #9281 (Feedback): ZFS encrypted+mirrored swap may not be activated on 2.4.4-p2
- Applied in changeset commit:14d470377eab89d7c3f6f765a150ce737409af28.
-
03:36 PM pfSense Docs Correction #8865 (Rejected): Feedback on Networking Concepts — IPv6 — IPv6 Subnetting
- You have misread what the page is stating. The table is primarily to indicate the enormity of the IPv6 space.
Netw... -
03:31 PM pfSense Docs Correction #8853 (Resolved): [feedback form] Explain what 0:0 means
- Added info to that page. ICMP doesn't have state levels like other protocols, so it's really just a placeholder. Does...
-
03:15 PM Revision 5e0fda8f: Fix desc of OpenVPN sync to show that it also syncs certs. Fixes #9283
- (cherry picked from commit 9f3b87d898e1fa8a5bfa40758e5747515cc38ad4)
-
03:14 PM Revision 9f3b87d8: Fix desc of OpenVPN sync to show that it also syncs certs. Fixes #9283
-
03:05 PM pfSense Docs Correction #9287 (Resolved): Feedback on The pfSense Book
- Fix committed
-
01:03 PM pfSense Docs Correction #9287 (Resolved): Feedback on The pfSense Book
- *Page:* https://www.netgate.com/docs/pfsense/book/index.html
*Feedback:* Printed page 264, section 16.1. Period m... -
02:49 PM Revision 3bb3fd45: Fix handling of special swap cases. Fixes #9281
- (cherry picked from commit 14d470377eab89d7c3f6f765a150ce737409af28)
-
02:48 PM Revision 14d47037: Fix handling of special swap cases. Fixes #9281
-
12:18 PM pfSense Packages Bug #9286: squidGuard - Unable to change IP for sgerror.php URL in configuration
- Also see bug #8827 that is exhibiting a similar issue.
-
12:13 PM pfSense Packages Bug #9286 (New): squidGuard - Unable to change IP for sgerror.php URL in configuration
- There is an issue with squidGuard where a user is not able to specify the address that squidGuard provides the client...
-
11:11 AM pfSense Packages Feature #8613: pfSense-pkg-acme: acme_certificates_edit.php - Add support for --challenge-alias acme.sh flag
- I added a checkbox to use challenge-domain instead of challenge-alias in ACME pkg version 0.5.2
-
11:11 AM pfSense Packages Feature #8211 (Feedback): ACME cron job <- log activity
- Fixed in ACME pkg version 0.5.2
Cron job output is now redirected to the main system log. -
10:41 AM pfSense Packages Bug #9279 (Duplicate): security/acme: acme pf sense package processes unnecessary notifications due to using stdout
- This will be solved by the fix for #8211 so I'm marking this as a duplicate for now.
-
10:28 AM Feature #9285 (Resolved): Add an option to disable the ping-check in dhcpd
- In experiencing some strange DHCP behavior at a customer site, where DHCP leases were getting abandoned and never re-...
-
09:39 AM Bug #9284: no default gateway after upgrade to 2.4.4_p2 using gateway group
- Jim Pingle wrote:
> Duplicate of #9004
Sorry I did search first. Not well apparently. -
09:36 AM Bug #9284 (Duplicate): no default gateway after upgrade to 2.4.4_p2 using gateway group
- Duplicate of #9004
-
09:32 AM Bug #9284: no default gateway after upgrade to 2.4.4_p2 using gateway group
- Art Manion wrote:
> Workaround: In System > Routing > Gateways set Default gateway IPv4 to automatic (or one of t... -
09:26 AM Bug #9284 (Duplicate): no default gateway after upgrade to 2.4.4_p2 using gateway group
- Two pfSense boxes A and B using HA sync, A is master, B is backup.
Two gateways, Verizon (tier 1) and ATT (tier 2)... -
09:35 AM Bug #9283: Not obvious that HA sync will still sync certs if cert sync disabled but OpenVPN sync enabled
- Jim Pingle wrote:
> The correct procedure for what you describe is to import all certs to the primary, and then sele... -
09:33 AM Bug #9283: Not obvious that HA sync will still sync certs if cert sync disabled but OpenVPN sync enabled
- Jim Pingle wrote:
> It does exclude certificates when all areas that need certificate sync are disabled. OpenVPN req... -
09:20 AM Bug #9283 (Feedback): Not obvious that HA sync will still sync certs if cert sync disabled but OpenVPN sync enabled
- Applied in changeset commit:9f3b87d898e1fa8a5bfa40758e5747515cc38ad4.
-
09:18 AM Bug #9283: Not obvious that HA sync will still sync certs if cert sync disabled but OpenVPN sync enabled
- It does exclude certificates when all areas that need certificate sync are disabled. OpenVPN requires certs to sync, ...
-
01:40 AM Bug #9283 (Resolved): Not obvious that HA sync will still sync certs if cert sync disabled but OpenVPN sync enabled
- system A has external/imported certificate A
system B has external/imported certificate B
Both just upgraded to 2... -
09:24 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- Daryl Morse wrote:
> As I mentioned, I emailed the author of rate. He replied this morning and confirmed that he is ... -
01:05 AM Bug #9282 (Resolved): Add static mapping count to DHCP Server interface tabs
- services - > DHCP Server > Interface
need a counter that count add static mapping in "DHCP Static Mappings for ...
01/21/2019
-
07:22 PM Revision 0b07930d: Packet capture page fixes. Fixes #9239
- * Add "None" output level
* Detect large files and refuse to print them in the GUI textarea
* Ensure output buffering... -
07:22 PM Revision 36192f4a: Packet capture page fixes. Fixes #9239
- * Add "None" output level
* Detect large files and refuse to print them in the GUI textarea
* Ensure output buffering... -
05:52 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- Jim Pingle wrote:
> The underlying program, rate, still doesn't work with IPv6 as far as I'm aware.
>
> I'd love ... -
09:42 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- With some small modifications, it does work. See my comments on the PR (and future discussion should happen on the PR...
-
04:12 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- you are certainly in an issue with bads crlf in the awk script.
please update by this one, i gzip it to avoid any co... -
04:49 PM Revision 5c8aaa20: Init array for 6o4 tunneling Fixes #9264
- (cherry picked from commit 5345b25405101eba3112c1d5daef99bd3b308533)
-
04:48 PM Revision 5345b254: Init array for 6o4 tunneling Fixes #9264
-
04:39 PM Revision 2cc24f95: Allow a trailing dot in a hostname on diag_dns.php. Fixes #9276
- (cherry picked from commit e56c473d7c4c2e7de71c43420c844e452dbcfa82)
-
04:39 PM Revision f6775a83: Remove links to DNSStuf tools. Fixes #9275
- (cherry picked from commit 08c49b4d74b87bf34dd46a37837147b857eb8859)
-
04:38 PM Revision e56c473d: Allow a trailing dot in a hostname on diag_dns.php. Fixes #9276
-
04:32 PM Revision 08c49b4d: Remove links to DNSStuf tools. Fixes #9275
-
03:38 PM Bug #9281 (Resolved): ZFS encrypted+mirrored swap may not be activated on 2.4.4-p2
- ZFS encrypted+mirrored swap may not be activated on 2.4.4-p2, the new swap device location code isn't validating the ...
-
02:51 PM Bug #9160 (Resolved): OCSP Must-Staple, when checked on the System > Advanced AND on the System > General Setup some IPv6 DNS servers are listed, then the nginx web configurator file will a contain syntax error
- This has been working for me in a test VM for over a month now, but it would be nice to have additional confirmation ...
-
01:30 PM Bug #9239 (Feedback): WebGUI: Diagnostics > Packet Capture will try to display any size of pcap file.
- Applied in changeset commit:36192f4a459ec5d5baf06819102ba783c1725ba1.
-
11:49 AM Feature #9268: Add Linode Dynamic DNS support
- FYI for anyone testing, and as noted on the PR:
Authentication uses "Personal Access Tokens":https://cloud.linode.... -
11:19 AM pfSense Packages Feature #9265 (Feedback): Add options to configure TIMEOUTclose and debug on stunnel package
- PR merged
-
11:18 AM pfSense Packages Feature #9250 (Feedback): Adjust download buttons and labels in OpenVPN Client Export
- PR merged
-
11:17 AM pfSense Packages Bug #9244 (Feedback): FRR Status BGP Summary only shows "IPv4 Unicast Summary"
- PR Merged
-
10:55 AM Bug #9264 (Feedback): Disabling "IPv6 over IPv4 Tunneling" breaks config
- Applied in changeset commit:5345b25405101eba3112c1d5daef99bd3b308533.
-
10:49 AM Bug #9264: Disabling "IPv6 over IPv4 Tunneling" breaks config
- That's a new error, not the same one. I can't reproduce that here, but I can see how it might happen. Pushed a new fix.
-
10:45 AM Bug #9276 (Feedback): DNS troubleshooting tool incorrectly reporting "ai." as an invalid hostname
- Applied in changeset commit:e56c473d7c4c2e7de71c43420c844e452dbcfa82.
-
10:38 AM Bug #9276: DNS troubleshooting tool incorrectly reporting "ai." as an invalid hostname
- Looks like it's easily fixed by having the validation check ignore a trailing dot on the hostname, but including it i...
-
10:45 AM Bug #9275 (Feedback): ip tools link not working
- Applied in changeset commit:08c49b4d74b87bf34dd46a37837147b857eb8859.
-
10:31 AM Bug #9275: ip tools link not working
- Actually the URL didn't just change, they also changed the format of the query and it doesn't appear to have the exac...
-
10:24 AM Bug #9270: "Remove all states to and from the filtered address" does not remove all states
- There does seem to be an issue here, looks like it's in the pfSense module function @pfSense_kill_states()@. Sometime...
-
09:28 AM Feature #9280: Add AAAA record type support for DynDNS with Digital Ocean
- * meant to create this as a "feature".
-
09:17 AM Feature #9280 (Resolved): Add AAAA record type support for DynDNS with Digital Ocean
- Add AAAA record type support for DynDNS with Digital Ocean
Updated dyndns.class, services.inc, and services_dyndns... -
05:37 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
- Hi Joshua,
Thanks for looking at this.
We don't have a WAN in a down state, it is connected but it has no NAT a...
01/20/2019
-
10:34 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- Joshua Sign wrote:
> ok,
>
> the first file "File Capture iftop.PNG" show that there is a problem with the awk s... -
06:48 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- ok,
the first file "File Capture iftop.PNG" show that there is a problem with the awk script.
This script is les... -
06:02 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- Another screen capture from the status graph.
-
05:57 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- Joshua Sign wrote:
> Daryl Morse wrote:
> > I got permission denied when I tried to run the script from the console... -
04:53 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Daryl Morse wrote:
> I got permission denied when I tried to run the script from the console shell.
please chec...-
04:01 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- just a thought, if you don't have ipv6, you could set up a tunnel with hurricane electric. It's free, it works very w...
-
03:58 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- Joshua Sign wrote:
> ok,
>
> to debbug it you can check if there is any ip6 in this output :
> [...]
>
> if... -
12:09 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- ok,
to debbug it you can check if there is any ip6 in this output : ... -
10:47 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- Joshua Sign wrote:
> can you chexk over console if iftop shows you some IPV6 adresses just by : `iftop -n` ?
>
> ... -
05:36 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- can you chexk over console if iftop shows you some IPV6 adresses just by : `iftop -n` ?
as far as i didn't have an... -
06:14 PM Feature #790: Advanced options for dnsclient (resolv.conf)
- PR created : https://github.com/pfsense/pfsense/pull/4040
-
03:29 PM Feature #790: Advanced options for dnsclient (resolv.conf)
- Mike Stupalov wrote:
> Possibility to add additional options in resolv.conf:
> * timeout:n (default 5)
> * attempt... -
05:43 PM pfSense Packages Bug #9279 (Duplicate): security/acme: acme pf sense package processes unnecessary notifications due to using stdout
- When email notifications enabled and pfsense acme (0.5.1) package installed and cron enabled, acme client will produc...
-
04:42 PM Bug #9223: SSHGUARD doesn't work as expected
- I investigate about this problem,
It seems that the sshguard purpose is to detect an attack and just launch a bac... -
11:36 AM pfSense Packages Bug #9050: Antartica does not make a rule
- Has this been released in the main version? I updated to 2.4.4-p2 and pfBlockerNG 2.1.4_16 and it still doesn't crea...
01/19/2019
-
12:33 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- Joshua Sign wrote:
> PR : https://github.com/pfsense/pfsense/pull/4039
I installed this patch on the most recent ... -
02:12 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- PR : https://github.com/pfsense/pfsense/pull/4039
-
12:27 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- Here is the patch
/usr/local/bin/iftop_parser.sh must have +x
-
09:58 AM Bug #9278 (Not a Bug): LAN IPv6 track interface Router Advertisement not assigning IPv6 addresses on Linux and macOS clients
- Sounds more like a configuration or local client issue. Post on the forum to discuss the issue and diagnose the probl...
-
09:51 AM Bug #9278 (Not a Bug): LAN IPv6 track interface Router Advertisement not assigning IPv6 addresses on Linux and macOS clients
- Comcast -> (WAN) NetGate (LAN) --> Linux, macOS clients
WAN is configured for IPv6 prefix delegation with prefix l... -
12:23 AM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
- I agree with David. DNS more so than Ping monitoring makes sense to me. I've been bit a few times with DNS failures b...
01/18/2019
-
06:17 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- here are the files you need to easely test, it is faster thant the PR
just put the two scripts into the root directo... -
06:10 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- yes it will be possible soon.
I just wrote this script to avoid process concurrent creation when many users are on... -
05:36 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- Joshua Sign wrote:
> Unfortunally i don't use IPV6, so i can't test this part.
I have IPv6 so I would be happy ... -
10:19 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- Hi Jim,
FYI, I just finish some tests : it seems to works as expected.
All we need to test is :
This awk scr... -
02:30 PM Feature #7416: DHCPv4 client does not support ``supersede`` statement for option 54
- The patch fixed it in OPNSense in 2017. It has been running flawlessly ever since. That's the only feedback I can pro...
-
11:10 AM Bug #9264 (Assigned): Disabling "IPv6 over IPv4 Tunneling" breaks config
-
10:57 AM Bug #9264: Disabling "IPv6 over IPv4 Tunneling" breaks config
- Reproduced the issue on SG-5100:
2.4.4-RELEASE-p2 (amd64)
built on Wed Dec 12 14:40:29 EST 2018
FreeBSD 11.2-REL... -
10:45 AM Bug #9171 (Resolved): Fix DigitalOcean Dynamic DNS client
- Tested on SG-5100 -
2.4.4-RELEASE-p2 (amd64)
built on Wed Dec 12 14:40:29 EST 2018
FreeBSD 11.2-RELEASE-p6
A... -
10:42 AM Bug #9024: Ping packet loss under load when using limiters
- I just wanted to chime in that I have the very same exact behaviour on my setup.
Is there any progress on the issue? -
09:29 AM Bug #9277: MBT-4220/2220: pfSense hangs when running sysctl -a
- I'm pretty sure I experienced the same issue on 2.4.4-p1 and or 2.4.4-p2.
It did happen only for the initial few r... -
07:07 AM Bug #9277 (Not a Bug): MBT-4220/2220: pfSense hangs when running sysctl -a
- That isn't a general issue with pfSense or the MBT-4220. Please contact our support team at https://go.netgate.com an...
-
03:48 AM Bug #9277 (Resolved): MBT-4220/2220: pfSense hangs when running sysctl -a
- Running 2.4.4-p2 on MBT-4220
Accessing the WebGUI appears to be causing OS-level hang (no response on WebGUI/SSH/...
01/17/2019
-
06:29 PM Bug #9053: Dynamic DNS will not allow Route 53 wildcard record
- https://github.com/pfsense/pfsense/pull/4038
It seems to me the wildcard checkbox is intended for providers that o... -
12:14 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- ok i will work on it and create a PR to change rate by iftop as soon as it works
(normaly it should be ok on sunday ... -
12:02 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- That does help a bit. It would be even better if iftop had an output mode like libxo where it would be trivial to par...
-
11:22 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Jim Pingle wrote:
> I'd love to see rate swapped out for iftop (which does support IPv6) but the output of iftop i...-
10:30 AM Bug #9276 (Resolved): DNS troubleshooting tool incorrectly reporting "ai." as an invalid hostname
- To reproduce:
Navigate to Diagnostics=>DNS Lookup (found at /diag_dns.php). Enter any TLD that should work as a si... -
08:31 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
- Hello,
One of my two firewalls has developed this issue - I can confirm disabling the WAN adapter resolved this sl... -
07:49 AM Feature #7416: DHCPv4 client does not support ``supersede`` statement for option 54
- The reply on the FreeBSD PR is ambiguous at best. It would also help if someone that was actually a part of the FreeB...
-
07:42 AM Feature #7416: DHCPv4 client does not support ``supersede`` statement for option 54
- I beg to differ and hope I'm not mistaken, but AFAIK Franco pulled that already into OPNsense and the last statement ...
-
07:21 AM Feature #7416: DHCPv4 client does not support ``supersede`` statement for option 54
- Might be, but it's still an open issue and hasn't been accepted into FreeBSD yet. There isn't even one person on that...
-
06:22 AM Feature #7416: DHCPv4 client does not support ``supersede`` statement for option 54
- @Jimp
I maybe wrong but isn't that the corresponding fix/workaround from upstream to this particular problem?
Cou...
01/16/2019
-
05:39 PM Bug #9275 (Resolved): ip tools link not working
- just discovered in 2.4.5 snapshots.. ip tools are not working http://private.dnsstuff.com/tools/whois.ch?ip= and...
-
10:24 AM Revision 28a5469e: add trim() to $_POST['auth_user'] & $_POST['auth_user2']
-
04:26 AM Feature #9274: CP - trim() username post_value
- https://github.com/pfsense/pfsense/pull/4037
-
04:24 AM Feature #9274 (Resolved): CP - trim() username post_value
- to trim leading & trailing whitespace of the username that is entered when signin in to captive-portal.
see [[https:... -
02:26 AM pfSense Packages Bug #9273 (Closed): missing Include=/usr/local/etc/zabbix4/zabbix_agentd.conf.d in /usr/local/etc/zabbix40/zabbix_agentd.conf
- because of the missing include line in the zabbix_agentd.conf, UserParameter definitions are not loaded.
we are us...
01/15/2019
-
11:55 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
- Jim Pingle wrote:
> The underlying program, rate, still doesn't work with IPv6 as far as I'm aware.
>
> I'd love ... -
09:49 PM Bug #7439: IKE_SA (IKEv2) does not rekey on break before make startegy, just issues IKE_DELETE and connection is closed
- I would like to reopen this thread as I'm experiencing same problem and I'm on 2.4.4-RELEASE (amd64)
My configuratio... -
09:40 PM Revision bd0a29ea: Linode Dynamic DNS syntax fixes
-
09:33 PM Revision b923a825: Add Dynamic DNS support for Linode #9268
-
04:35 PM pfSense Packages Feature #9272 (Resolved): Allow multiple IP in ListenIP for Zabbix Agent
- The web interface for the zabbix-agent service does not allow to add multiple IPs comma separated. The validation rul...
-
02:50 PM Bug #9271 (Resolved): Azure DDNS whitespace cleanup
- Fix some indenting surrounding the Azure DDNS implementation to be consistent with the rest of the file.
https://g... -
12:38 PM pfSense Packages Feature #8613: pfSense-pkg-acme: acme_certificates_edit.php - Add support for --challenge-alias acme.sh flag
- Markus Barckmann wrote:
>
> It would be very nice to have a UI option to choose between this two (sub)methods.
... -
11:17 AM pfSense Packages Feature #8574: Enable AgentX-support in lldpd using GUI
- The above patch works for me. The Net-SNMP package already adds "master agentx" to /var/etc/netsnmpd.conf by default...
-
09:32 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
- Hi,
I just test it :
- Loading dashboard normaly takes about 1 second or less.
- Without WAN connectivity, it ... -
07:26 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
- Hi Luke,
Thanks for the suggestion but I've tried that, same issue.
It looks like whatever is timing out due to... -
06:57 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
- If you remove all widgets from the dashboard does that help at all? It's probably a widget that's causing this delay.
-
06:52 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
- To add to this bug we've been using pfSense 2.3.5 for an internal project and its been working brilliantly.
We're ...
01/14/2019
-
09:56 PM Feature #9268: Add Linode Dynamic DNS support
- https://github.com/pfsense/pfsense/pull/4035
-
10:45 AM Feature #9130: Request ID [#INC-16195]: DHCP - PXE Boot
- I also look for this feature, as described in:
https://forum.netgate.com/topic/138637/ipxe-chainloading
-
07:12 AM pfSense Packages Bug #8873 (Resolved): PHP7 warning in squidguard
-
03:09 AM pfSense Packages Bug #8873: PHP7 warning in squidguard
- i just test it on a fresh install 2.4.4-RELEASE-p2 (amd64)
blank_img works without any error.
Problem solved.
01/13/2019
-
11:02 PM pfSense Packages Bug #9244: FRR Status BGP Summary only shows "IPv4 Unicast Summary"
- Created a pull request.
Changed this on my 2.4.4p2 with FRR 0.2_4
"show ip bgp summary $" to "show bgp summary ... -
01:25 PM Bug #9270 (Resolved): "Remove all states to and from the filtered address" does not remove all states
- Simple use case:
Filter all states for an IP of any device (used my iPhone IP) in *_"Diagnostics"/"States"/"States_"... -
10:45 AM Bug #9269: No Internet after reboot, wrong gateway.
- Forum link: https://forum.netgate.com/topic/139570/no-internet-after-reboot-wrong-gateway
-
10:17 AM pfSense Packages Bug #8872 (Resolved): PHP7 error in squid
-
09:59 AM pfSense Packages Bug #8872: PHP7 error in squid
- sorry Jim, i just tested it before my comment on : 2.4.4-RELEASE-p2 (amd64)
i try " _edit/save options on the squid... -
09:40 AM pfSense Packages Bug #8872: PHP7 error in squid
- That commit is already referenced above. It must be tested and confirmed as fixed.
-
06:32 AM pfSense Packages Bug #8872: PHP7 error in squid
- should be solved since this commit : https://github.com/pfsense/FreeBSD-ports/commit/90c367bf2f2fcd61ed631bd3c4fd6634...
-
09:43 AM Bug #8142 (Resolved): OpenVPN client does not remove static route for custom monitor IP
- In the forum thread, others who could reproduce it were also on airvpn, so it is likely specific to something that pr...
-
07:58 AM Bug #8142: OpenVPN client does not remove static route for custom monitor IP
- I'm not able to reproduce this on 2.4.4p1. However, I will say I'm also no longer using the same vpn provider. I'm ...
-
09:40 AM pfSense Packages Bug #8873: PHP7 warning in squidguard
- That commit is already referenced in the first comment on this issue.
A fix was committed, but it needs to be test... -
06:25 AM pfSense Packages Bug #8873: PHP7 warning in squidguard
- i bet this issue was solved by this commit https://github.com/pfsense/FreeBSD-ports/commit/824d08577196346be0e7d24d92...
-
09:36 AM Bug #1690 (Resolved): PPPoE Server not passing IP from RADIUS server
-
12:23 AM Bug #1690: PPPoE Server not passing IP from RADIUS server
- Seems to be working as of latest dev release with freeradius (daloradius).
01/12/2019
-
09:38 PM Bug #9269 (Rejected): No Internet after reboot, wrong gateway.
- There isn't enough here for a valid bug report. Please start a forum thread to discuss and diagnose the issue. If a s...
-
09:33 PM Bug #9269 (Rejected): No Internet after reboot, wrong gateway.
- I'm running pfsense from a USB key that slows down after a few days unless I reboot the box and everything's back to ...
-
09:20 PM Bug #8142: OpenVPN client does not remove static route for custom monitor IP
- Is this issue still present in the latest development build? If so, what are the specific steps to reproduce the beha...
-
09:20 PM Feature #5675 (Resolved): Theme specific textarea background color
-
09:16 PM Feature #5675: Theme specific textarea background color
- Yep
-
09:13 PM Feature #5675: Theme specific textarea background color
- Can this be marked resolved?
-
09:19 PM pfSense Packages Bug #8872: PHP7 error in squid
- If you're on 2.4.4 or later, edit/save options on the squid cache settings tab.
-
09:02 PM pfSense Packages Bug #8872: PHP7 error in squid
- How to reproduce the issue?
-
09:18 PM pfSense Packages Bug #8873: PHP7 warning in squidguard
- Looks like it would take activating and tripping a squidGuard filter that replaced content with a blank image. If it ...
-
09:03 PM pfSense Packages Bug #8873: PHP7 warning in squidguard
- How to reproduce the issue?
-
09:18 PM Bug #6896: unbound root.key file corruption possibly related to full file system
- Looks like the OP traced the issue, can the report be marked resolved now?
-
09:15 PM pfSense Packages Bug #8780: Apcupsd PHP errors in 2.4.4 snapshot
- It wasn't really the upgrade that did anything. Only need to test apcupsd on 2.4.4 or later to make sure there are no...
-
09:01 PM pfSense Packages Bug #8780: Apcupsd PHP errors in 2.4.4 snapshot
- There is no way to test this, without an instance of pfSense already running 2.4.3 *with* apcupsd already installed.
... -
09:09 PM Bug #1690: PPPoE Server not passing IP from RADIUS server
- Is this issue still present in the latest development build?
-
09:07 PM Bug #1575: Limiters are bypassed by local applications injecting rules
- Is this issue still present in the latest development build?
-
08:05 PM Bug #9264: Disabling "IPv6 over IPv4 Tunneling" breaks config
- On 2.4.5.a.20190111.1435 (stock - factory default), able to reproduce the behavior....
- 01:42 PM Revision 58d009bc: Update gwlb.inc
-
11:16 AM Feature #9268 (Resolved): Add Linode Dynamic DNS support
- Let's add support for updating Linode DNS as a Dynamic DNS provider using their v4 REST API and Personal Access Token...
01/11/2019
-
08:05 PM Feature #1831: Captive portal IPv6 support
- PHP RADIUS package (used for RADIUS authentication/accounting) is not IPv6 compatible, which is a captive portal depe...
-
07:06 PM Bug #7801: UDP fragments received over IPsec tunnel are not properly reassembled and forwarded
- Hi, I have been waiting a year for that fix, for us, it's RDS sessions that disconnects randomly when using UDP over ...
- 04:41 PM Revision 67dd34a0: Update gwlb.inc
- Correct BUG 9004 -> set the default gateway when system start and a gateway_group is default IPV4 gateway
-
12:34 PM pfSense Packages Bug #8476: OpenVPN Client Export TLS Key Direction Directive Location
- Tested on:
2.4.4-RELEASE-p2 (amd64)
built on Wed Dec 12 14:40:29 EST 2018
FreeBSD 11.2-RELEASE-p6
client expo... -
11:15 AM Bug #9266: status_monitoring.php : failed to have quality graph
- A direct acccess to https://x.x.x.x/rrd_fetch_json.php display { "error" : "Invalid RRD file" }
Checking if the fi... -
10:16 AM Bug #9004: Default gateway IPv4 set to a group fails after restart on 2.4.4
- I think i found the bug
file /etc/inc/gwlb.inc... -
01:01 AM pfSense Packages Bug #9211: GeoIP broken in pfSense-pkg-ntopng-0.8.13_3
- in the topic mentioned above there has been found a possible cause for this:
> "Using pfSense 2.4.4-RELEASE-p2 wit...
01/10/2019
-
10:25 PM Bug #9267: dhclient does not handle protocol timeouts or script failures correctly
- Also to add, this is seen on version 2.4.4-RELEASE-p1 (amd64),
FreeBSD 11.2-RELEASE-p4, but affects versions back at... -
07:49 PM Bug #9267 (Resolved): dhclient does not handle protocol timeouts or script failures correctly
- pfSense-dhclient-script fails to return nonzero in the case where a DHCP timeout occurs and the cached gateway addres...
-
02:00 PM Revision 4ec6eee8: Fix saving IPv6 over IPv4 tunneling NAT setting. Fixes #9264
- (cherry picked from commit 3fcf5ad71216922921801d85d063d360fde5566f)
-
01:59 PM Revision 3fcf5ad7: Fix saving IPv6 over IPv4 tunneling NAT setting. Fixes #9264
-
01:48 PM Feature #1831: Captive portal IPv6 support
- It's 2019 and guess what: This is still missing, while the fixes were apparently ready years ago....
-
12:32 PM Bug #9266: status_monitoring.php : failed to have quality graph
- Hi David,
I just try to reproduce but without any success.
Even on a fresh install 2.4.4-RELEASE-p2 (amd64) or an... -
11:14 AM Bug #9266 (Not a Bug): status_monitoring.php : failed to have quality graph
- Problem :
---------------------------------------------------------
Status, Monitoring, failed to display the quali... -
08:05 AM Bug #9264 (Feedback): Disabling "IPv6 over IPv4 Tunneling" breaks config
- Applied in changeset commit:3fcf5ad71216922921801d85d063d360fde5566f.
-
07:19 AM pfSense Packages Feature #9265 (Resolved): Add options to configure TIMEOUTclose and debug on stunnel package
- Hello all...
This PR[1] add options to configure TIMEOUTclose and debug (log level) and also fix package doc URL o...
01/09/2019
-
06:12 PM Bug #9264: Disabling "IPv6 over IPv4 Tunneling" breaks config
- lower urgency now.
I fixed my local config with viconfig.
The setting that got stick is 'ipvnat'
It looked l... -
05:57 PM Bug #9264: Disabling "IPv6 over IPv4 Tunneling" breaks config
- Raising urgency of bug, as it seems it does actually prevent toggling other settings on the networking page. Until I...
-
05:54 PM Bug #9264: Disabling "IPv6 over IPv4 Tunneling" breaks config
- missed step 4 which is hit save and apply again.
-
05:53 PM Bug #9264 (Resolved): Disabling "IPv6 over IPv4 Tunneling" breaks config
- Steps that may possibly reproduce.
1 - enable "IPv6 over IPv4 Tunneling" and set an ip address in the "ipv4 addres... -
08:11 AM Bug #9239: WebGUI: Diagnostics > Packet Capture will try to display any size of pcap file.
- Even when downloading a too large capture it will fail..... (it just has to be large enough).
-
08:08 AM pfSense Packages Feature #9227: Please include Tinc in base pfSense, as a standard way of configuring tunnels
- I don't see the advantage by installing it by default, the whole purpose of packages is to make the base system not t...
01/08/2019
-
04:57 PM Bug #9123: Adding/configuring vlan on ixl-devices causes aq_add_macvlan err -53, aq_error 14
- Not sure about the similarity of conditions yet, but I'm seeing this message being logged on my FreeNAS box with the ...
-
03:04 PM Bug #9263: Incorrect ICMP reply when using limiters
- Relevant forum topics:
https://forum.netgate.com/post/815824
https://forum.netgate.com/topic/137090/traceroute-omit... -
03:01 PM Bug #9263 (Resolved): Incorrect ICMP reply when using limiters
- My setup is as follows. pfSense 2.4.4_p2, it maintains a L2TP tunnel to my ISP and all the traffic is configured to g...
-
12:41 PM pfSense Packages Bug #9261: haproxy GUI failure
- The acl "Traffic is ssl (no value needed)" is using the actual haproxy option: "req.ssl_ver gt 0" this is one that on...
-
11:23 AM pfSense Packages Bug #9261 (New): haproxy GUI failure
- The GUI is misbehaving. I'm unable to add a specific ACL via the GUI. Simply adding "http-request redirect scheme htt...
-
11:37 AM Feature #9262 (Duplicate): Strongswan DHCP plugin
- Would it be possible for the DHCP plugin for Strongswan to be implemented? (https://wiki.strongswan.org/projects/stro...
-
12:56 AM Feature #9260: ssh_tunnel_shell: Disable console message output
- It’s worse than that. If I’m looking at the right source, that binary does nothing but chatter at the poor user.
...
01/07/2019
-
09:53 PM Revision 14b1c98d: Unbound python integration
- * Add changes as requested by @jim-p
-
07:22 PM Revision a4ca3a94: pfSense Unbound - Mount folders for python
- * DNS Resolver python integration
-
03:09 PM Feature #9251: DNS Resolver (Unbound) Python Integration
- +1 : good feature !
nice work! -
01:26 PM Feature #9251: DNS Resolver (Unbound) Python Integration
- The final code for mounting the /bin and /lib folders has been submitted for review (Services.inc):
https://github.c... -
01:59 PM Revision 0d869333: Disable RUST option for aarch64 as well
-
01:59 PM Revision 32bec44e: Disable RUST option for aarch64 as well
-
01:54 PM Revision 69581e1c: Fix syntax
-
01:54 PM Revision 06aaf56e: Fix syntax
-
01:41 PM Revision f4cd1d1a: Re-enable suricata, without RUST, for armv6
-
01:40 PM Revision f33ab193: Re-enable suricata, without RUST, for armv6
-
01:09 PM Feature #8511: Dynamic DNS: Cloudflare Add TTL option
- +1 I suggest allowing the TTL setting to be a configurable value, as it is for other Dynamic DNS clients, such as Azu...
-
12:55 PM Feature #855: Ability to selectively kill states on gateway recovery
- +1 I'm surprised this isn't already a feature. I noticed this today when we our primary connection came back online, ...
-
12:55 PM Revision faf91e6a: Fix suricata port path
-
12:43 PM Revision f236aa92: Disable drm-kmod and suricata on ARMv6
-
12:43 PM Revision 25722094: Sort
-
12:35 PM Revision d8317463: Disable drm-kmod and suricata on ARMv6
-
12:34 PM Revision a14df366: Remove rust, it's suricata dependency now
-
12:34 PM Revision 46970457: Sort
-
11:28 AM Bug #9259: User with "Deny Config Write" privilege is not fully prevented from creating accounts
- The only way you can see that "Deny Config Write" message is if your user, or a group they are in, has the "Deny Conf...
-
11:04 AM Bug #9259: User with "Deny Config Write" privilege is not fully prevented from creating accounts
- That is not the case. I just have tried another system, where this issue does not show. My latest install does behave...
-
08:17 AM Bug #9259: User with "Deny Config Write" privilege is not fully prevented from creating accounts
- You must have incorrectly added the "User - Config: Deny Config Write" privilege to your admin group, which is common...
-
04:24 AM Bug #9259 (Resolved): User with "Deny Config Write" privilege is not fully prevented from creating accounts
- I do log into the web GUI as a user "myuser" with admin group membership (other than the builtin admin/root). I used ...
-
07:50 AM Feature #9260 (Resolved): ssh_tunnel_shell: Disable console message output
- Users with only the "User - System: SSH Tunneling" privilege get the @ssh_tunnel_shell@ program as their shell. When ...
-
01:19 AM Bug #9258: Error deleting tunnel type P2 when mixed with VTI
- Edit:
Workaround:
1. disable vti interface
2. remove all unwanted p2
3. enable vti interface -
01:16 AM Bug #9258 (Resolved): Error deleting tunnel type P2 when mixed with VTI
- When trying to delete a (tunnel mode) phase 2 entry were both "tunnel" and "vti" modes are mixed the GUI is respondin...
01/06/2019
-
10:53 AM Feature #6240: vxlan driver
- +1
-
09:44 AM Feature #5644: Captive Portal retain logins across reboot
- Pull Request : https://github.com/pfsense/pfsense/pull/4054
-
09:14 AM Bug #9255: Potential performance issue when using multiple authentication servers in a zone
- Pull Request : https://github.com/pfsense/pfsense/pull/4056
-
08:33 AM Bug #8616: When reconfiguring a captiveportal, connected users get disconnected and can't login back
- -Pull Request : https://github.com/pfsense/pfsense/pull/4031-
Netgate choosed to fix this issue in another way. ne... -
07:18 AM pfSense Packages Feature #9257 (Duplicate): add more servers to acme
- Support for that is already in ACME 0.5, available on 2.4.5 snapshots. If stable, it will be made available for 2.4.4...
-
04:04 AM pfSense Packages Feature #9257 (Duplicate): add more servers to acme
- Hi,
The Security Researcher Scott Helme has just blogged about an alternative to Let's Encrypt; https://scotthelme... -
02:56 AM Revision 7e114786: making sure my tabs align with upstream
-
02:46 AM Revision 059538ad: adjust GEOM rebuild notifications to only notify the user when raid rebuild hits 25% increments
- When a geom rebuild is occurring, this script by default notices that the device status has changed every time the re...
Also available in: Atom