Project

General

Profile

Activity

From 04/03/2019 to 05/02/2019

05/02/2019

09:50 PM pfSense Packages Bug #9211: GeoIP broken in pfSense-pkg-ntopng-0.8.13_3
I got this working on my SG-3100 by copying files from:
https://centminmod.com/centminmodparts/geoip-legacy/
to...
Mark Vejvoda
05:52 PM pfSense Packages Feature #9498: ACME Package: Sorting on name, expiration, etc
The ACME package has been working flawless for me now, for well over a year, I've migrated all of my ACME certs to it... Dan Thunder
05:44 PM pfSense Packages Feature #9498 (Resolved): ACME Package: Sorting on name, expiration, etc

The ACME package has been working flawless for me now, for well over a year, I've migrated all of my ACME certs t...
Dan Thunder

05/01/2019

02:58 PM pfSense Packages Bug #9492 (Assigned): Cannot reload remote haproxy via ACME package
Yeah, you're right. I didn't have a setup to test that handy, but it would have to come earlier. I'll come up with a ... Jim Pingle
02:51 PM pfSense Packages Bug #9492: Cannot reload remote haproxy via ACME package
Jim Pingle wrote:
> Fixed in ACME pkg v0.5.6
I just tried this and it still throws an error, to the best of my un...
Florian Apolloner
10:52 AM pfSense Packages Bug #9492 (Feedback): Cannot reload remote haproxy via ACME package
Fixed in ACME pkg v0.5.6 Jim Pingle
10:54 AM pfSense Packages Bug #9368 (Resolved): ACME certificates cannot have more than ~35 SAN entries due to input variable limits
Jim Pingle
10:54 AM pfSense Packages Feature #8613 (Resolved): pfSense-pkg-acme: acme_certificates_edit.php - Add support for --challenge-alias acme.sh flag
Jim Pingle
10:54 AM pfSense Packages Feature #8490 (Resolved): pfSense-pkg-acme: acme_certificates_edit.php - Add ability to specify (vs generate) private key
Jim Pingle
10:53 AM pfSense Packages Feature #8211 (Resolved): ACME cron job <- log activity
Jim Pingle
10:52 AM pfSense Packages Bug #9340 (Feedback): Buypass CA does not support wildcard
Fixed in ACME pkg v0.5.6 Jim Pingle
10:14 AM pfSense Packages Bug #9495: AWS VPC VPN wizard produces incorrect config (SHA256 should be SHA1)
So far I have been unable to replicate this.
Tested with a 7100 and 1100 against us-west-2 and us-east-2 using AWS W...
Steve Wheeler
10:06 AM pfSense Packages Bug #9497: AWS VPN Wizard: WebGUI times out.
When you apply the settings at step 3 the GUI times out. If you check AWS suring that time the Virtual Private Gatewa... Steve Wheeler

04/30/2019

01:42 PM pfSense Packages Bug #9497 (New): AWS VPN Wizard: WebGUI times out.
When creating a new VPN using the AWS VPN Wizard the webgui times out at step 3 going to step 4 and also at step 4 go... Steve Wheeler
11:03 AM Feature #9496 (Duplicate): Include the athp(4) driver.
It would be great to get the athp driver into a 2.5 snapshot for testing. Even if it's not loaded by default.
https:...
Steve Wheeler
09:53 AM pfSense Packages Bug #9495: AWS VPC VPN wizard produces incorrect config (SHA256 should be SHA1)
Sorry, forgot to add: in looking over the download configuration from AWS, I noticed that it also recommends the Phas... Frank Hecker
09:24 AM pfSense Packages Bug #9495 (New): AWS VPC VPN wizard produces incorrect config (SHA256 should be SHA1)
I was trying to create a site-to-site VPN to my AWS default VPC in the us-west-2 region using the AWS VPC VPN Wizard ... Frank Hecker
07:05 AM Bug #9460 (Resolved): OpenVPN local auth failing due to fcgicli output
Jim Pingle

04/29/2019

10:19 PM Bug #9460: OpenVPN local auth failing due to fcgicli output
OpenVPN auth both local and radius are now functioning for me Jake K
02:00 PM pfSense Docs Correction #9494 (Resolved): Feedback on VPN — IPsec — NAT with IPsec Phase 2 Networks
*Page:* https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/phase-2-nat.html
*Feedback:*
https://docs.netgate.co...
Wayne Johnson
11:41 AM Feature #9493 (Closed): XMLRPC Sync to ECMP clusters
That is not what the XMLRPC sync features was designed to do, or to be. It is only intended to be used for two nodes ... Jim Pingle
11:33 AM Feature #9493 (Closed): XMLRPC Sync to ECMP clusters
We scale PFSense by running ECMP though BGP and taking advantage of pfsync to keep up to six firewalls active simulta... Eric Houston
08:20 AM Bug #9491: Can't create vlans or change interfaces when logged in as AD-User via LLDP
Jim Pingle wrote:
> Almost certainly a problem with your configuration, such as accidentally selecting "Deny Config ...
David Teslow
07:54 AM Bug #9491 (Not a Bug): Can't create vlans or change interfaces when logged in as AD-User via LLDP
Almost certainly a problem with your configuration, such as accidentally selecting "Deny Config Write" on the group f... Jim Pingle
06:23 AM Bug #9491: Can't create vlans or change interfaces when logged in as AD-User via LLDP
Sorry i ment LDAP in the subjects field not LLDP. David Teslow
04:59 AM Bug #9491 (Not a Bug): Can't create vlans or change interfaces when logged in as AD-User via LLDP
Hello pfSense Team,
as described in the subject that pretty much the problem that i noticed.
Create a vlan and pr...
David Teslow
07:53 AM Feature #8602 (Resolved): DNS over TLS host verification
Jim Pingle
07:53 AM Bug #9446 (Resolved): Filter reload error with NAT reflection enabled
Jim Pingle
07:52 AM Bug #9470 (Resolved): unbound remotecontrol.conf not rewritten when the file is empty
Jim Pingle
07:52 AM Feature #9412 (Resolved): Add sorting and search/filtering to CA/Certificates
Jim Pingle
06:33 AM Bug #9488: No console when booting CE Memstick UEFI.
The ISO image behaves exactly the same. There is no output after root is mounted other than the interface state chang... Steve Wheeler
06:04 AM Bug #9488: No console when booting CE Memstick UEFI.
ISO image is hybrid and can be used to boot using a flash drive. Can you try it to see if the results are the same? Renato Botelho
05:20 AM pfSense Packages Bug #9492: Cannot reload remote haproxy via ACME package
If I replace:... Florian Apolloner
05:14 AM pfSense Packages Bug #9492 (Resolved): Cannot reload remote haproxy via ACME package
The acme instance cannot restart a remote haproxy service. I looked at the code and found this snippet: https://githu... Florian Apolloner

04/28/2019

11:49 PM Feature #8602: DNS over TLS host verification
Similar results here. Mismatched FQDN for the server results in a certificate verify error for unbound:
Apr 29 04:48...
Chris Linstruth
11:37 PM Bug #9446: Filter reload error with NAT reflection enabled
Getting parens on that interface. No rule loading errors:
eg. no nat on vtnet0 proto tcp from (vtnet0) to 172.25.236...
Chris Linstruth
11:30 PM Bug #9470: unbound remotecontrol.conf not rewritten when the file is empty
Looks good here. cp /dev/null /var/etc/unbound.conf then a save of the unbound configuration populated the file. Chris Linstruth
11:25 PM Feature #9412: Add sorting and search/filtering to CA/Certificates
This looks great to me. Searching and column sorting work. Chris Linstruth
10:13 PM Bug #9490 (Not a Bug): PFSense fails to mount drives under KVM/QEMU
Nothing for pfSense to do there. That's all between FreeBSD and your hypervisor. Maybe choosing a different partition... Jim Pingle
09:29 PM Bug #9490 (Not a Bug): PFSense fails to mount drives under KVM/QEMU
I'm not sure if this is relevant to the pfsense code itself, but caught me this afternoon so will pass along for refe... B C
09:53 PM pfSense Packages Bug #9211: GeoIP broken in pfSense-pkg-ntopng-0.8.13_3
Looks like it :(. Anybody knows how to do a quick workaround and install 3.8 manually? or can I download the old vers... Tj Ng
07:30 PM Bug #9489 (Not a Bug): pfsense with ha closing sessions when apply any rule, xmlrpc erros are shown
You have a configuration error, probably a down gateway triggering state killing. Keep the discussion on the forum. Jim Pingle
07:05 PM Bug #9489 (Not a Bug): pfsense with ha closing sessions when apply any rule, xmlrpc erros are shown
Cloned from:
https://forum.netgate.com/topic/131916/pfsense-with-ha-closing-sessions-when-apply-any-rule
On XG-71...
Daniele Palumbo
05:32 PM Bug #8235: The browser must support cookies to login
I'm getting affected by this as well, under similar circumstances.
Jim Pingle wrote:
> Does the same thing happen...
Greg Toombs
07:50 AM Bug #9488 (Resolved): No console when booting CE Memstick UEFI.
Testing 2.5 snapshots. When booting the VGA Memstick image as UEFI there is no usable console presented.
This appl...
Steve Wheeler

04/27/2019

12:33 PM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
I currently have a DNS server configured in "System->General Setup" and have the DNS Resolver enabled so I can do loo... Rafael Possamai

04/26/2019

06:18 PM Revision b8d74978: Fix #9451: Enable build of zabbix 4.2
Renato Botelho
06:17 PM Revision 30335336: Fix #9451: Enable build of zabbix 4.2
Renato Botelho
05:43 PM Revision 1b5941eb: Remove zabbix 3.2 and 3.4 options
Renato Botelho
05:42 PM Revision f5adb939: Add Zabbix 4.2 config options
(cherry picked from commit 169754517a586b259677025e551b8e972de310e5) Danilo Baio
05:42 PM Revision 92e209a4: Merge pull request #4065 from dbaio/zabbix42
Renato Botelho
01:59 PM pfSense Packages Bug #9487: FRR package sending dual Hello packets on carp (OSPF)
v 2.4.4 FRR 0.2_8 Andres Noriega
01:59 PM pfSense Packages Bug #9487 (Rejected): FRR package sending dual Hello packets on carp (OSPF)
There is not enough information here to identify anything with certainty. Nothing about the versions, your config, et... Jim Pingle
01:56 PM pfSense Packages Bug #9487 (Rejected): FRR package sending dual Hello packets on carp (OSPF)
I have detected FRR package on an OSPF implementation sending hello packets related to the protocol, with 2 ips
car...
Andres Noriega
01:31 PM Revision 16975451: Add Zabbix 4.2 config options
Danilo Baio
01:25 PM pfSense Packages Bug #9451 (Feedback): Add Zabbix 4.2 (agent and proxy) packages
Applied in changeset pfsense:commit:30335336358db3bcdc0ede634a4f81b7f3273c7b. Renato Botelho
12:47 PM pfSense Packages Bug #9451: Add Zabbix 4.2 (agent and proxy) packages
PR adding make.conf items was merged and original commit adding 4.2 to ports tree cherry-picked Renato Botelho
01:08 AM pfSense Packages Bug #9451: Add Zabbix 4.2 (agent and proxy) packages
4.2 seems to be available in FreeBSD Ports now. https://www.freebsd.org/cgi/ports.cgi?query=zabbix&stype=all Sebastian Werner
01:16 PM pfSense Packages Bug #9486 (New): ifindex values used for softflowd are incorrect
With this patch, we now pass ifIndex values to softflowd for inclusion in the flow packets:
https://github.com/pfs...
Jesse White
08:52 AM Bug #9485 (New): password match error on system_usermanager causes Group membership to be reset.
I went to set the pre-shared key on my own account. In the process, a browser form filler entered my password on the... Wayne Johnson
07:24 AM Bug #9431 (Resolved): Upgrading to 2.5.0 with devel/aws-sdk-php installed fails
Jim Pingle
05:59 AM Bug #9431: Upgrading to 2.5.0 with devel/aws-sdk-php installed fails
It is :)
Thanks!
Greg M

04/25/2019

01:21 PM Bug #9484 (Closed): With proper timing on boot dhclient won't be started for WAN without manual intervention
My setup
* Pfsense WAN (igb0) connected directly to ISP modem (configured as bridge)
* Pfesnse LAN (igb1 - with a f...
Tomasz K.
07:29 AM Bug #9479 (Duplicate): Alias table not updated when adding new entry
Jim Pingle
02:18 AM Bug #9479: Alias table not updated when adding new entry
Removed FQDN's - it didn't happen. Looks 9296 related. Vladimir Lind

04/24/2019

11:59 AM Feature #9104: Add a FAT32 partition to memstick installer images
Just tried this rescuing a 2.4.4-p2 config.xml
System installed correctly, and config was restored, but packages t...
James Tandy
12:29 AM Revision 6a4635fc: Unbound python mod - services.inc
* Include any additional functions as defined by python script include file
* Add missing escapeshellarg()'s
* Make g...
BBcan177 .

04/23/2019

04:43 PM pfSense Packages Feature #9238: Add support for Zerotier
I don't think my code would be of much use, I was just trying to get the package to work with the latest pfS version.... Corey Boyle
04:12 PM pfSense Packages Feature #9238: Add support for Zerotier
Seconding this request!
It seems Corey has and ChanceM have already done most of the heavy lifting:
Ref: https...
Christian McDonald
10:29 AM Bug #9431 (Feedback): Upgrading to 2.5.0 with devel/aws-sdk-php installed fails
It should be fixed in pfSense-upgrade 0.67 Renato Botelho
07:48 AM Bug #9431: Upgrading to 2.5.0 with devel/aws-sdk-php installed fails
Greg M wrote:
> Great!
>
> Are you able to replicate?
>
> If not what else can we provide to help troubleshoot...
Renato Botelho
07:29 AM Bug #9431: Upgrading to 2.5.0 with devel/aws-sdk-php installed fails
Great!
Are you able to replicate?
If not what else can we provide to help troubleshoot it?
Greg M

04/22/2019

06:49 PM Revision 40a8898b: Stop building zabbix 3.2 and 3.4 since they will be deprecated from FreeBSD ports tree in few days
Renato Botelho
02:41 PM Bug #9431 (In Progress): Upgrading to 2.5.0 with devel/aws-sdk-php installed fails
I'll work on it Renato Botelho
02:00 PM Bug #9483 (Resolved): UFS filesystem is not being mounted noatime.
On a clean CE install using the default options the / filesystem is not mounted noatime.
This is leading to increa...
Steve Wheeler
01:54 PM pfSense Packages Todo #9482 (Resolved): Remove zabbix 3.2 and 3.4 from pfSense
Zabbix ports versions 3.2.x and 3.4.x will be removed from FreeBSD ports tree in Apr 2019. Remove them from pfSense Renato Botelho

04/21/2019

09:27 AM pfSense Packages Bug #9451: Add Zabbix 4.2 (agent and proxy) packages
We don't use precompiled binaries from other sites. It has to be in FreeBSD ports. Jim Pingle
08:48 AM pfSense Packages Todo #9200: Add DNS support for Google domain to Acme manager
I would also like to see Google Domains added into the list of supported validation methods. Don McLean

04/20/2019

11:51 PM pfSense Packages Bug #9451: Add Zabbix 4.2 (agent and proxy) packages
there is a freebsd package on official site https://www.zabbix.com/download_agents rub man

04/18/2019

08:17 PM Revision 80e50918: Update status.php to use ping-auth for pubkey
Jim Pingle
08:01 AM Bug #9431: Upgrading to 2.5.0 with devel/aws-sdk-php installed fails
Hi!
I have:
a) Removed all packages via GUI and upgraded, same error
b) Used command "pkg delete pfSense-pkg-...
Greg M
07:10 AM Bug #9248: Dynamic dns updates on azure ipv6 service is not working properly
PR: https://github.com/pfsense/pfsense/pull/4064 Jim Pingle
03:09 AM Revision 1ca156ea: Fix AzureV6 DynDNS client
`AAAARecords` in the Azure DNS API is case sensitive
Documentation: https://docs.microsoft.com/en-us/rest/api/dns/re...
Tyler Szabo

04/17/2019

03:24 PM pfSense Packages Bug #9481 (Closed): traffic totals documentation link goes to 404 page
The question mark on the top right corner goes
Page not found: https://www.netgate.com/docs/pfsense/index.php/Traf...
Brendon Baumgartner
01:54 PM Bug #9459: patch pf: silence a runtime warning pfr_update_stats: assertion failed.
Update: I was able to stop the warnings by disabling nat reflection.
Possible bug?
!https://forum.netgate.com/a...
rub man
08:26 AM pfSense Packages Bug #9211: GeoIP broken in pfSense-pkg-ntopng-0.8.13_3
It seems clear no one at Netgate is reading this ticket. :-( B D
07:29 AM Bug #9479: Alias table not updated when adding new entry
Try to replicate without the FQDNs. If the issue doesn't happen, then this can be closed in favor of the earlier ticket. Jim Pingle
07:22 AM Bug #9479: Alias table not updated when adding new entry
Yes, it does contain a couple of FQDNs in both cases. Vladimir Lind
07:18 AM Bug #9479: Alias table not updated when adding new entry
Does the alias contain any FQDNs? Or only IP addresses and subnets? If it contains FQDNs, this may be a duplicate of ... Jim Pingle
01:55 AM Bug #9479 (Duplicate): Alias table not updated when adding new entry
On 2.4.4-p2 CE and arm - tested on MBT2220 and SG3100:
I can't replicate it every time - I would say the majority ...
Vladimir Lind
06:44 AM Bug #9480 (Not a Bug): sylogd crash with misconfigured static arp entries
That's not a syslogd problem, just a symptom of your misconfiguration. It can't send the packet out due to your broke... Jim Pingle
06:32 AM Bug #9480 (Not a Bug): sylogd crash with misconfigured static arp entries
Hi,
h2. My setup
* 2 pfSense boxes running in HA setup
* Remote logging enabled
* DHCP servers with failover ...
Boris Lechner

04/16/2019

10:43 AM Bug #9478 (Resolved): Unable to check for updates from the GUI when using a proxy with authentication
When pfSense is set to use an upstream proxy with authentication, the update check fails to run from the GUI. It work... Jim Pingle

04/15/2019

05:20 PM Bug #9477 (Not a Bug): 2.4.4-RELEASE-p2 + XG-1537 SFP+ port issue - critical
This seems more like a configuration issue, such as not having a high enough mbuf allocation setup.
Please post to...
Jim Pingle
04:18 PM Bug #9477 (Not a Bug): 2.4.4-RELEASE-p2 + XG-1537 SFP+ port issue - critical
If something is installed in the SFP+ Ports on the XG-1537 then the interfaces ix0 and ix1 will not come up during bo... Kristian Junkov
03:12 PM Revision a0930ca6: Fix another typo
Jim Pingle
02:59 PM Revision 2309b26a: status.php updates
* Ensure firewall info is generated when run from the CLI
* For SG-1100, also include its public key
Jim Pingle
01:53 PM Revision b0945941: Fix a typo.
Reported by: jimt Luiz Souza
12:05 PM Revision 929cc874: Fix typo
Jim Pingle
11:56 AM pfSense Packages Bug #9473 (Resolved): Lightsquid 1.8_5 doesn't ensure line breaks between cert and key when generating cert.pem file
Fixed in lightsquid pkg version 3.0.6_6. Jim Pingle
10:44 AM pfSense Packages Feature #6226: Add usb_modeswitch to the pfSense package repo
Docs have been updated. Jim Pingle
08:08 AM pfSense Packages Feature #6226: Add usb_modeswitch to the pfSense package repo
Jim Pingle wrote:
> usb_modeswitch has been available from the pfSense (not FreeBSD) repo for months now, including ...
Savas Yucedag
07:23 AM pfSense Packages Feature #6226 (Closed): Add usb_modeswitch to the pfSense package repo
usb_modeswitch has been available from the pfSense (not FreeBSD) repo for months now, including in the latest release... Jim Pingle
04:27 AM pfSense Packages Feature #6226: Add usb_modeswitch to the pfSense package repo
khaled osama wrote:
> update for pfsense 2.4.4
>
> run the following command to support pfsense 2.4.4
>
> pkg ...
Savas Yucedag
09:32 AM pfSense Packages Bug #9475 (Duplicate): Monitoring "add view" bug
Duplicate of #9352 Jim Pingle
09:05 AM pfSense Packages Bug #9475 (Duplicate): Monitoring "add view" bug
1. Open Status/Monitoring
2. Expand Settings
3. Click Display Advanced
4. Click Add View and then Cancel (or Esc)
...
Alex Kolesnik
09:12 AM Bug #9476 (Rejected): pfSense 2.4.x sending ARP replies with non-CARP source MAC address

pfSense 2.4.x will send ARP replies for CARP interfaces with the local system's "real" source MAC address, instead ...
Michael Reygers
07:57 AM Bug #9474 (Not a Bug): no default gateway after changing the wan interface ipv4 configuration type from dhcp to fixed ip
what started the problem
- ISP unexpectedly changed it's router configuration from dhcp to static ip but all IP ar...
david stievenard

04/14/2019

02:15 PM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
With WAN down and that being the only default route, this should result in an "No route to host" error, and no connec... Anonymous
02:08 AM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
Well I think it's only because ews.netgate.com is down. I've override the host to localhost and this solves the probl... Car F

04/13/2019

10:38 PM pfSense Packages Bug #9473 (Resolved): Lightsquid 1.8_5 doesn't ensure line breaks between cert and key when generating cert.pem file
similar to stunnel Bug #9118
If user imported key doesn't contain a trailing line break, the cert.pem will not con...
Marc Skarshinski

04/12/2019

05:18 PM Bug #9472 (Resolved): Unable to select QinQ interfaces for PPP interface
After a QinQ interface has been created eg. vmx0.13.2 , this interface isn't available in the drop-down menu when sel... Tony Jago
03:23 PM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
Hello Gentlemen,
Been sandbagging this thread as I've ran into this issue several times and I think I have an easy...
Anonymous
02:31 PM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
https://ews.netgate.com/copyright is down right now (504 Gateway Timeout): all attempts at loading the dashboard are ... Mr Reed
01:09 PM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
Speaking from some recent experience:
This behavior interferes with troubleshooting if the root cause is a WAN fai...
John Burwell
12:32 PM Bug #8987: Web GUI main page very slow to load if wan interface is enabled but not connected.
Since 3 hours I'm having the exact same issue! Car F
02:52 PM Bug #9471 (Resolved): GIF tunnel not added to interface group after reboot
Hello!
I have a GIF tunnel (gif0, opt4, TUN_6IN4_HE) configured as part of an interface group (PFORWARD_WAN). It g...
Foster Snowhill

04/11/2019

12:57 PM Revision 4b70a200: Rewrite unbound remotecontrol.conf when it is empty. Fixes #9470
Jim Pingle
12:00 PM Revision 503df8f6: Enable Telegraf build on ARMv7
Renato Botelho
08:05 AM Bug #9470 (Feedback): unbound remotecontrol.conf not rewritten when the file is empty
Applied in changeset commit:4b70a2006e6afb7813344eec8cafb8570e67256b. Jim Pingle
07:54 AM Bug #9470 (Resolved): unbound remotecontrol.conf not rewritten when the file is empty
If @/var/unbound/remotecontrol.conf@ is empty, it will not be rewritten. The code to write the file checks that the f... Jim Pingle

04/10/2019

02:11 PM Feature #1189: Gateway: Multiple monitor ips
Yep. I want that too. Just my Parents hadnt Phone, because my PoolDNS IP went down and it switched over to only Inter... Marvin Klose
10:18 AM Bug #9469 (Resolved): Removing the last ATLQ traffic shaper queue does not sync to secondary via XMLRPC
With an HA cluster synchronizing settings via XMLRPC, when the last ATLQ traffic shaper queue is deleted that change ... Jim Pingle
10:16 AM Bug #9468 (Resolved): Removing the last limiter does not sync to secondary via XMLRPC
With an HA cluster synchronizing settings via XMLRPC, when the last limiter is deleted that change is not reflected o... Jim Pingle
10:13 AM Bug #9467 (Resolved): vmx(4) interfaces do not have ALTQ support on pfSense 2.5, they had ALTQ support on 2.4
Shamelessly copied from #7066 since it's the same issue here.
Attempting to configure traffic shaping on a pfSense...
Jim Pingle
09:22 AM Bug #9466: DHCP (IPv4) relay mistakenly listening on upstream interface
Once upon a time that was necessary to see the return traffic. The most recent version of @dhcrelay@ now supports a c... Jim Pingle
09:14 AM Bug #9466 (Resolved): DHCP (IPv4) relay mistakenly listening on upstream interface
Hello!
Not sure if this is dhcrelay's intended behaviour, but it is listening on the upstream interface when it's ...
Foster Snowhill

04/09/2019

06:31 PM Bug #9465 (Duplicate): Lost default gateway after recover from failover with CARP VIP and HA
Hi all
This problem is still (or again) reproducable with 2.4.4p2.
https://redmine.pfsense.org/issues/8465
Tom Huerlimann
04:47 PM Feature #8645: Upload certificate file instead of pasting
Just submitted: https://github.com/pfsense/pfsense/pull/4063 Michael Newton
12:15 PM Revision 78645511: Revert "Change ovpn_auth_verify_async to php-cgi. Fixes #9460"
check_reload_status 0.0.10 fixes the original issue, this can go back
the way it was.
This reverts commit ce76f29985...
Jim Pingle

04/08/2019

07:18 PM Bug #9460 (Feedback): OpenVPN local auth failing due to fcgicli output
check_reload_status 0.0.10 should fix it Renato Botelho
05:49 PM Bug #9460: OpenVPN local auth failing due to fcgicli output
Tested a potential change from Renato and it appears to work as expected... Jim Pingle
08:20 AM Bug #9460 (In Progress): OpenVPN local auth failing due to fcgicli output
Looks like the issue in fcgicli should be addressed as a better fix. Assigning to Renato per his request. Jim Pingle
07:58 AM Feature #9464 (New): Marvell 6000 -- netgate hardware (e.g.: XG-7100, XG-3100) internal switch LACP support
The Netgate Hardware with Marvell 6000 Series internal switch lack of the LACP feature on the external ports.
This b...
Daniele Palumbo
07:31 AM Bug #9427 (Duplicate): OpenVPN Server Local User Auth fails
Duplicated by #9460 but it has the cause and fix there, so closing this one. Jim Pingle
07:29 AM Bug #9463: Extremely Slow Performance with Chelsio NICs on Hyper-V (Only Pfsense Impacted)
Thanks for the reply. In theory, I entirely understand where you are coming from. What I am struggling with signifi... Taylor Higley
07:22 AM Bug #9463 (Not a Bug): Extremely Slow Performance with Chelsio NICs on Hyper-V (Only Pfsense Impacted)
If pfSense is connected to a virtual switch it has no way to know what kind of network adapter is tied into that swit... Jim Pingle
04:34 AM Bug #9463 (Not a Bug): Extremely Slow Performance with Chelsio NICs on Hyper-V (Only Pfsense Impacted)
I have a multi-node Hyper-V cluster, each with an Intel X540 10G NIC and a Chelsio T540-BT 10G NIC. The Intel NICs a... Taylor Higley

04/07/2019

10:38 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Hi All,
I have experienced the same issue as reported in the bug descrip.
I have also discovered when searching...
Shane Angelo
03:21 PM Bug #9447: Configuring LAGG at XG-7100 Switch Ports Broken
Daniele Palumbo wrote:
> +1 as i was about to report the same bug.
> I think the following is the fix, applicable t...
DRago_Angel [InV@DER]
08:26 AM Bug #9447: Configuring LAGG at XG-7100 Switch Ports Broken
+1 as i was about to report the same bug.
I think the following is the fix, applicable to 2.4.4p2
https://forum.net...
Daniele Palumbo
10:05 AM Feature #9462 (Rejected): auto alias update
This already works if you put the hostname in the alias to start with. If you have more questions, post on the forum. Jim Pingle
09:50 AM Feature #9462 (Rejected): auto alias update
I think it would be great to add a feature to update automatically the ip address lists for a dns record involved in ... Federico Galli
02:23 AM pfSense Packages Todo #9200: Add DNS support for Google domain to Acme manager
Adding a request for this myself. Matt D

04/06/2019

10:18 PM pfSense Docs Correction #9461 (Closed): Feedback on Services — DNS — Configuring the DNS Resolver
*Page:* https://docs.netgate.com/pfsense/en/latest/dns/unbound-dns-resolver.html
*Feedback:*
I think the explan...
Anchal Nigam
11:04 AM Bug #7918: Nightly error reloading rules
Ok in my case the error was caused by me accidentally setting two queues to the same priority on FAIRQ.
So to avoi...
Chris Collins
09:47 AM Bug #9357: rc.newwanipv6 called regardless of REASON
A dirty patch I am using for now is adding these lines in /var/etc/dhcp6c_wan_script.sh... Flole Systems
04:01 AM Revision ce76f299: Change ovpn_auth_verify_async to php-cgi. Fixes #9460
Jim Pingle

04/05/2019

11:10 PM Bug #9460 (Feedback): OpenVPN local auth failing due to fcgicli output
Applied in changeset commit:ce76f299853dccb036de229f08a30013593c98fd. Jim Pingle
11:00 PM Bug #9460 (Resolved): OpenVPN local auth failing due to fcgicli output
OpenVPN local auth is failing on 2.5.0, due to what appears to be a change in fcgicli output.
Testing with @set -x...
Jim Pingle
03:29 PM pfSense Packages Feature #8613: pfSense-pkg-acme: acme_certificates_edit.php - Add support for --challenge-alias acme.sh flag
You are right. I could swear when I did that it was the other way, but I don't see any history of that being the para... Jim Pingle
03:19 PM Bug #9459 (Resolved): patch pf: silence a runtime warning pfr_update_stats: assertion failed.
I get pf warning spam non-stop
@pfr_update_stats: assertion failed.@
!1554493871691-a1c96692-b5ae-4d45-9f73-719...
rub man
11:08 AM Bug #9458 (Rejected): IPSec cannot use under more than 2 phase1 rules
Not enough information. This is most likely a configuration or environment issue. Please post on the forum to discuss... Jim Pingle
11:03 AM Bug #9458 (Rejected): IPSec cannot use under more than 2 phase1 rules
for example:
I have 4 pfsense devices, A,B,C,D
I add 3 phase 1 rules in device A in IKEv2 to connect B(con1000) C...
Jinwen Guo
07:30 AM Bug #9455 (Rejected): Disable fetching of bogon tables when not used
They have to be kept up-to-date or otherwise when someone chooses to enable bogons later, they could be very outdated... Jim Pingle
03:21 AM Bug #9455 (Rejected): Disable fetching of bogon tables when not used
If all interfaces has "Block bogon networks" unticked I would expect that periodic fetching of bogon tables was not n... Lars Pedersen
07:27 AM Bug #9456 (Rejected): pfsense clears given smtp auth fields
Can't reproduce the problem as stated. When the form is filled in and saved, the values all stay as expected. Even wh... Jim Pingle
03:38 AM Bug #9456 (Rejected): pfsense clears given smtp auth fields
Configuring smtp-auth for smtp.gmail.com:
E-Mail-server: smtp.gmail.com
SMTP-Port: 465
Secure SMTP Connection: y...
Thomas Schweikle
07:22 AM pfSense Docs Correction #9457 (Rejected): Feedback on Services — IPv4 DHCP Server
There are no DHCP options available that work from the system tunables tab. Jim Pingle
05:40 AM pfSense Docs Correction #9457 (Rejected): Feedback on Services — IPv4 DHCP Server
*Page:* https://docs.netgate.com/pfsense/en/latest/book/services/ipv4-dhcp-server.html
*Feedback:*
Please add a...
Rickard u
05:26 AM Feature #4632: Support for Multipath TCP (MPTCP)
+1
would be great to have
IT IGP
05:06 AM Feature #4632: Support for Multipath TCP (MPTCP)
+1
Support for mptcp would be greatly appreciated
Thomas Möhle

04/04/2019

11:06 PM pfSense Docs New Content #9454 (New): Add examples of Snort Suppression Lists to stop alerts based on source and destination IP addresses
*Page:* https://docs.netgate.com/pfsense/en/latest/packages/snort/suppress-list.html
*Feedback:*
The documentat...
Michael De
06:53 PM Bug #9453 (Resolved): Reconfiguring a parent LAGG interface breaks its VLANs
Environment: SG-1000
Not sure if this is valid in other environment.
Upon boot, all the VLANs get orphaned.
Th...
Daniele Palumbo
03:57 PM pfSense Packages Bug #9020: Impossible to register ACME wildcard certificate regardless documentation
Same Bug here:
Version: 2.4.4_2
Same Config: Issue/Renew --> Bug goes away!
I have see the Bug more then one (...
Tobias Haas
02:55 PM Feature #1257: Handle encypted CA/Certificate private keys
I made a preliminary PR that adds support for encrypted private keys to the CA, certificate, and user managers.
Woul...
Peter Feichtinger
05:41 AM Feature #9452: Add Gandi LiveDNS DynDNS client.
PR created https://github.com/pfsense/pfsense/pull/4061 Eric VANTILLARD
05:37 AM Feature #9452 (Resolved): Add Gandi LiveDNS DynDNS client.
Add Gandi as a DynDNS client using the LiveDNS API (see doc https://doc.livedns.gandi.net/)
I will commit a PR in ...
Eric VANTILLARD

04/03/2019

04:42 PM pfSense Packages Bug #9451: Add Zabbix 4.2 (agent and proxy) packages
It's not in FreeBSD ports yet. Jim Pingle
04:38 PM pfSense Packages Bug #9451 (Resolved): Add Zabbix 4.2 (agent and proxy) packages
https://www.zabbix.com/documentation/4.2/manual/introduction/whatsnew420 benoit moreau
04:41 PM Revision cd39f5e7: Merge pull request #1 from Augustin-FL/patch-captiveportal-trim
Also trim if() statement jeroen van breedam
12:22 PM Bug #7918: Nightly error reloading rules
confirmed same problem here, never seen it before then out of nowhere suddenly no type of rule update can be carried ... Chris Collins
07:24 AM Bug #9444: Multi-WAN IPsec does not fail over with Gateway Group, needs restart
3 minutes sounds about right for a DNS-based changeover. It takes time for DNS updates to propagate and be noticed. T... Jim Pingle
02:26 AM Bug #9444: Multi-WAN IPsec does not fail over with Gateway Group, needs restart
Mouad Mimouni wrote:
> Jim Pingle wrote:
> > There isn't enough information here to speculate as to the cause or fi...
Mouad Mimouni
06:01 AM Bug #9450 (Resolved): Multiwan gateway group fail-over not working as expected (possible race condition)
Multiwan gateway group fail-over not working as expected. After a link state change is triggered by dpinger (rc.gatew... nasir ahmed
01:17 AM Bug #9449 (Resolved): Empty lines in various forms
I noticed a couple of empty lines in some forms, which are caused by using @addInput@ instead of @addGlobal@ to add h... Peter Feichtinger
 

Also available in: Atom