Project

General

Profile

Activity

From 01/15/2019 to 02/13/2019

02/13/2019

07:39 PM Revision 2944e2f7: Revert "Fix the build of net-mgmt/net-snmp on 12, disable the TLS support for now."
This reverts commit 39d77ff1985789c7edb352ba4697355e591b7622. Luiz Souza
07:11 PM pfSense Packages Bug #9322 (Resolved): telegraf "Additional configuration for Telegraf" lost configuration after reboot
Version: 2.4.5.a.20190211.0331
after reboot, the "Additional configuration for Telegraf" appending configurations ...
mrco chen
06:48 PM Revision 98e71167: Fix the build of security/openssl.
The PADLOCK cannot be fetched. Luiz Souza
04:36 PM Revision 6b2acc67: Disable other GSSAPI options to prevent conflict
Renato Botelho
04:23 PM Revision b018b7af: Build p5-GSSAPI using MIT while using openssl from ports
Renato Botelho
04:19 PM Revision d73d911c: Use the OpenSSL from ports for now.
This should allow the build of the broken ports (no OpenSSL 1.1.0 support). Luiz Souza
03:16 PM Bug #9321 (Rejected): Traffic Graphs on Dashboard not loading with certain types of interfaces
Traffic Graph is not loading at all when GRE, OpenVPN or IPSec graphs are enabled because it doesn't receive data for... Flole Systems
02:47 PM Revision a432c227: Revert "Don't use DISTFILES_CACHE"
This reverts commit 683a0581699f2654c9673a73dec696c929238a32. Renato Botelho
02:46 PM Revision 382c5ba6: Revert "Don't use DISTFILES_CACHE"
This reverts commit 81041332b295b383d85ee3057d5d4d626c73cdc2. Renato Botelho
02:38 PM Revision a73f3147: Disable the build of www/pound for now, it is not compatible with OpenSSL 1.1.0.
Luiz Souza
02:27 PM Revision 39d77ff1: Fix the build of net-mgmt/net-snmp on 12, disable the TLS support for now.
Luiz Souza
01:59 PM Revision b761d75c: Fix the build of miniupnpd in 12, disable CHECK_PORTINUSE.
Luiz Souza
01:39 PM Revision 978ebbf7: Fix OU Name DN entry when creating a user cert. Fixes #9317
(cherry picked from commit 354b1c750d9eeb9ccf0dc22033c9c813ec88e6f3) Jim Pingle
01:39 PM Revision edf4b0fb: Correct syntax error in diag_backup.php. Fixes #9316
(cherry picked from commit e0b32eb9e6b040fd14025b5c32644959ba67250e) Jim Pingle
01:38 PM Revision be8a5a8a: Force the <enableserial> on when restoring a backup on a device with serial only console.
Affects multiple devices.
Ticket #1547
(cherry picked from commit c91af4ac6a6b501b59a542acb4ace05e2b10e3ea)
Luiz Souza
01:37 PM Revision 354b1c75: Fix OU Name DN entry when creating a user cert. Fixes #9317
Jim Pingle
01:36 PM Revision e0b32eb9: Correct syntax error in diag_backup.php. Fixes #9316
Jim Pingle
01:11 PM Revision 4a3c0547: Bump version to 2.5.0-DEVELOPMENT and use RELENG_2_5 branch, based on FreeBSD 12.x
Renato Botelho
12:04 PM Bug #9320 (Resolved): Outbound NAT and multiple IPSEC IPs for mobile warriors
https://github.com/pfsense/pfsense/pull/4049
Normally all IPs are added to the automatic outbound NAT. With the ch...
Christian R.
11:15 AM Bug #9319 (Duplicate): Certificates synced even with disabled Sync option - "Certificate Authorities, Certificates, and Certificate Revocation Lists"
Duplicate of #9283 which is already fixed. Jim Pingle
11:09 AM Bug #9319 (Duplicate): Certificates synced even with disabled Sync option - "Certificate Authorities, Certificates, and Certificate Revocation Lists"
Certificates and CA's are still being synced from primary to secondary even with disabled Sync option - "Certificate ... Vladimir Lind
07:45 AM Bug #9317 (Feedback): Warning/crash when adding a new user and choosing to generate a certificate
Applied in changeset commit:354b1c750d9eeb9ccf0dc22033c9c813ec88e6f3. Jim Pingle
07:42 AM Bug #9317 (In Progress): Warning/crash when adding a new user and choosing to generate a certificate
Jim Pingle
12:48 AM Bug #9317 (Resolved): Warning/crash when adding a new user and choosing to generate a certificate
User and certificate are created fine, but this crash is reported, running 2.4.5.a.20190212.1501
Crash report begi...
Mohamed Eltantawi
07:45 AM Bug #9316 (Feedback): diag_backup.php: Parse error: syntax error, unexpected ';' in /usr/local/www/diag_backup.php on line 333
Applied in changeset commit:e0b32eb9e6b040fd14025b5c32644959ba67250e. Jim Pingle
07:41 AM Bug #9316 (In Progress): diag_backup.php: Parse error: syntax error, unexpected ';' in /usr/local/www/diag_backup.php on line 333
Jim Pingle
12:44 AM Bug #9316: diag_backup.php: Parse error: syntax error, unexpected ';' in /usr/local/www/diag_backup.php on line 333
No configuration can be backed up or restored due to this crash. Mohamed Eltantawi
12:43 AM Bug #9316 (Resolved): diag_backup.php: Parse error: syntax error, unexpected ';' in /usr/local/www/diag_backup.php on line 333
Running 2.4.5.a.20190212.1501
Crash report begins. Anonymous machine information:
amd64
11.2-RELEASE-p8
Free...
Mohamed Eltantawi
07:44 AM pfSense Packages Bug #9318 (Not a Bug): Acme - standalone validation takes long time to start internal server
Not seeing a bug there. Please keep the discussion on the forum unless something specific can be identified. That's a... Jim Pingle
03:30 AM pfSense Packages Bug #9318 (Resolved): Acme - standalone validation takes long time to start internal server
Hi!
As per post here: https://forum.netgate.com/topic/140537/certificate-long-time-to-issue
I have ACME in stan...
Greg M

02/12/2019

10:59 PM pfSense Packages Bug #8067: Avahi can't be stopped from registering on unassigned interfaces
I'm also impacted by this issue.
https://forum.netgate.com/topic/137256/avahi-openvpn-missing-from-deny-interfaces
John Marzella
10:48 PM Revision c91af4ac: Force the <enableserial> on when restoring a backup on a device with serial only console.
Affects multiple devices.
Ticket #1547
Luiz Souza
03:32 PM Revision b473b576: Fix limiter selection validation.
(cherry picked from commit d0e9c310708fe7be6de86fe082f57e1fc27ce143) Jim Pingle
03:32 PM Revision d0e9c310: Fix limiter selection validation.
Jim Pingle
03:24 PM Revision 95246687: Test $sform before use, fixes #9313
(cherry picked from commit 069585172e6408195b16bbe3090aeba56699ee51) Jim Pingle
03:23 PM Revision 06958517: Test $sform before use, fixes #9313
Jim Pingle
09:30 AM Bug #9313 (Feedback): PHP Fatal error: Uncaught Error: Call to a member function addGlobal() on null in /usr/local/www/firewall_shaper_vinterface.php:415
Applied in changeset commit:069585172e6408195b16bbe3090aeba56699ee51. Jim Pingle
09:23 AM Bug #9313 (In Progress): PHP Fatal error: Uncaught Error: Call to a member function addGlobal() on null in /usr/local/www/firewall_shaper_vinterface.php:415
OK, I was able to reproduce it following your procedure, hitting a URL for a queue that had already been deleted.
...
Jim Pingle

02/11/2019

04:34 PM Bug #9313: PHP Fatal error: Uncaught Error: Call to a member function addGlobal() on null in /usr/local/www/firewall_shaper_vinterface.php:415
Extra note:
The next line shows that I did get from the queue "delete" action to the "show" action of the same que...
Anonymous
04:27 PM Bug #9313: PHP Fatal error: Uncaught Error: Call to a member function addGlobal() on null in /usr/local/www/firewall_shaper_vinterface.php:415
I looked at the code - I guess that $sform is null.
By default $dontshow is false. So by default it will expect $...
Anonymous
02:50 PM Bug #9313 (Feedback): PHP Fatal error: Uncaught Error: Call to a member function addGlobal() on null in /usr/local/www/firewall_shaper_vinterface.php:415
Jim Pingle
02:50 PM Bug #9313: PHP Fatal error: Uncaught Error: Call to a member function addGlobal() on null in /usr/local/www/firewall_shaper_vinterface.php:415
There must be something unique to your configuration triggering this. It does not appear to be a general issue affect... Jim Pingle

02/10/2019

04:50 PM pfSense Packages Feature #9315 (New): Add Package: dnscrypt-proxy
!https://i.ibb.co/1GdDyGs/dnscrypt-proxy.png!
Hi all,
I've lately been manually installing the awesome GitHub p...
neo b.
03:01 PM Bug #9314 (Not a Bug): if interface list is longer then the browser window is high you cant manage all interfaces
That can only happen if you have the menu set to stay in the browser window when you scroll. Change it to stay at the... Jim Pingle
02:41 PM Bug #9314 (Not a Bug): if interface list is longer then the browser window is high you cant manage all interfaces
Hi!
We just added another 30 interfaces to our pfSense setup (Alot of VLAN) and i noticed that if the list of inte...
Ola Ekegren
11:02 AM Bug #9313 (Resolved): PHP Fatal error: Uncaught Error: Call to a member function addGlobal() on null in /usr/local/www/firewall_shaper_vinterface.php:415
Crash report begins. Anonymous machine information:
arm
11.2-RELEASE-p6
FreeBSD 11.2-RELEASE-p6 #4 ed5153fb2b9(...
Anonymous

02/09/2019

08:37 PM pfSense Packages Bug #9312 (Duplicate): Once nmap package completes a scan, the pfSense menu becomes unresponsive
Duplicate of #8502 Jim Pingle
01:54 PM pfSense Packages Bug #9312 (Duplicate): Once nmap package completes a scan, the pfSense menu becomes unresponsive
On latest 2.4.5 snapshot, with nmap package version 1.4.4_1, once a user runs a scan in the WebGUI with nmap, the pfS... Anonymous
03:10 AM Feature #6960: Introduce Kea DHCP as an alternative DHCP server for IPv4 and IPv6
Any progress on Kea dhcp? It looks like ISC has allocated more resources to Kea and put the legacy ISC dhcp in the ba... Bogdan P
01:29 AM Bug #9311 (Resolved): Captive Portal continues to limit per-user bandwidth when not enabled
In a Captive Portal, this bug occurs after using the "Enable per-user bandwidth restriction" feature and specifying d... Polar Nerd

02/08/2019

03:07 PM Bug #6876: Firewall alias issue after adding a wrong alias
Tried to reproduce on latest 2.4.5 snapshot:
Made a couple of aliases, one for the machine I am using to connect t...
Anonymous
01:25 PM pfSense Docs Correction #9310: Appliances with internal switch need the MAC Address section of their Getting Started guides updated
For SG-1100 where the user wants to spoof the MAC address for WAN in a single-WAN configuration, the user can assign ... Anonymous
10:29 AM pfSense Packages Feature #9265 (Resolved): Add options to configure TIMEOUTclose and debug on stunnel package
Jim Pingle
10:23 AM pfSense Packages Feature #9265: Add options to configure TIMEOUTclose and debug on stunnel package
tested on CE built on Thu Feb 07 19:44:20 EST 2019 <--> factory built on Thu Feb 07 18:13:07 EST 2019
tested web ...
Vladimir Lind
07:12 AM Bug #9004: Default gateway IPv4 set to a group fails after restart on 2.4.4
Normally work on 2.4.4 p1 & p2 for sure, maybe 2.4.4
try this :...
jonathan MANTOVANI
07:06 AM Bug #9004: Default gateway IPv4 set to a group fails after restart on 2.4.4
Ioannis Kampolis wrote:
> jonathan's fix works.
>
> Thank you very much!
Tried on 2.4.4-RELEASE and the code g...
Tiago Alves da Silva

02/07/2019

09:14 PM pfSense Docs Correction #9310 (Closed): Appliances with internal switch need the MAC Address section of their Getting Started guides updated
At https://docs.netgate.com/pfsense/en/latest/solutions/sg-1100/getting-started.html#mac-address
https://docs.netg...
Anonymous
04:24 PM Revision 51b58d81: Ticket #9308: Sort country codes
Renato Botelho
04:24 PM Revision 63cf3f32: Ticket #9308: Sort country codes
Renato Botelho
03:48 PM Feature #1831: Captive portal IPv6 support
If authentication is based on IP Address yes, if it would be based on MAC Address then no.
If it's not MAC based t...
Flole Systems
03:37 PM Revision 70cee41e: Fix #9308: Obsolete now unused /etc/ca_countries
Renato Botelho
03:37 PM Revision 54d88644: Ticket #9308: Replace use of /etc/ca_countries by get_cert_country_codes()
Renato Botelho
03:37 PM Revision a56762ba: Ticket #9308: Implement get_cert_country_codes() to get the list of country codes to be used by CAs and Certs
Renato Botelho
03:37 PM Revision 988640d3: Make get_countr_code() parameter default to 'ALL'
Renato Botelho
03:35 PM Revision a2b80f45: Fix #9308: Obsolete now unused /etc/ca_countries
Renato Botelho
03:34 PM Revision 232b1a69: Ticket #9308: Replace use of /etc/ca_countries by get_cert_country_codes()
Renato Botelho
03:34 PM Revision 6a532672: Ticket #9308: Implement get_cert_country_codes() to get the list of country codes to be used by CAs and Certs
Renato Botelho
02:57 PM Revision d166b7e2: Make get_countr_code() parameter default to 'ALL'
Renato Botelho
02:29 PM Feature #9309: Allow manual selection of IPsec IKE Pseudo-Random Function (PRF)
Thanks Jim for pointing out the documentation - but the documentation does not match the implementation:
The docum...
Florian K.
01:42 PM Feature #9309: Allow manual selection of IPsec IKE Pseudo-Random Function (PRF)
That's what AES-XCBC is for:
https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/configuring-a-site-to-site-ipsec...
Jim Pingle
01:26 PM Feature #9309 (Resolved): Allow manual selection of IPsec IKE Pseudo-Random Function (PRF)
If you want to use AES-GCM, you don't need an integrity algorithm, but you do need a pseudo random function.
See h...
Florian K.
10:59 AM Bug #9308: Missing countries from list used on certificate pages
Fix works for me here, will re-test once it's in a snapshot. Jim Pingle
09:45 AM Bug #9308 (Feedback): Missing countries from list used on certificate pages
Applied in changeset commit:a2b80f4510faf81850c7d51ba6ed7aacf978433c. Renato Botelho
09:28 AM Bug #9308 (Resolved): Missing countries from list used on certificate pages
Country codes list used when creating CAs and certs is obtained from /etc/ca_countries instead of Country list from I... Renato Botelho

02/06/2019

07:13 PM Revision 7e8bfed2: Add back DNS over TLS host verification code. Fixes #8602
Requires Unbound 1.9.0_1 from pfsense/freebsd-ports, which fixes a bug
in Unbound 1.9.0 which did not fully implement...
Jim Pingle
03:27 PM Bug #9307: Virtual Address Pool in Pre-Shared Keys is not used
Jim Pingle wrote:
> Probably a configuration issue or it isn't matching the identifier as expected. Post on the foru...
Florian K.
03:27 PM Bug #9307: Virtual Address Pool in Pre-Shared Keys is not used
Additional observation:
- On the status page under "Leases", it shows both pools, but 192.168.7.0 is never used.
- ...
Florian K.
02:40 PM Bug #9307 (Not a Bug): Virtual Address Pool in Pre-Shared Keys is not used
Probably a configuration issue or it isn't matching the identifier as expected. Post on the forum unless a specific b... Jim Pingle
02:35 PM Bug #9307 (Not a Bug): Virtual Address Pool in Pre-Shared Keys is not used
For most of my road warriors, I want to have different firewall rules than for e.g. me.
Therefore, I assigned a defa...
Florian K.
01:26 PM Feature #8602: DNS over TLS host verification
The next build that includes unbound 1.9.0_1 and the changes referenced on this issue will be ready for testing. Usin... Jim Pingle
01:20 PM Feature #8602 (Feedback): DNS over TLS host verification
Applied in changeset commit:7e8bfed216304b37342a0800eb35ef7c29546f5d. Jim Pingle
01:09 PM Feature #8602: DNS over TLS host verification
Unbound 1.9.0 added support for verifying hosts on OpenSSL 1.0.2, but it still doesn't seem to work. Unbound 1.9.0 is... Jim Pingle
08:17 AM Bug #9306 (Duplicate): DNS Made Easy client on PPPoE interface not working
To recreate, setup a DNS Made Easy DDNS client on a DHCP WAN interface and confirm that it works. Then switch the int... Corey Boyle

02/05/2019

11:52 AM pfSense Docs Correction #9305 (Resolved): Feedback on Virtual LANs (VLANs) — pfSense VLAN Configuration
*Page:* https://www.netgate.com/docs/pfsense/book/vlan/pfsense-vlan-configuration.html
*Feedback:* In the section ...
Alex Brothman

02/04/2019

09:45 PM Revision d6601c8f: Also trim if() statement
A FL
02:18 PM Feature #7618: Add support for user-supplied Host-Uniq tag and handle PADM messages in Netgraph PPPoE
I've created a pull request -to my own branch for tests, when stable I'll pull the request- to pfSense master.
Li...
Nano Caiordo
07:20 AM Bug #6896 (Not a Bug): unbound root.key file corruption possibly related to full file system
Jim Pingle
06:03 AM Bug #9148 (Feedback): PPPoE over a VLAN fails to reconnect.
This should be fixed in 2.4.4p2 Steve Wheeler
05:39 AM Feature #1831: Captive portal IPv6 support
Flole Systems wrote:
> Unfortunately that site is down. However, I've done some additional research and it seems lik...
Mantas Mikulėnas
05:12 AM Bug #6579: IPv6 CARP VIPs lost upon config sync where they include non-significant zeros
I have just experienced an interesting mutation of the issue. My IPv6 CARP virtual address was ending with zero: fddf... Yaroslav Sokolov

02/03/2019

05:08 PM Feature #9304: DNS Rebind Protection should be configurable, defaults should be more sensible
The problem I ran into with the stock configuration is that there's absolutely no way to disable DNS rebind protectio... Andrew Bobulsky
04:57 PM Feature #9304: DNS Rebind Protection should be configurable, defaults should be more sensible
The default is fine as-is, it is the most secure assumption and safest.
There are documented ways to make exceptio...
Jim Pingle
04:53 PM Feature #9304 (Resolved): DNS Rebind Protection should be configurable, defaults should be more sensible
h2. Problem
The DNS rebind protection approach currently being used by pfSense is too heavy handed. It indiscrimi...
Andrew Bobulsky
07:19 AM Bug #9303: HA sync : disabling captive portal HA sync does remove all zones on slave
fix : https://github.com/pfsense/pfsense/commit/3d382f50c3a25230e7166e9877a0d88c7e62c24b.diff
(if you want to apply ...
A FL
07:13 AM Bug #9303 (Resolved): HA sync : disabling captive portal HA sync does remove all zones on slave
Issue #8808 has been fixed in 2.4.4, however the fix induced another problem : unselecting "captive portal" in HA syn... A FL

02/02/2019

04:30 AM Feature #9302: radvd always advertises DNS servers and Domain Search List regardless of M or O flag
An example radvd configuration can be found here:
[http://sophiedogg.com/radvd-and-dhcpd6-server-configuration-for-d...
Elbin Teh
04:27 AM Feature #9302 (Resolved): radvd always advertises DNS servers and Domain Search List regardless of M or O flag
In "Managed" or "Stateless DHCP" mode, DNS servers and Domain Search List should be requested from DHCPv6 Server.
...
Elbin Teh

02/01/2019

06:44 PM pfSense Packages Bug #8780 (Resolved): Apcupsd PHP errors in 2.4.4 snapshot
Got it. Tested on 2.4.5.a.20190201.0810 with apcupsd version 0.3.91_4, no issues. Anonymous
06:39 PM Bug #8633: thousands PHP undef gwname /etc/inc/gwlib.inc line 1210
What are the steps to reproduce this issue? Anonymous
06:34 PM pfSense Packages Bug #8651 (Resolved): another php error (broke stable pfBng)
Not able to reproduce this behavior on 2.4.5.a.20190201.0810 with pfBlockerNG 2.1.4_16. Anonymous
06:21 PM Bug #9275 (Resolved): ip tools link not working
Anonymous
06:03 PM Bug #9275: ip tools link not working
Tested on 2.4.5.a.20190201.0810. Links have been removed. Anonymous
06:20 PM Bug #9239 (Resolved): WebGUI: Diagnostics > Packet Capture will try to display any size of pcap file.
Anonymous
06:20 PM Bug #9239: WebGUI: Diagnostics > Packet Capture will try to display any size of pcap file.
On 2.4.5.a.20190201.0810, tested with an iperf3 traffic stream running over WAN with a simultaneous packet capture on... Anonymous
02:23 PM pfSense Docs Correction #9301 (Resolved): Broken link to HashTab in Verifying Downloaded Image section of Writing OS Image to Media
It was also broken in the pfSense docs. Fixed both.
Jim Pingle
01:52 PM pfSense Docs Correction #9301 (Resolved): Broken link to HashTab in Verifying Downloaded Image section of Writing OS Image to Media
At https://www.netgate.com/docs/reference/create-flash-media.html#verify-the-downloaded-image the link to HashTab sho... Anonymous
11:29 AM Bug #9123: Adding/configuring vlan on ixl-devices causes aq_add_macvlan err -53, aq_error 14
I have tested the FreeBSD Version 11.1, 11.2 and 12.0 on the Hardware and got following results.
+FreeBSD 11.1 (Fr...
Alexander Meckelein
10:22 AM Feature #1831: Captive portal IPv6 support
Unfortunately that site is down. However, I've done some additional research and it seems like others simply use stri... Flole Systems
08:43 AM pfSense Packages Bug #9211: GeoIP broken in pfSense-pkg-ntopng-0.8.13_3
New ntopng 3.8 (December 2018) release supports the GeoIP2 library
* Adds the new libmaxminddb geolocation library
YP Lo

01/31/2019

12:06 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
I believe my issues may be related to this. We updated to 2.4.4 p2 on Jan 9, but only in the past few days have seen ... Eduard Rozenberg
05:32 AM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
I have now prepared a minimal example:
As you can see fqdn1 is missing the entry for one.one.one.one
Please FIX
Ph. T
09:42 AM pfSense Packages Feature #9300 (Rejected): ACME package: last time updated
Did you mean something else besides "Last Updated"? "Last Renewed" would always be the same as "Last Updated".
Unl...
Jim Pingle
12:37 AM pfSense Packages Feature #9300: ACME package: last time updated
Not to be a naysayer, but isn't that a little redundant? Acme knows LE is 90 days and if run manually before Day 60 ... Tyler L
12:09 AM Bug #7609: NTP Status not parsing all NTP Access Restrictions preventing status display when it is actually allowed
As of 2.4.4-p2 issue as described in the original post still exists and has not been resolved.
There are a couple ...
Paul K

01/30/2019

10:13 PM pfSense Packages Feature #9300 (Rejected): ACME package: last time updated
It’s low priority but nice to have.
Please expose in addition to ‘Last renewed’ time stamp “Last updated” on the t...
Yuri Weinstein
10:09 PM pfSense Packages Feature #9299 (New): ACME package : Automate add/remove firewall rule for port forwarding

Currently if user wants to fordward port 80 (for stand alone method for example) to a different port and also not ...
Yuri Weinstein
02:41 PM Bug #9298 (Not a Bug): php error: utime failed
I reported this last year, Issue #8707 and gave up on a fix.
Updated last night to 1.28.19 build, hoping maybe the...
Tyler L
01:05 PM Feature #9297 (Resolved): Graph for hardware temperature readings
It would very nice to be able to see a history of available temperature readings even if that was just whatever CPU t... Steve Wheeler
12:22 PM Bug #9296 (Resolved): Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
If you are using FQDN-Aliases each FQDN can only be used once, if
you use the alias twice, the generated tables are...
Ph. T
10:59 AM Revision c07f1c26: Revert "Switch the 2.4.5 CE images to the new 2.4.5 development branch."
This reverts commit 2735541ea6fa553673d90e75f7e821497723fb23. Renato Botelho
10:36 AM pfSense Packages Feature #8232: different ssl options based on the sni name
Hey Pi Ba
I got the same Problem. When will the Fix be upstreamd to the "Main Channel" of pfs?
Greetings
Cedric
cedric kopplin

01/29/2019

07:23 PM Revision 5c4fef46: Add validation and encoding to various firewall advanced values. Issue #9294
(cherry picked from commit 62baf0777924b2c21c832db3c0040988e7451c61) Jim Pingle
07:23 PM Revision 9712ce4e: Encode shaper queue name before printing. Issue #9294
Validation is already present and prevents bad values from being
entered.
(cherry picked from commit 1072b9333c47df5...
Jim Pingle
07:23 PM Revision 7e9de4b1: Input validation and encoding of IGMP proxy addresses. Issue #9294
(cherry picked from commit 261916e5d3f833a58d5cef1afdadc7495ec2c74b) Jim Pingle
07:23 PM Revision ca0234c3: Validate NTP GPS type, encode output. Issue #9294
(cherry picked from commit 938988609c306fcd44e25a053745c4b8332eeeb5) Jim Pingle
07:23 PM Revision f39d3332: Encode traceroute error message. Issue #9294
(cherry picked from commit 57ccd08bf7ee05b9a00750a1fd9cf8f148e0c9ac) Jim Pingle
07:23 PM Revision 587c2d55: Validate submitted interfaces. Issue #9294
(cherry picked from commit 5cc7d21dc08be6c65a2bf7f8f4481dc13f4ae115) Jim Pingle
07:23 PM Revision 10b06be5: Fix input validation of webguiproto. Issue #9294
(cherry picked from commit 56888f24ca2715e678a1324633a08d3a611b4136) Jim Pingle
07:15 PM Revision 62baf077: Add validation and encoding to various firewall advanced values. Issue #9294
Jim Pingle
05:40 PM Revision 1072b933: Encode shaper queue name before printing. Issue #9294
Validation is already present and prevents bad values from being
entered.
Jim Pingle
05:04 PM Revision 261916e5: Input validation and encoding of IGMP proxy addresses. Issue #9294
Jim Pingle
04:48 PM Revision 93898860: Validate NTP GPS type, encode output. Issue #9294
Jim Pingle
04:15 PM Revision 57ccd08b: Encode traceroute error message. Issue #9294
Jim Pingle
04:11 PM Revision 5cc7d21d: Validate submitted interfaces. Issue #9294
Jim Pingle
04:05 PM Feature #9293: Custom message text for the login screen
Hi Joshua,
Yes, that was just an example of a similar requirement. This requirement can be found for "web servers":h...
Ryan H
12:02 PM Feature #9293: Custom message text for the login screen
Hi,
You are sure it is required for WebGUI ?
Because in the document you link it is only for "console login prom...
Joshua Sign
06:18 AM Feature #9293 (Resolved): Custom message text for the login screen
While trying to deploy in govt environments, they have security guidelines (STIGs) we're required to follow. Some, as... Ryan H
03:47 PM Revision 56888f24: Fix input validation of webguiproto. Issue #9294
Jim Pingle
01:24 PM Bug #9294: XSS issues on multiple pages
* XSS1 - Reproduced during redirect when changing protocols, added validation for the input and redirect
* XSS2 - Un...
Jim Pingle
09:03 AM Bug #9294 (Resolved): XSS issues on multiple pages
A list of 30 XSS issues was posted publicly without following responsible disclosure practices, they all need tested/... Jim Pingle
11:51 AM Bug #9295 (New): IPv6 PD does not work with PPPOE (Server & Client)
Hi,
as encountering DHCPv6 with Prefix delegation does not work together with PPPOE Server vice versa it is not p...
Dirk Steingäßer
05:02 AM Bug #9123: Adding/configuring vlan on ixl-devices causes aq_add_macvlan err -53, aq_error 14
Same problem here.
Hardware: Dell PowerEdge 330 with Intel(R) 10GbE 2P X710 Adapter
Done so far:
* installati...
Alexander Meckelein
04:09 AM Feature #7244: Publish pfsense as a Vagrant Basebox
I'm looking into implementing this one, because I need an easy way to launch pfsense instances for running automatic ... Mikael Lepistö

01/28/2019

11:55 PM Revision 2735541e: Switch the 2.4.5 CE images to the new 2.4.5 development branch.
Start to pave the way to 2.5. Luiz Souza
06:18 PM Revision e5b43cf8: type cast traffic graph inputs to fix #9072
Jared Dillard
03:10 PM Bug #9072: RRD graph mouseover information shows up as Mb when unit size is set to MB
Thanks for digging into the problem and for testing the fix! Jared Dillard
03:09 PM Bug #9072 (Resolved): RRD graph mouseover information shows up as Mb when unit size is set to MB
Jared Dillard
12:34 PM Bug #9072: RRD graph mouseover information shows up as Mb when unit size is set to MB
It Works! ;)
tested on :
2.4.4-RELEASE-p2 (amd64)
built on Wed Dec 12 07:40:18 EST 2018
FreeBSD 11.2-RELEASE-p6
Joshua Sign
12:25 PM Bug #9072: RRD graph mouseover information shows up as Mb when unit size is set to MB
Applied in changeset commit:e5b43cf8b86586486d951ab1da35b6c45ad6edf6. Jared Dillard
12:24 PM Bug #9072 (Feedback): RRD graph mouseover information shows up as Mb when unit size is set to MB
Jared Dillard
12:24 PM Bug #9072: RRD graph mouseover information shows up as Mb when unit size is set to MB
It looks like it was introduced in this commit (not that the code before it was perfect): https://github.com/pfsense/... Jared Dillard
07:49 AM Feature #9290 (Resolved): Need a way to suppress status output display in /status.php
Jim Pingle
12:14 AM Revision dcc887a3: RADVD: In "managed" or "stateless_dhcp" mode, don't use default values for DNS servers etc (these should come from DHCPv6)
Elbin Teh

01/27/2019

07:20 PM Feature #9290: Need a way to suppress status output display in /status.php
This all looks great. Tested everything I think. Works. Chris Linstruth
08:26 AM Bug #9292 (Resolved): Default route as indicated by "(Default)" does not match the actual default route on the OS.
Default route as indicated by "(Default)" does not match the actual default route on the OS.
Fix: https://github.c...
Pi Ba
12:52 AM Bug #8991: Codel limiter generating error in system log and console
Per below two forum posts by dummynet creator configuring Codel AQM and fq_codel scheduler, as shown in Youtube video... Paul K

01/26/2019

08:02 PM Bug #8554: /etc/rc.kill_states code not correctly parsing pfctl output
I'm running 2.4.4_2 and it still seems to be an issue. Are those actions logged somewhere so I can take a look please? Srdjan Jankovic
09:56 AM Bug #9276 (Resolved): DNS troubleshooting tool incorrectly reporting "ai." as an invalid hostname
Jim Pingle
12:02 AM Bug #9276: DNS troubleshooting tool incorrectly reporting "ai." as an invalid hostname
On 2.4.5-DEVELOPMENT (arm)
built on Fri Jan 25 05:46:46 EST 2019
Entered "ai.: in Diagnostics=>DNS Lookup an...
Vladimir Lind
09:46 AM Feature #9290: Need a way to suppress status output display in /status.php
That snapshot was before this commit. The newest snapshot should have it, if you update and try it again, it should w... Jim Pingle
12:16 AM Feature #9290: Need a way to suppress status output display in /status.php
On 2.4.5-DEVELOPMENT (arm)
built on Fri Jan 25 05:46:46 EST 2019 - SG3100
When I issue this command I get html ...
Vladimir Lind

01/25/2019

04:08 PM Bug #6876: Firewall alias issue after adding a wrong alias
Tested on:
2.4.4-RELEASE-p2 (arm)
built on Wed Dec 12 14:40:29 EST 2018
FreeBSD 11.2-RELEASE-p6
Followed instru...
Danilo Zrenjanin
04:04 PM Revision 140655f7: status.php optimizations. Implements #9290
* Rewrites the command output so it is first written to files, then read through line-by-line to PHP. Should be much ... Jim Pingle
04:04 PM Revision 6c17da07: status.php optimizations. Implements #9290
* Rewrites the command output so it is first written to files, then read through line-by-line to PHP. Should be much ... Jim Pingle
01:54 PM Feature #9288: SSHGuard add pfSense signature in standard
FYI
Kevin Zheng from sshguard bitbucker wrote :
> I’d be happy to include this signature in SSHGuard if the rule ...
Joshua Sign
11:56 AM pfSense Packages Bug #9050: Antartica does not make a rule
What should I track to see when it is released? Stuart Wyatt
10:28 AM Bug #9004: Default gateway IPv4 set to a group fails after restart on 2.4.4
jonathan's fix works.
Thank you very much!
Ioannis Kampolis
10:07 AM Feature #9290 (Feedback): Need a way to suppress status output display in /status.php
Implemented this and some other changes.
* Rewrites the command output so it is first written to files, then read ...
Jim Pingle
07:40 AM Bug #9239: WebGUI: Diagnostics > Packet Capture will try to display any size of pcap file.
tested on 2.4.5-DEVELOPMENT (arm)
built on Fri Jan 25 05:46:46 EST 2019
Invoked a lot of traffic while running...
Vladimir Lind

01/24/2019

08:46 PM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
I have also noticed this issue on my home pfSense. I was able to reproduce it reliably with a VM and it appears to h... Tom Embt
12:40 PM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
James Howel wrote:
> It appears that if pfSense has NEVER been connected to the internet, the way it behaves with th...
Joshua Sign
10:26 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
Maverick Phillips wrote:
> Hello,
>
> One of my two firewalls has developed this issue - I can confirm disabling ...
Corey Bock
04:57 PM Feature #4632: Support for Multipath TCP (MPTCP)
+1 here
this is a great added value for pfsense !
Michael F
04:25 PM Bug #9291: Schedule icon missing
Ok copy thx Yuri Weinstein
04:05 PM Bug #9291 (Not a Bug): Schedule icon missing
Unless you are viewing the web page between 3:15-3:30 AM, that icon will not show because the schedule is not active.... Jim Pingle
03:47 PM Bug #9291 (Not a Bug): Schedule icon missing
See attached.
Fine print says <icon >"Indicates that the schedule is currently active."
But there is no icon on...
Yuri Weinstein
02:17 PM Bug #9072: RRD graph mouseover information shows up as Mb when unit size is set to MB
i can confirm
the problem comes when you change from bytes to bits and then bits to bytes.
one temporary workaro...
Joshua Sign
12:45 PM Bug #9072: RRD graph mouseover information shows up as Mb when unit size is set to MB
Discussion about it here and validation
https://forum.netgate.com/topic/139922/solved-dashboard-traffic-not-consiste...
JohnPoz _
06:24 AM Bug #8758: filterdns stops working on a regular basis.
Just ran into this on 2.4.4-p2 with a not updating alias table:
[2.4.4-RELEASE][root@fw2]/root: ps aux | grep filt...
Rudolf Mayerhofer
12:56 AM pfSense Packages Bug #9050: Antartica does not make a rule
I answered this in my post above... Its already fixed in Devel. I am hoping to get devel released next month and that... BBcan177 .

01/23/2019

07:13 PM Revision 683a0581: Don't use DISTFILES_CACHE
Renato Botelho
07:13 PM Revision 81041332: Don't use DISTFILES_CACHE
Renato Botelho
05:57 PM Revision 97bca189: Remove unnecessary ports from dependency list
Renato Botelho
05:57 PM Revision fa6f675e: Remove unnecessary ports from dependency list
Renato Botelho
02:18 PM Feature #9290 (Resolved): Need a way to suppress status output display in /status.php
Many times on a large system a status output cannot be taken because displaying things like a large state table can e... Chris Linstruth
01:22 PM Feature #336: Option to create lagg under assign interfaces
+1 Very important feature! Alessandro Pessanha
09:30 AM pfSense Packages Feature #9250 (Resolved): Adjust download buttons and labels in OpenVPN Client Export
Tested:... Steve Wheeler
04:52 AM pfSense Packages Feature #9289 (New): Snort enable react
I like to use the "config enable_react" parameter to show a http site on blocked ips. The SNORT package dont't know t... Theo Wolf

01/22/2019

07:56 PM Revision a0541b29: use disablepingcheck as option name
Arthur Wiebe
06:26 PM Feature #9288 (New): SSHGuard add pfSense signature in standard
Hi,
I discuss with sshguard team about possibility to add the pfSense signature in standard, as it is ever done by...
Joshua Sign
04:21 PM Revision 7847e55f: add an option to the DHCP server to disable the ping check feature
Arthur Wiebe
03:37 PM Bug #9281 (Resolved): ZFS encrypted+mirrored swap may not be activated on 2.4.4-p2
Thanks for testing! Jim Pingle
03:11 PM Bug #9281: ZFS encrypted+mirrored swap may not be activated on 2.4.4-p2
Jim Pingle wrote:
> ZFS encrypted+mirrored swap may not be activated on 2.4.4-p2, the new swap device location code ...
Vincent Bentley
08:55 AM Bug #9281 (Feedback): ZFS encrypted+mirrored swap may not be activated on 2.4.4-p2
Applied in changeset commit:14d470377eab89d7c3f6f765a150ce737409af28. Jim Pingle
03:36 PM pfSense Docs Correction #8865 (Rejected): Feedback on Networking Concepts — IPv6 — IPv6 Subnetting
You have misread what the page is stating. The table is primarily to indicate the enormity of the IPv6 space.
Netw...
Jim Pingle
03:31 PM pfSense Docs Correction #8853 (Resolved): [feedback form] Explain what 0:0 means
Added info to that page. ICMP doesn't have state levels like other protocols, so it's really just a placeholder. Does... Jim Pingle
03:15 PM Revision 5e0fda8f: Fix desc of OpenVPN sync to show that it also syncs certs. Fixes #9283
(cherry picked from commit 9f3b87d898e1fa8a5bfa40758e5747515cc38ad4) Jim Pingle
03:14 PM Revision 9f3b87d8: Fix desc of OpenVPN sync to show that it also syncs certs. Fixes #9283
Jim Pingle
03:05 PM pfSense Docs Correction #9287 (Resolved): Feedback on The pfSense Book
Fix committed Jim Pingle
01:03 PM pfSense Docs Correction #9287 (Resolved): Feedback on The pfSense Book
*Page:* https://www.netgate.com/docs/pfsense/book/index.html
*Feedback:* Printed page 264, section 16.1. Period m...
Giuseppe Cimmino
02:49 PM Revision 3bb3fd45: Fix handling of special swap cases. Fixes #9281
(cherry picked from commit 14d470377eab89d7c3f6f765a150ce737409af28) Jim Pingle
02:48 PM Revision 14d47037: Fix handling of special swap cases. Fixes #9281
Jim Pingle
12:18 PM pfSense Packages Bug #9286: squidGuard - Unable to change IP for sgerror.php URL in configuration
Also see bug #8827 that is exhibiting a similar issue. Kris Douglas
12:13 PM pfSense Packages Bug #9286 (New): squidGuard - Unable to change IP for sgerror.php URL in configuration
There is an issue with squidGuard where a user is not able to specify the address that squidGuard provides the client... Kris Douglas
11:11 AM pfSense Packages Feature #8613: pfSense-pkg-acme: acme_certificates_edit.php - Add support for --challenge-alias acme.sh flag
I added a checkbox to use challenge-domain instead of challenge-alias in ACME pkg version 0.5.2 Jim Pingle
11:11 AM pfSense Packages Feature #8211 (Feedback): ACME cron job <- log activity
Fixed in ACME pkg version 0.5.2
Cron job output is now redirected to the main system log.
Jim Pingle
10:41 AM pfSense Packages Bug #9279 (Duplicate): security/acme: acme pf sense package processes unnecessary notifications due to using stdout
This will be solved by the fix for #8211 so I'm marking this as a duplicate for now. Jim Pingle
10:28 AM Feature #9285 (Resolved): Add an option to disable the ping-check in dhcpd
In experiencing some strange DHCP behavior at a customer site, where DHCP leases were getting abandoned and never re-... Arthur Wiebe
09:39 AM Bug #9284: no default gateway after upgrade to 2.4.4_p2 using gateway group
Jim Pingle wrote:
> Duplicate of #9004
Sorry I did search first. Not well apparently.
Art Manion
09:36 AM Bug #9284 (Duplicate): no default gateway after upgrade to 2.4.4_p2 using gateway group
Duplicate of #9004 Jim Pingle
09:32 AM Bug #9284: no default gateway after upgrade to 2.4.4_p2 using gateway group
Art Manion wrote:
> Workaround: In System > Routing > Gateways set Default gateway IPv4 to automatic (or one of t...
Art Manion
09:26 AM Bug #9284 (Duplicate): no default gateway after upgrade to 2.4.4_p2 using gateway group
Two pfSense boxes A and B using HA sync, A is master, B is backup.
Two gateways, Verizon (tier 1) and ATT (tier 2)...
Art Manion
09:35 AM Bug #9283: Not obvious that HA sync will still sync certs if cert sync disabled but OpenVPN sync enabled
Jim Pingle wrote:
> The correct procedure for what you describe is to import all certs to the primary, and then sele...
Art Manion
09:33 AM Bug #9283: Not obvious that HA sync will still sync certs if cert sync disabled but OpenVPN sync enabled
Jim Pingle wrote:
> It does exclude certificates when all areas that need certificate sync are disabled. OpenVPN req...
Art Manion
09:20 AM Bug #9283 (Feedback): Not obvious that HA sync will still sync certs if cert sync disabled but OpenVPN sync enabled
Applied in changeset commit:9f3b87d898e1fa8a5bfa40758e5747515cc38ad4. Jim Pingle
09:18 AM Bug #9283: Not obvious that HA sync will still sync certs if cert sync disabled but OpenVPN sync enabled
It does exclude certificates when all areas that need certificate sync are disabled. OpenVPN requires certs to sync, ... Jim Pingle
01:40 AM Bug #9283 (Resolved): Not obvious that HA sync will still sync certs if cert sync disabled but OpenVPN sync enabled
system A has external/imported certificate A
system B has external/imported certificate B
Both just upgraded to 2...
Art Manion
09:24 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Daryl Morse wrote:
> As I mentioned, I emailed the author of rate. He replied this morning and confirmed that he is ...
Jim Pingle
01:05 AM Bug #9282 (Resolved): Add static mapping count to DHCP Server interface tabs
services - > DHCP Server > Interface
need a counter that count add static mapping in "DHCP Static Mappings for ...
reza mansoorpour

01/21/2019

07:22 PM Revision 0b07930d: Packet capture page fixes. Fixes #9239
* Add "None" output level
* Detect large files and refuse to print them in the GUI textarea
* Ensure output buffering...
Jim Pingle
07:22 PM Revision 36192f4a: Packet capture page fixes. Fixes #9239
* Add "None" output level
* Detect large files and refuse to print them in the GUI textarea
* Ensure output buffering...
Jim Pingle
05:52 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Jim Pingle wrote:
> The underlying program, rate, still doesn't work with IPv6 as far as I'm aware.
>
> I'd love ...
Daryl Morse
09:42 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
With some small modifications, it does work. See my comments on the PR (and future discussion should happen on the PR... Jim Pingle
04:12 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
you are certainly in an issue with bads crlf in the awk script.
please update by this one, i gzip it to avoid any co...
Joshua Sign
04:49 PM Revision 5c8aaa20: Init array for 6o4 tunneling Fixes #9264
(cherry picked from commit 5345b25405101eba3112c1d5daef99bd3b308533) Jim Pingle
04:48 PM Revision 5345b254: Init array for 6o4 tunneling Fixes #9264
Jim Pingle
04:39 PM Revision 2cc24f95: Allow a trailing dot in a hostname on diag_dns.php. Fixes #9276
(cherry picked from commit e56c473d7c4c2e7de71c43420c844e452dbcfa82) Jim Pingle
04:39 PM Revision f6775a83: Remove links to DNSStuf tools. Fixes #9275
(cherry picked from commit 08c49b4d74b87bf34dd46a37837147b857eb8859) Jim Pingle
04:38 PM Revision e56c473d: Allow a trailing dot in a hostname on diag_dns.php. Fixes #9276
Jim Pingle
04:32 PM Revision 08c49b4d: Remove links to DNSStuf tools. Fixes #9275
Jim Pingle
03:38 PM Bug #9281 (Resolved): ZFS encrypted+mirrored swap may not be activated on 2.4.4-p2
ZFS encrypted+mirrored swap may not be activated on 2.4.4-p2, the new swap device location code isn't validating the ... Jim Pingle
02:51 PM Bug #9160 (Resolved): OCSP Must-Staple, when checked on the System > Advanced AND on the System > General Setup some IPv6 DNS servers are listed, then the nginx web configurator file will a contain syntax error
This has been working for me in a test VM for over a month now, but it would be nice to have additional confirmation ... Jim Pingle
01:30 PM Bug #9239 (Feedback): WebGUI: Diagnostics > Packet Capture will try to display any size of pcap file.
Applied in changeset commit:36192f4a459ec5d5baf06819102ba783c1725ba1. Jim Pingle
11:49 AM Feature #9268: Add Linode Dynamic DNS support
FYI for anyone testing, and as noted on the PR:
Authentication uses "Personal Access Tokens":https://cloud.linode....
Tom Embt
11:19 AM pfSense Packages Feature #9265 (Feedback): Add options to configure TIMEOUTclose and debug on stunnel package
PR merged Jim Pingle
11:18 AM pfSense Packages Feature #9250 (Feedback): Adjust download buttons and labels in OpenVPN Client Export
PR merged Jim Pingle
11:17 AM pfSense Packages Bug #9244 (Feedback): FRR Status BGP Summary only shows "IPv4 Unicast Summary"
PR Merged Jim Pingle
10:55 AM Bug #9264 (Feedback): Disabling "IPv6 over IPv4 Tunneling" breaks config
Applied in changeset commit:5345b25405101eba3112c1d5daef99bd3b308533. Jim Pingle
10:49 AM Bug #9264: Disabling "IPv6 over IPv4 Tunneling" breaks config
That's a new error, not the same one. I can't reproduce that here, but I can see how it might happen. Pushed a new fix. Jim Pingle
10:45 AM Bug #9276 (Feedback): DNS troubleshooting tool incorrectly reporting "ai." as an invalid hostname
Applied in changeset commit:e56c473d7c4c2e7de71c43420c844e452dbcfa82. Jim Pingle
10:38 AM Bug #9276: DNS troubleshooting tool incorrectly reporting "ai." as an invalid hostname
Looks like it's easily fixed by having the validation check ignore a trailing dot on the hostname, but including it i... Jim Pingle
10:45 AM Bug #9275 (Feedback): ip tools link not working
Applied in changeset commit:08c49b4d74b87bf34dd46a37837147b857eb8859. Jim Pingle
10:31 AM Bug #9275: ip tools link not working
Actually the URL didn't just change, they also changed the format of the query and it doesn't appear to have the exac... Jim Pingle
10:24 AM Bug #9270: "Remove all states to and from the filtered address" does not remove all states
There does seem to be an issue here, looks like it's in the pfSense module function @pfSense_kill_states()@. Sometime... Jim Pingle
09:28 AM Feature #9280: Add AAAA record type support for DynDNS with Digital Ocean
* meant to create this as a "feature". Matthew Fine
09:17 AM Feature #9280 (Resolved): Add AAAA record type support for DynDNS with Digital Ocean
Add AAAA record type support for DynDNS with Digital Ocean
Updated dyndns.class, services.inc, and services_dyndns...
Matthew Fine
05:37 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
Hi Joshua,
Thanks for looking at this.
We don't have a WAN in a down state, it is connected but it has no NAT a...
James Howel

01/20/2019

10:34 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Joshua Sign wrote:
> ok,
>
> the first file "File Capture iftop.PNG" show that there is a problem with the awk s...
Daryl Morse
06:48 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
ok,
the first file "File Capture iftop.PNG" show that there is a problem with the awk script.
This script is les...
Joshua Sign
06:02 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Another screen capture from the status graph. Daryl Morse
05:57 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Joshua Sign wrote:
> Daryl Morse wrote:
> > I got permission denied when I tried to run the script from the console...
Daryl Morse
04:53 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready

Daryl Morse wrote:
> I got permission denied when I tried to run the script from the console shell.
please chec...
Joshua Sign
04:01 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
just a thought, if you don't have ipv6, you could set up a tunnel with hurricane electric. It's free, it works very w... Daryl Morse
03:58 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Joshua Sign wrote:
> ok,
>
> to debbug it you can check if there is any ip6 in this output :
> [...]
>
> if...
Daryl Morse
12:09 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
ok,
to debbug it you can check if there is any ip6 in this output : ...
Joshua Sign
10:47 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Joshua Sign wrote:
> can you chexk over console if iftop shows you some IPV6 adresses just by : `iftop -n` ?
>
> ...
Daryl Morse
05:36 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
can you chexk over console if iftop shows you some IPV6 adresses just by : `iftop -n` ?
as far as i didn't have an...
Joshua Sign
06:14 PM Feature #790: Advanced options for dnsclient (resolv.conf)
PR created : https://github.com/pfsense/pfsense/pull/4040 Joshua Sign
03:29 PM Feature #790: Advanced options for dnsclient (resolv.conf)
Mike Stupalov wrote:
> Possibility to add additional options in resolv.conf:
> * timeout:n (default 5)
> * attempt...
Matthew Hines
05:43 PM pfSense Packages Bug #9279 (Duplicate): security/acme: acme pf sense package processes unnecessary notifications due to using stdout
When email notifications enabled and pfsense acme (0.5.1) package installed and cron enabled, acme client will produc... Derek Schrock
04:42 PM Bug #9223: SSHGUARD doesn't work as expected
I investigate about this problem,
It seems that the sshguard purpose is to detect an attack and just launch a bac...
Joshua Sign
11:36 AM pfSense Packages Bug #9050: Antartica does not make a rule
Has this been released in the main version? I updated to 2.4.4-p2 and pfBlockerNG 2.1.4_16 and it still doesn't crea... Stuart Wyatt

01/19/2019

12:33 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Joshua Sign wrote:
> PR : https://github.com/pfsense/pfsense/pull/4039
I installed this patch on the most recent ...
Daryl Morse
02:12 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
PR : https://github.com/pfsense/pfsense/pull/4039 Joshua Sign
12:27 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Here is the patch
/usr/local/bin/iftop_parser.sh must have +x
Joshua Sign
09:58 AM Bug #9278 (Not a Bug): LAN IPv6 track interface Router Advertisement not assigning IPv6 addresses on Linux and macOS clients
Sounds more like a configuration or local client issue. Post on the forum to discuss the issue and diagnose the probl... Jim Pingle
09:51 AM Bug #9278 (Not a Bug): LAN IPv6 track interface Router Advertisement not assigning IPv6 addresses on Linux and macOS clients
Comcast -> (WAN) NetGate (LAN) --> Linux, macOS clients
WAN is configured for IPv6 prefix delegation with prefix l...
Vividh Siddha
12:23 AM Feature #4354: Allow dpinger to ping more than one destination for a gateway.
I agree with David. DNS more so than Ping monitoring makes sense to me. I've been bit a few times with DNS failures b... Mark Noga

01/18/2019

06:17 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
here are the files you need to easely test, it is faster thant the PR
just put the two scripts into the root directo...
Joshua Sign
06:10 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
yes it will be possible soon.
I just wrote this script to avoid process concurrent creation when many users are on...
Joshua Sign
05:36 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Joshua Sign wrote:
> Unfortunally i don't use IPV6, so i can't test this part.
I have IPv6 so I would be happy ...
Daryl Morse
10:19 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Hi Jim,
FYI, I just finish some tests : it seems to works as expected.
All we need to test is :
This awk scr...
Joshua Sign
02:30 PM Feature #7416: DHCPv4 client does not support ``supersede`` statement for option 54
The patch fixed it in OPNSense in 2017. It has been running flawlessly ever since. That's the only feedback I can pro... Fabian Kurtz
11:10 AM Bug #9264 (Assigned): Disabling "IPv6 over IPv4 Tunneling" breaks config
Jim Pingle
10:57 AM Bug #9264: Disabling "IPv6 over IPv4 Tunneling" breaks config
Reproduced the issue on SG-5100:
2.4.4-RELEASE-p2 (amd64)
built on Wed Dec 12 14:40:29 EST 2018
FreeBSD 11.2-REL...
Danilo Zrenjanin
10:45 AM Bug #9171 (Resolved): Fix DigitalOcean Dynamic DNS client
Tested on SG-5100 -
2.4.4-RELEASE-p2 (amd64)
built on Wed Dec 12 14:40:29 EST 2018
FreeBSD 11.2-RELEASE-p6
A...
Danilo Zrenjanin
10:42 AM Bug #9024: Ping packet loss under load when using limiters
I just wanted to chime in that I have the very same exact behaviour on my setup.
Is there any progress on the issue?
Patrik Hildingsson
09:29 AM Bug #9277: MBT-4220/2220: pfSense hangs when running sysctl -a
I'm pretty sure I experienced the same issue on 2.4.4-p1 and or 2.4.4-p2.
It did happen only for the initial few r...
Nano Caiordo
07:07 AM Bug #9277 (Not a Bug): MBT-4220/2220: pfSense hangs when running sysctl -a
That isn't a general issue with pfSense or the MBT-4220. Please contact our support team at https://go.netgate.com an... Jim Pingle
03:48 AM Bug #9277 (Resolved): MBT-4220/2220: pfSense hangs when running sysctl -a
Running 2.4.4-p2 on MBT-4220
Accessing the WebGUI appears to be causing OS-level hang (no response on WebGUI/SSH/...
Adam Gibson

01/17/2019

06:29 PM Bug #9053: Dynamic DNS will not allow Route 53 wildcard record
https://github.com/pfsense/pfsense/pull/4038
It seems to me the wildcard checkbox is intended for providers that o...
Tom Embt
12:14 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
ok i will work on it and create a PR to change rate by iftop as soon as it works
(normaly it should be ok on sunday ...
Joshua Sign
12:02 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
That does help a bit. It would be even better if iftop had an output mode like libxo where it would be trivial to par... Jim Pingle
11:22 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready

Jim Pingle wrote:
> I'd love to see rate swapped out for iftop (which does support IPv6) but the output of iftop i...
Joshua Sign
10:30 AM Bug #9276 (Resolved): DNS troubleshooting tool incorrectly reporting "ai." as an invalid hostname
To reproduce:
Navigate to Diagnostics=>DNS Lookup (found at /diag_dns.php). Enter any TLD that should work as a si...
Steve Malloy
08:31 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
Hello,
One of my two firewalls has developed this issue - I can confirm disabling the WAN adapter resolved this sl...
Maverick Phillips
07:49 AM Feature #7416: DHCPv4 client does not support ``supersede`` statement for option 54
The reply on the FreeBSD PR is ambiguous at best. It would also help if someone that was actually a part of the FreeB... Jim Pingle
07:42 AM Feature #7416: DHCPv4 client does not support ``supersede`` statement for option 54
I beg to differ and hope I'm not mistaken, but AFAIK Franco pulled that already into OPNsense and the last statement ... Jens Groh
07:21 AM Feature #7416: DHCPv4 client does not support ``supersede`` statement for option 54
Might be, but it's still an open issue and hasn't been accepted into FreeBSD yet. There isn't even one person on that... Jim Pingle
06:22 AM Feature #7416: DHCPv4 client does not support ``supersede`` statement for option 54
@Jimp
I maybe wrong but isn't that the corresponding fix/workaround from upstream to this particular problem?
Cou...
Jens Groh

01/16/2019

05:39 PM Bug #9275 (Resolved): ip tools link not working
just discovered in 2.4.5 snapshots.. ip tools are not working http://private.dnsstuff.com/tools/whois.ch?ip= and... Nico Maco
10:24 AM Revision 28a5469e: add trim() to $_POST['auth_user'] & $_POST['auth_user2']
jeroen van breedam
04:26 AM Feature #9274: CP - trim() username post_value
https://github.com/pfsense/pfsense/pull/4037 jeroen van breedam
04:24 AM Feature #9274 (Resolved): CP - trim() username post_value
to trim leading & trailing whitespace of the username that is entered when signin in to captive-portal.
see [[https:...
jeroen van breedam
02:26 AM pfSense Packages Bug #9273 (Closed): missing Include=/usr/local/etc/zabbix4/zabbix_agentd.conf.d in /usr/local/etc/zabbix40/zabbix_agentd.conf
because of the missing include line in the zabbix_agentd.conf, UserParameter definitions are not loaded.
we are us...
Rabie Zamane Abou-Taleb

01/15/2019

11:55 PM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Jim Pingle wrote:
> The underlying program, rate, still doesn't work with IPv6 as far as I'm aware.
>
> I'd love ...
Daryl Morse
09:49 PM Bug #7439: IKE_SA (IKEv2) does not rekey on break before make startegy, just issues IKE_DELETE and connection is closed
I would like to reopen this thread as I'm experiencing same problem and I'm on 2.4.4-RELEASE (amd64)
My configuratio...
Daniel Ann
09:40 PM Revision bd0a29ea: Linode Dynamic DNS syntax fixes
Tom Embt
09:33 PM Revision b923a825: Add Dynamic DNS support for Linode #9268
Tom Embt
04:35 PM pfSense Packages Feature #9272 (Resolved): Allow multiple IP in ListenIP for Zabbix Agent
The web interface for the zabbix-agent service does not allow to add multiple IPs comma separated. The validation rul... Jakob Ackermann
02:50 PM Bug #9271 (Resolved): Azure DDNS whitespace cleanup
Fix some indenting surrounding the Azure DDNS implementation to be consistent with the rest of the file.
https://g...
Tom Embt
12:38 PM pfSense Packages Feature #8613: pfSense-pkg-acme: acme_certificates_edit.php - Add support for --challenge-alias acme.sh flag
Markus Barckmann wrote:
>
> It would be very nice to have a UI option to choose between this two (sub)methods.
...
Jesse Norell
11:17 AM pfSense Packages Feature #8574: Enable AgentX-support in lldpd using GUI
The above patch works for me. The Net-SNMP package already adds "master agentx" to /var/etc/netsnmpd.conf by default... Jon Gerdes
09:32 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
Hi,
I just test it :
- Loading dashboard normaly takes about 1 second or less.
- Without WAN connectivity, it ...
Joshua Sign
07:26 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
Hi Luke,
Thanks for the suggestion but I've tried that, same issue.
It looks like whatever is timing out due to...
James Howel
06:57 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
If you remove all widgets from the dashboard does that help at all? It's probably a widget that's causing this delay. → luckman212
06:52 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
To add to this bug we've been using pfSense 2.3.5 for an internal project and its been working brilliantly.
We're ...
James Howel
 

Also available in: Atom