Project

General

Profile

Activity

From 07/15/2019 to 08/13/2019

08/13/2019

09:33 PM Feature #7158: Captive Portal should have logs facilities for blocked sites
Reverse DNS almost never bears a relationship to a website these days. You'll only get a random CDN or other hosting ... Jim Pingle
09:31 PM Feature #7158: Captive Portal should have logs facilities for blocked sites
Jim Pingle:
Having the IP address being requested I could make a reverse lookup to identify the owner of the IP th...
Jose Torres
03:57 PM Feature #7158: Captive Portal should have logs facilities for blocked sites
The firewall has no way to know what any of that is. It sees a request to an IP address on port 80, for example, and ... Jim Pingle
03:55 PM Feature #7158: Captive Portal should have logs facilities for blocked sites
Jim Pingle:
Since it was rejected. Please tell me an alternative to get the address that is being redirected to t...
Jose Torres
02:56 PM Feature #7158 (Rejected): Captive Portal should have logs facilities for blocked sites
The subject says Captive Portal, description says proxy. Captive Portal doesn't block sites, it redirects everything ... Jim Pingle
08:07 PM pfSense Packages Feature #9682 (Rejected): Please supply Emacs
The base install includes vi and ee, and you can edit remotely via scp.
It's meant to be a firewall not a general ...
Jim Pingle
07:59 PM pfSense Packages Feature #9682 (Rejected): Please supply Emacs
Emacs is not installed by default, and is not available as a package for installation. For emacs users, pfSense is ef... Jeffrey Walton
08:00 PM Bug #7382: DNS Forwarder does not resolve DNS names on first boot
Hard to say what will help when we don't have much to go on. You'd pretty much have to setup a lab box and then add b... Jim Pingle
07:38 PM Bug #7382: DNS Forwarder does not resolve DNS names on first boot
I believe we have one of those edge cases that still requires the forwarder - we need to specify a source IP for host... Jeremy Nelson
05:45 PM Bug #7382: DNS Forwarder does not resolve DNS names on first boot
I wouldn't say "not supported", but not preferred. We prefer to focus any development toward the DNS Resolver. There ... Jim Pingle
04:26 PM Bug #7382: DNS Forwarder does not resolve DNS names on first boot
I can confirm this is still an issue, but am I to understand that DNS Forwarder is no longer supported and that all f... Jeremy Nelson
03:22 PM Bug #7382 (Closed): DNS Forwarder does not resolve DNS names on first boot
Old report and no recent recurrences. DNS Forwarder is no longer the preferred resolver, if it's still and issue with... Jim Pingle
07:21 PM Bug #7298 (Closed): IPv6 on a second interface doesn't work until the router is pinged
OK, thanks for the update! Jim Pingle
07:10 PM Bug #7298: IPv6 on a second interface doesn't work until the router is pinged
This issue stopped at some point. I don't recall if I did something, or an update took care of it or what, but I'd c... Andy Wang
06:50 PM pfSense Packages Feature #4503: GNUGateKeeper H.323 Proxy Package
Jim Pingle, this is very good news, I'm really looking forward to this package, but I'm not sure that this package pr... Aleksei Aksenov
12:53 PM pfSense Packages Feature #4503: GNUGateKeeper H.323 Proxy Package
If someone wants to package that up properly and submit a PR, we can consider it for inclusion as a package. Jim Pingle
06:40 PM Revision 083a9a82: Disable packages that don't build on armv7
Renato Botelho
03:49 PM Bug #7759 (Closed): No version control number showing when going to System > Update
Old report and no recent recurrences. Lots of things in this area have changed, so most likely it's either fixed no l... Jim Pingle
03:46 PM Bug #7653 (Closed): 3gstats.php holding open the cuaU0.3 device
Old report and no recent recurrences. Lots of things in this area have changed, so most likely it's either fixed no l... Jim Pingle
03:46 PM Bug #7656 (Closed): TypeError: n is undefined JavaScript error in status_monitoring.php
Old report and no recent recurrences (plus I can't reproduce it). Lots of things in this area have changed, so most l... Jim Pingle
03:46 PM Bug #7663 (Closed): Persistent CARP Maintenance Mode doesn't work right in upgrade from 2.3.3-RELEASE-p1 to 2.3.4
Old report and no recent recurrences. Lots of things in this area have changed, so most likely it's either fixed no l... Jim Pingle
03:46 PM Feature #7668 (Closed): MAC Address spoofing
VLAN interfaces no longer have enabled controls to set the MAC, so this is moot. See #1337 Jim Pingle
03:46 PM Bug #7700 (Closed): Port Forwarding Failing - with Alias
Old report and no recent recurrences. Lots of things in this area have changed, so most likely it's either fixed no l... Jim Pingle
03:46 PM Bug #7697 (Resolved): NAT port forward rule using "WAN address" doesn't work as expected if router does not acquire a WAN address on startup
Likely solved by the linked PR and no feedback either way from OP. Closing. Jim Pingle
03:46 PM Bug #7721 (Feedback): NTPd stops using external peers if listening on one interface only in a muliwan setup
Can you re-test this on a current release or development snapshot? Preferably a 2.5.0 snapshot. Jim Pingle
03:46 PM Feature #7738: Highlight which IPSec (or other VPN) crypto modes are hardware-accelerated in the UI
I'm not sure if we can do this. A lot of this is hardware-dependent, and unfortunately, OpenSSL 1.1.1 seems to have m... Jim Pingle
03:32 PM Bug #7494 (Closed): SG-1000 - WAN Status UP - Hosts no internet connection
Old report and no recent recurrences. Lots of things in this area have changed, so most likely it's either fixed no l... Jim Pingle
03:32 PM Bug #7492 (Closed): SG-1000 occasionally loses Internet connectivity
Old report and no recent recurrences. Lots of things in this area have changed, so most likely it's either fixed no l... Jim Pingle
03:32 PM Bug #6957 (Closed): CARP arp reply with wrong src mac
That patch was removed long ago, and is not included in pfSense 2.4.x or 2.5.x. Doubtful there is anything to do here... Jim Pingle
03:32 PM Bug #7601 (Feedback): Dynamic DNS - Hostname should not be required for DNS-O-Matic
Is this still a problem? There have been lots of DynDNS changes since this report, but I don't see anything that look... Jim Pingle
03:29 PM Bug #7371 (Closed): pfsense load balancer relayd does not load balance dns with udp+tcp
relayd has been deprecated and removed from 2.5.0 Jim Pingle
03:23 PM Bug #4674: invalid state table entries after WAN IP change
Looking at /etc/rc.newwanip it does appear to make more sense to configure before killing the old states. Jim Pingle
03:22 PM Feature #7304: DHCP: Enable OMAPI Config
PR link: https://github.com/pfsense/pfsense/pull/4077
Jim Pingle
03:22 PM Bug #7186: Unable to use national symbols in password fo ACB package
This should just be a matter of adding @'encryption_password'@ to the @$cdata_fields@ array in @etc/inc/xmlparse.inc@. Jim Pingle
03:22 PM Feature #7350 (Duplicate): Unbound host/domain override needs better IPv4/IPv6 handling?
Duplicate of #6881 Jim Pingle
03:22 PM Feature #6242 (Rejected): Use local user datebase for IKEv2 EAP-Charpv2
For that to work you need EAP, which is not something the base system is going to be able to do easily. Fortunately i... Jim Pingle
03:22 PM Feature #4372 (Closed): dnscrypt support
For most use cases, DNS over TLS has made this unnecessary. For others, there is #9315 Jim Pingle
03:22 PM Feature #7442: Suggestions for Diagnostics / ARP Table and Diagnostics / NDP Table
Ping is not likely to be helpful or useful in most cases. For mass pings, use the nmap package.
There is a status ...
Jim Pingle
03:22 PM Feature #7441: Display start/end times for Static Mapping leases on DHCP Leases/DHCPv6 Leases
There is no 'release' or 'renew' action for the server to perform. Those must be done by the client.
Displaying th...
Jim Pingle
03:22 PM Feature #7459: "Refresh" button for Diagnostics/Tables display
A refresh button would definitely be useful.
The current "Update" button updates the table from a remote source, l...
Jim Pingle
02:56 PM Bug #7018 (Closed): DHCP packets replicated on non-DHCP relay interface
Most likely solved by #9466 or other changes in the last few years. Jim Pingle
02:56 PM Feature #7030: New Feature Load Balance Per Amount Of GB
There is no viable mechanism to pull this off. It isn't supported in pf, and there are no built-in long-term traffic ... Jim Pingle
02:56 PM Bug #6981 (Closed): IPv6, rc.newwanipv6, flooding log and resets connection periodically
Jim Pingle
02:56 PM Feature #7092: Kernel modules for alternate congestion control algorithms
There are more available now:... Jim Pingle
02:56 PM Bug #7184 (Rejected): FW limits MTU to 1280 when using VPN tunnel to F5
This site is not for support or diagnostic discussion.
For assistance in solving problems, please post on the "Net...
Jim Pingle
02:56 PM Bug #7200 (Closed): Diagnostics> DNS Lookup: external links to DNSstuff use wrong parameter
These tools were removed a while ago, as they were no longer working. See #9275 Jim Pingle
02:56 PM Bug #7207 (Closed): Updates and Package Manager broken when pfSense accessed via SSH port forward
Old report and no recent recurrences. Lots of things in this area have changed, so most likely it's either fixed no l... Jim Pingle
02:55 PM Bug #7168 (Closed): Vague kernel messages in system log
This still happens but there isn't much we can do about it, and even if we could, I'm not sure it would be helpful. T... Jim Pingle
02:55 PM Bug #6687 (Duplicate): Secure email fails with private CA
The root issue is definitely #4068, but an option was added to bypass this check in #9001 so this is a duplicate twic... Jim Pingle
02:36 PM Feature #6909 (Duplicate): Copy FW rules to new interface efficiency
Duplicate of #8365 Jim Pingle
02:36 PM Feature #6795 (Duplicate): User certificate for webGUI login
Duplicate of #8694 Jim Pingle
02:35 PM Bug #6694 (Resolved): Change setting at interfaces_ppps_edit.php not working
This was fixed long, long ago. Jim Pingle
02:35 PM Bug #6747 (Closed): pfctl - getting high cpu usage
Old report and no recent recurrences. Lots of things in this area have changed, so most likely it's either fixed no l... Jim Pingle
02:35 PM Feature #6827 (Closed): Add Proxy Mobile IPv6 (PMIPv6)
I don't see any evidence that it's currently supported on FreeBSD. If a FreeBSD implementation happens and someone wa... Jim Pingle
02:35 PM Bug #6834 (Closed): VIPs can cause hard-to-trace issues with dhcpd.conf
I don't see anything actionable here. There is only so much we can do to prevent foot-shooting. Jim Pingle
02:35 PM Feature #6839 (Closed): Mechanism to prevent flooding log with entries from blocked packets
The solution is as others stated, disable the default rules (or logging of same) and create your own rules that do wh... Jim Pingle
02:34 PM Bug #6912 (Closed): install on Hyper-v R2
Old version of pfSense and Hyper-V from years ago, unlikely to be a current problem. Test on 2.5.0 and if it still ha... Jim Pingle
02:34 PM Bug #6955 (Resolved): The uniqid of the virtual IP address is lost when you modify the vip type
This was solved a while back, likely with PR https://github.com/pfsense/pfsense/pull/3842 (commit:807160e9db2e7fe2296... Jim Pingle
01:43 PM Feature #9661: Increase the number of DHCP/DHCPv6 NTP server options to three (or more)
PR Link: https://github.com/pfsense/pfsense/pull/4078 Jim Pingle
12:03 PM Feature #9661: Increase the number of DHCP/DHCPv6 NTP server options to three (or more)
sorry i was still writing, i will do the pr later on Manuel Piovan
12:01 PM Feature #9661: Increase the number of DHCP/DHCPv6 NTP server options to three (or more)
this need to go on services_dhcpv6.php
line 154...
Manuel Piovan
11:59 AM Feature #9661: Increase the number of DHCP/DHCPv6 NTP server options to three (or more)
Submit that as a PR and we can test/merge it much easier.
https://docs.netgate.com/pfsense/en/latest/development/s...
Jim Pingle
11:53 AM Feature #9661: Increase the number of DHCP/DHCPv6 NTP server options to three (or more)
pls we ask to add this on services_dhcp.php at least ntp3
line 175 -> ...
Manuel Piovan
11:19 AM Feature #9661: Increase the number of DHCP/DHCPv6 NTP server options to three (or more)
right i have local ntp stratum 1 servers myself but i configure ntpd manually, i had never thought of it before ... ,... Manuel Piovan
01:43 PM Revision fc79c7d3: Merge pull request #4029 from BBcan177/patch-1
Renato Botelho
01:41 PM pfSense Packages Feature #7903: Duo ssh package
See also: #6556 Jim Pingle
01:41 PM Feature #6556 (Duplicate): Support Duo Security two-factor authentication for local user database
Duplicate of #7903 Jim Pingle
01:40 PM Bug #6540 (Resolved): Virtual IPs -> Edit does not allow upper-case IPv6 digits
I'm pretty sure this was all fixed in https://github.com/pfsense/pfsense/pull/3199 and maybe additional PRs. Jim Pingle
01:40 PM Bug #6565 (Closed): OpenVPN calculates incorrect TCP checksums when running in bridged/tap mode with 'mode server'
Old report, this was several OS and OpenVPN versions ago, and no recent sightings. Jim Pingle
01:39 PM Bug #6568 (Not a Bug): NanoBSD image unconditionally enables comconsole.
NanoBSD has been deprecated for a while now. Jim Pingle
01:39 PM Bug #6575 (Closed): GEOM Mirror Status Change Re-sync notices
There was some recent work on notifications that may help here, but some people may need to know about this progress,... Jim Pingle
01:39 PM Todo #6645 (Closed): More reliable update system
A lot has been fixed here in the years since this report. Jim Pingle
01:39 PM Feature #6644 (Closed): Add console shutdown option along with reboot at end of installation
Between installer changes and Hyper-V changes in the last 3 years, this doesn't seem to be an issue for users anymore. Jim Pingle
01:39 PM Bug #6678 (Duplicate): Virtual IPv6 IP (IP Alias) on a DHCPv6-PD tracked interface causes inconsistencies
Jim Pingle
01:39 PM Feature #6546 (Closed): pfSense should support logging to e.g. ELK stacks
This will be moot on 2.5.0: See #8350 Jim Pingle
01:23 PM Feature #6385 (Closed): Add Download-only option to System Update
This is unnecessary. You can run @pkg upgrade --fetch-only@ or @pkg upgrade -F@ and it will offer to download before ... Jim Pingle
01:23 PM Bug #6409 (Closed): hostname in alias does not work for port forwarding
I've seen this working recently (other filterdns issues notwithstanding). Jim Pingle
01:23 PM Feature #6411 (Closed): Classification if updates require a reboot
Upgrades that do not need a reboot are extremely rare, and the release announcement/upgrade notes will state whether ... Jim Pingle
01:23 PM Bug #6426 (Not a Bug): Regression Bug #3216
This works fine but you have to navigate straight to the voucher page(s) with the correct zone in the URL.
It can'...
Jim Pingle
01:23 PM Feature #6526 (Closed): pfSense Update information via SNMP
There isn't a viable way to do this in base SNMP. You can script up something with the NET-SNMP extend feature withou... Jim Pingle
01:23 PM Bug #6542 (Closed): Cannot revoke DHCPv6 leases from the GUI
There isn't a way to revoke a lease from either IPv4 or IPv6 DHCP server status/leases pages. I'm not sure if there i... Jim Pingle
01:23 PM Feature #6544: RFC 3046 DHCP Option 82 support (and RFC 3315/4649/4580 for IPv6)
If someone wants to make PR to show this info in the GUI somewhere, we can consider it. But adding a whole column for... Jim Pingle
12:55 PM Feature #6336 (Duplicate): link to release notes on update page
Duplicate of #5074 Jim Pingle
12:53 PM Todo #4123 (Closed): Add support to multiple tables to expiretable
@virusprot@ is the only base table left using this, so I don't think we need to change it anymore. Jim Pingle
12:53 PM Todo #5553 (Resolved): Suggestion: higher default MBUF values
This has been in place for some time now for hardware we can predict. The OS is a bit smarter in other situations as ... Jim Pingle
12:53 PM Feature #5708 (Rejected): NAT 1:1 applicate on some interfaces and/or interface group
The request isn't clear. If you mean allow choosing an interface for the external IP address of 1:1 NAT, I doubt we'l... Jim Pingle
12:52 PM Feature #6207: Please, add "THIS_IF broadcast" Macro for use in firewall rules
Note: If this gets implemented, input validation should reject choosing this with IPv6 or IPv4+6 rules since IPv6 has... Jim Pingle
12:24 PM Feature #736 (Resolved): Privileges for accessing each service that uses the user manager
This has been in place for some time now. Jim Pingle
12:24 PM Feature #1223 (Closed): gateway group based sticky connections
No further requests and given how quirky sticky is already, I doubt this would help much. Jim Pingle
12:23 PM Feature #2994 (Resolved): Allow setting a default scale type for the traffic graphs widget
This has been in place for some time now, and the graphing library has changed since this was opened. Jim Pingle
12:23 PM Feature #2319 (Resolved): include SSD TRIM option in installer
No longer relevant. It's automatic for ZFS and is already enabled where needed. Jim Pingle
12:23 PM Bug #2544 (Closed): Installer does not allow exact partition sizes
This installer has been completely changed out since this was opened. Jim Pingle
12:23 PM Bug #3547 (Closed): When using LDAP Groups, user is authenticated and granted xauth ipsec irrespective of group permissions
The IPsec daemon and other subsystems have changed a lot since this was opened. If it's still an issue, please post o... Jim Pingle
11:10 AM pfSense Packages Bug #8251: Captiveportal + FreeRadius "Last activity" resets to Session start
Really? I checked the changelogs before and didn't see anything too interesting.
Also since I am somewhat afraid of ...
Frotty Zaoldyeck
09:37 AM pfSense Packages Bug #8251 (Feedback): Captiveportal + FreeRadius "Last activity" resets to Session start
There have been lots of Captive Portal changes since this was opened, you should re-test on a 2.5.0 snapshot to see i... Jim Pingle
10:45 AM Bug #9258: Error deleting tunnel type P2 when mixed with VTI
Problem remains on 2.4.4-RELEASE-p3
Work-around works.
Mix Room
10:27 AM Bug #8124 (Closed): username/password not used by proxy support
This has been fixed for a while. There is still one issue on snapshots (#9478) but that bug has more current informat... Jim Pingle
10:25 AM Bug #4251 (Closed): NAT Reflection not working if LAN is bridged
This is almost certainly solved via pure NAT reflection. Open a new issue with current info if it is not. Jim Pingle
10:23 AM Bug #1575 (Resolved): Limiters are bypassed by local applications injecting rules
Jim Pingle
10:23 AM Bug #3640 (Closed): Sierra Wireless 3G Modem support driver
I'm fairly certain this has been solved, either by #4863 or by one of the various OS upgrades that have happened sinc... Jim Pingle
10:22 AM Bug #3771 (New): Webinterface and dhcpdcrashes with 500+ static leases
Needs re-tested on a current release or development snapshots (preferably 2.5.0 snapshots) Jim Pingle
10:20 AM Bug #4856 (Closed): Traffic Shaper blocks traffic when the config is otherwise changed
Jim Pingle
10:19 AM Bug #4981 (Closed): Remote logging not active after reboot
As far as I'm aware this isn't currently an issue any longer. Jim Pingle
10:18 AM Bug #5319 (Closed): Error message "No config named" in charon daemon
No timely and meaningful feedback received. Jim Pingle
10:17 AM Bug #5702 (Closed): Bug in code manipulating IP subnets - could be pervasive?
PR was closed, so this shall follow. Jim Pingle
10:16 AM Bug #6668: IPSec tunnel + L2TP/IPSec VPN - wrong PSK chosen by pfSense
Is this still a problem, even on 2.5.0 snapshots? Jim Pingle
10:15 AM Bug #6685 (Closed): LAGG groups get stuck with an unconfigurable 1400MTU with em NICs.
No feedback received. Jim Pingle
10:15 AM Bug #7600 (Closed): Unable to save DNS Resolver settings
Either this has been resolved, or it may be a package issue. Either way this specific issue can be closed. If it can ... Jim Pingle
10:13 AM Bug #7611 (Not a Bug): Diagnostics/Routes ipv6 ( netstat ), causes kernel panic
Jim Pingle
10:13 AM Bug #7778: DHCP relay not working correctly with bridges
Can you test this again on a 2.5.0 snapshot? There have been other DHCP Relay changes and it may be solved. Jim Pingle
10:11 AM Bug #8287 (Not a Bug): /var/unbound/test/unbound_server.pem: No such file or directory
Cannot reproduce Jim Pingle
10:11 AM Bug #8633 (Resolved): thousands PHP undef gwname /etc/inc/gwlib.inc line 1210
No feedback received. Jim Pingle
10:10 AM Bug #9070 (Closed): After performing in-place upgrade from 2.4.3-RELEASE-p1 to 2.4.4 DHCPV6 client fails to retireve a WAN address
No feedback received. Jim Pingle
10:10 AM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
Lynn Dixon wrote:
> I am still wishing this would get fixed as well. Not much traction on my bounty thread either.
...
xander bron
10:09 AM Bug #9429 (Rejected): When enabling https access to WebConfigurator
No feedback received. Jim Pingle
10:04 AM pfSense Packages Bug #9573 (Rejected): GeoIP database FAIL to download - Suricata package
Jim Pingle
10:00 AM pfSense Packages Bug #9573: GeoIP database FAIL to download - Suricata package
I do not believe this represents an actual bug in the Suricata package. The user was attempting to follow one of the... Bill Meeks
10:02 AM pfSense Packages Feature #4581 (Closed): Add dshield-sensor port to pfPorts
Jim Pingle
09:59 AM Bug #6907 (Duplicate): DNS Resolver does not use domain name set in DHCP subnet, only the global one
Duplicate of #1819 Jim Pingle
09:57 AM Bug #6405 (Not a Bug): OpenVPN Server fails to start at boot when listening on v6
Old and misfiled. Resubmit if it's still an issue. Jim Pingle
09:57 AM pfSense Packages Feature #4687 (Duplicate): OpenVPN Client Export - Use the VPN description when producing the exported file (instead of host-proto-port combination)
Something like this was implemented long ago. Jim Pingle
09:57 AM pfSense Packages Bug #4473 (Closed): Still can't run EGP and IGP on the same system
This is possible with FRR. Jim Pingle
09:57 AM pfSense Packages Bug #7862 (Duplicate): package zabbix lts
Jim Pingle
09:50 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
AFAIK This is because last I looked, miniupnpd doesn't support its "masquerade" options on FreeBSD/pf like it does on... Jim Pingle
09:50 AM pfSense Packages Feature #7655 (Bogus): Captive portal and squid non transparent
Jim Pingle
09:50 AM pfSense Packages Bug #7617 (Closed): OpenBGP not restarting on new WAN IP or firewall reload
Jim Pingle
09:50 AM Feature #7275 (Resolved): Add help text for DNS Made Easy
PR was merged years ago Jim Pingle
09:37 AM Bug #8253 (Rejected): Corrupt video during 2.4.x install on Dell Wyse thin client with AMD Radeon HD 6250
Unlikely we can do anything for that. Try a 2.5.0 snapshot, the FreeBSD 12 base likely behaves better. Jim Pingle
09:33 AM Bug #8814 (Rejected): After changing WAN CARP VIP Outbound NAT rules don't import new value but stay with old one and need to be changed manually
Outbound NAT rules with a CARP VIP like that are 100% manual, there is no mechanism to update those automatically sin... Jim Pingle
09:33 AM pfSense Packages Bug #8619 (Resolved): Domains improperly checked when registering DHCP static mappings
PR was merged over a year ago. Jim Pingle
09:33 AM Bug #8612 (Rejected): LAN Interface track IPv6 to PPPoE Interface didn't renew subnet
Not enough information here for a valid bug report. Jim Pingle
09:33 AM pfSense Packages Feature #8574: Enable AgentX-support in lldpd using GUI
Can you submit those patches as a PR? Jim Pingle
09:33 AM Bug #8549 (Not a Bug): IPsec: Enable bypass for LAN interface IP has no effect when supernetting in IPSec P2
Not enough here to say what's going on, start a forum thread if it's still a concern. Bypass LAN wouldn't have anythi... Jim Pingle
09:25 AM pfSense Packages Bug #9108 (Closed): OpenVPN client without "explicit-exit-notify" does not trigger client-disconnect portion of /usr/local/sbin/openvpn.attributes.sh
Jim Pingle
09:25 AM pfSense Packages Feature #9240 (Rejected): allow users to define custom ipsec configuration using web-page for ipsec
This isn't really viable, since there wouldn't be way for it to be useful to most people. It might get close if you h... Jim Pingle
09:15 AM pfSense Packages Bug #9481 (Closed): traffic totals documentation link goes to 404 page
Either this has been fixed or I just can't reproduce it. Link goes to the main docs page since there is no specific p... Jim Pingle
09:15 AM pfSense Packages Bug #9339 (Resolved): Misc typos in pfsense/FreeBSD-ports
PR was merged months ago Jim Pingle
09:15 AM Bug #9677: Dashboard hangs when widget needs data from a remote host which is down
Seems more like a general dashboard issue rather than a package-specific issue, but there may not be a good way to so... Jim Pingle
09:08 AM pfSense Packages Bug #9204 (Feedback): ospfd: GRE tunnels became unnumbered since 2.4.4
Can you test this with the current version of FRR (preferably on 2.5.0, if 2.4.4 doesn't work)?
FRR OSPF underwent...
Jim Pingle
09:03 AM pfSense Packages Bug #9451 (Resolved): Add Zabbix 4.2 (agent and proxy) packages
Jim Pingle
09:03 AM pfSense Packages Feature #7179 (Resolved): Package Filer into 2.3
Jim Pingle
09:03 AM pfSense Packages Feature #8731 (Resolved): FreeIPA support in FreeRADIUS package
Jim Pingle
09:03 AM pfSense Packages Bug #6305 (Closed): Quagga problems updating routes / mistakenly showing "kernel"-routes while they are not
Jim Pingle
09:03 AM pfSense Packages Bug #6350 (Closed): Auto Config Backup - Uncaught Exception
Jim Pingle
09:03 AM pfSense Packages Bug #7161 (Resolved): pfSense-pkg-bind9 changelog pointing to non-existent location
Jim Pingle
09:00 AM pfSense Packages Todo #9354 (Resolved): Update OpenVPN Client Export with OpenVPN 2.4.7
Jim Pingle
09:00 AM pfSense Packages Feature #8610 (Resolved): FRR BGP "no bgp default ipv4-unicast" option.
Jim Pingle
08:59 AM pfSense Packages Bug #9657 (Resolved): STunnel fails to generate an rc script
Jim Pingle
08:59 AM pfSense Packages Bug #9640 (Resolved): FRR redistribution route maps not functional
Jim Pingle
08:58 AM pfSense Packages Bug #9554 (Resolved): Stored XSS in ACME Package (version 0.5.7_1) /acme/acme_accountkeys_edit.php
Jim Pingle
08:58 AM pfSense Packages Bug #9556 (Resolved): Encoding/validation issues in apcupsd_status.php
Jim Pingle
08:58 AM pfSense Packages Bug #8308 (Resolved): FRR OSPF6D: interfaces not assigned to areas if they only have a link-local address
Jim Pingle
08:58 AM pfSense Packages Bug #8749 (Resolved): OSPF6 nssa not working
Jim Pingle
08:58 AM pfSense Packages Bug #8751 (Resolved): FRR prefix lists issues
Jim Pingle
08:58 AM pfSense Packages Todo #8662 (Resolved): FFR OSPF Cleartext Password Lengths
Jim Pingle
08:58 AM pfSense Packages Todo #8433 (Resolved): Upgrade NRPE-SSL Package to NRPE3
Jim Pingle
08:58 AM pfSense Packages Bug #9340 (Resolved): Buypass CA does not support wildcard
Jim Pingle
08:58 AM pfSense Packages Feature #9498 (Resolved): ACME Package: Sorting on name, expiration, etc
This has been in and working fine for a while. Jim Pingle
08:51 AM pfSense Packages Bug #8167 (Resolved): FRR OSPF6 range problem (subnet not advertized)
Ended up adding this back, AFAIR it was an issue with the ordering of the statements. It's been fixed (properly) for ... Jim Pingle
08:47 AM Feature #9251 (Feedback): DNS Resolver (Unbound) Python Integration
PR has been merged. Thanks! Renato Botelho
05:41 AM Feature #2358: NAT64 support
Another upvote. Would ease migration to IPv6-only LAN tremendously. Martin Grüning

08/12/2019

01:08 PM pfSense Packages Bug #9681: [Monitoring] New views title are always in lower case.
At older systems I still have titles with mixed case. But new titles are in lower case. Grischa Zengel
01:03 PM pfSense Packages Bug #9681 (Resolved): [Monitoring] New views title are always in lower case.
If I add "CamelCase" I will get "camelcase" as title.
With mixed upper and lower case the titles are more readable.
Grischa Zengel
12:58 PM pfSense Packages Bug #9679 (Resolved): [Monitoring] Add View does not work
Great, thanks for testing! Jim Pingle
12:57 PM pfSense Packages Bug #9679: [Monitoring] Add View does not work
There a no more new default tabs and removed the old one successfully with viconfig.
Thank you!
You can close t...
Grischa Zengel
12:07 PM pfSense Packages Bug #9679 (Feedback): [Monitoring] Add View does not work
I pushed a fix to avoid creating those extra "default" views, though they still cannot be deleted. You will have to m... Jim Pingle
11:50 AM pfSense Packages Bug #9679 (In Progress): [Monitoring] Add View does not work
Jim Pingle
11:33 AM pfSense Packages Bug #9679: [Monitoring] Add View does not work
The first bug is fixed. Thank you!
On cancel I still get new "default" views:...
Grischa Zengel
10:40 AM pfSense Packages Bug #9679 (Feedback): [Monitoring] Add View does not work
I was able to reproduce the problem here.
I pushed a new version of Status_Monitoring which corrects the usage of ...
Jim Pingle
07:31 AM pfSense Packages Bug #9679: [Monitoring] Add View does not work
That XML result looks like what happens when there is an attempt by the code to use an uninitialized array. Shouldn't... Jim Pingle
05:45 AM pfSense Packages Bug #9679 (Resolved): [Monitoring] Add View does not work
I added "WAN" as new View and got "wan" in lower letters. Why lower letters?
I removed it and now I can't add a new ...
Grischa Zengel
07:45 AM Feature #9680 (New): Seperate DHCP Server and relay per interface
Hello, as of now if you have dhcp relay enable you cannot enable the dhcp server on any other interface. It would be ... Mike LaCroix
07:30 AM Todo #9367 (Resolved): Update SMART Page with new capabilities
Jim Pingle
02:18 AM Todo #9367: Update SMART Page with new capabilities
Tested. Looks good. Chris Linstruth
07:30 AM Feature #9285 (New): Add an option to disable the ping-check in dhcpd
Jim Pingle
01:53 AM Feature #9285: Add an option to disable the ping-check in dhcpd
This looks like it should be added on a per-subnet basis instead of globally. As this patch stands right now if you d... Chris Linstruth
07:30 AM Bug #9569 (Resolved): Fix serial console terminal size issues
Jim Pingle
01:23 AM Bug #9569: Fix serial console terminal size issues
This looks like it works great. It tracks window size on login and changing window size on-the-fly. Welcome change. T... Chris Linstruth
07:29 AM Feature #9111 (Resolved): Add IPsec VTI interface MTU support
Jim Pingle
01:14 AM Feature #9111: Add IPsec VTI interface MTU support
Verified MTU settings are stored and applied properly. Loogs good. Chris Linstruth
07:23 AM Bug #7116: a floating 'match' rule on LAN does not put traffic from a broswer on a clientpc into a shaper queue
Im seeing this issue also on 2.4.4-RELEASE-p3 (amd64). I have several queues setup and sometimes traffic ends up in ... Adam Esslinger
12:28 AM pfSense Packages Bug #8811: in pfblockerng when change Rule Order generates duplicate all rules.
Its best to move to pfBlockerNG-devel which has this issue fixed plus many other improvements. These changes are not ... BBcan177 .
12:22 AM pfSense Packages Bug #9662: PfblockerNG do not update after pfsense reboot and wait for next cron task
If you are using RAMdisks, its not recommend for packages that store data in the /var folder as that folder is wiped ... BBcan177 .
12:20 AM pfSense Packages Bug #9676: AS lookup fails
The pkg uses the following service for ASN information:
https://api.bgpview.io/asn/8786/prefixes
Also BGP HE:
ht...
BBcan177 .

08/11/2019

04:59 PM Bug #9074 (Resolved): Alias URL lists only storing last-most list in config.
Jim Pingle
04:04 PM Bug #9074: Alias URL lists only storing last-most list in config.
Tested. Table populated with last URL contents under 2.4.4-p3 and both URL contents using latest snapshot. Looks good. Chris Linstruth
04:58 PM Feature #3792 (Resolved): Group name size limit too restrictive on Active Directory Users
Jim Pingle
03:32 PM Feature #3792: Group name size limit too restrictive on Active Directory Users
Tested. Group names longer that 16 characters are allowed only if the group type is Remote. Chris Linstruth
04:55 PM Bug #9357 (New): rc.newwanipv6 called regardless of REASON
Jim Pingle
08:18 AM Bug #9357: rc.newwanipv6 called regardless of REASON
Actually the script posted above is only used if "don't wait for RA" is set, otherwise the "old" script is still used... Flole Systems
04:54 PM Bug #9678 (Rejected): DHCP Relay (IPv4)
There is not enough information here for a valid bug report. Please start a thread on the forum and provide a lot mor... Jim Pingle
07:19 AM Bug #9678 (Rejected): DHCP Relay (IPv4)
DHCP Relay doesn't work.
Have DHCP server on my network, use pfSense to relay to that server, but clients don't ge...
Aaron Unpublished
07:30 AM Feature #9661: Increase the number of DHCP/DHCPv6 NTP server options to three (or more)
Yes, it is the role of ntpd, ntpdate, chronyd, etc. to make decisions on the quality of the clocks, and yes for most ... Paul Moore
04:49 AM Feature #9661: Increase the number of DHCP/DHCPv6 NTP server options to three (or more)
The "falsetickers" check is the role of ntpd / ntpdate which must be configured accordingly. however the dhcp client ... Manuel Piovan

08/10/2019

12:26 PM Feature #9661: Increase the number of DHCP/DHCPv6 NTP server options to three (or more)
I am referring to the number of NTP servers that pfSense send to DHCP clients as part of a DHCP exchange; I am not ta... Paul Moore
10:49 AM Feature #9661: Increase the number of DHCP/DHCPv6 NTP server options to three (or more)
you are talking about NTP servers but the client need only one address, you can configure the server to have as many ... Manuel Piovan

08/09/2019

09:26 PM Bug #9677 (New): Dashboard hangs when widget needs data from a remote host which is down
The pfsense dashboard will take a very long time to load (30sec to 1minute) when it contains a widget that needs data... M Jurgens
01:11 PM Bug #9466: DHCP (IPv4) relay mistakenly listening on upstream interface
See also #9669 for another problem that appears to be related, and which also appears to be fixed by this patch. Jim Pingle
01:10 PM Bug #9669 (Duplicate): dhcrelay stops working after certain time
That's great! I think it's fairly safe to say that this can be closed out as a duplicate of #9466 (different symptoms... Jim Pingle
01:08 PM Bug #9669: dhcrelay stops working after certain time
After more than 80 hours of service uptime for dhcrelay, I've restarted the Server and the address assignment process... Luki TJ

08/08/2019

06:35 AM pfSense Packages Bug #9676 (New): AS lookup fails
Using pfBlockerNG-devel 2.2.5_23
Trying to permit AS8786 gives no results (Other ASN works):...
Rolf Larsen
12:09 AM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
Justin J: I took your advice and posted on the forum and was promptly referred back here. Here's the link in case y... Tom Hebert

08/07/2019

07:28 PM Revision 81f19e11: ipsec.inc: Safety belt in case package array is missing.
Jim Pingle
02:55 PM pfSense Packages Bug #9675 (Resolved): ACME package "domain alias mode" is ignored
I was already in there fixing something else which, as it turns out, had a similar root cause, so it all worked out.
...
Jim Pingle
02:50 PM pfSense Packages Bug #9675: ACME package "domain alias mode" is ignored
Jim Pingle wrote:
> This should be fixed in ACME pkg version 0.6.2, which is building now.
That was quick! Update...
Jonathan Grande
01:21 PM pfSense Packages Bug #9675 (Feedback): ACME package "domain alias mode" is ignored
This should be fixed in ACME pkg version 0.6.2, which is building now. Jim Pingle
11:56 AM pfSense Packages Bug #9675 (Resolved): ACME package "domain alias mode" is ignored
The domain alias mode check box seems to have no affect.
Expected result: --domain-alias added to to the acme.sh c...
Jonathan Grande
02:49 PM Revision ecfd1ddc: Fixup format of XMLRPC auth error to match GUI auth error.
(cherry picked from commit 6e0d47510ee553f5219c08c097c32d377985822b) Jim Pingle
02:48 PM Revision 6e0d4751: Fixup format of XMLRPC auth error to match GUI auth error.
Jim Pingle
08:29 AM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
That sounds like it might be something else Tom. Check your output from the CLI with: pfctl -T show -t ALIASNAME
If...
Justin J

08/06/2019

05:06 PM pfSense Packages Feature #7449: feature request for openvpn-client-export package, add the support for openvpn up and down script, for mapping network drive
Pippin MMD wrote:
> This seems like not so good idea to me.
> One could setup a "Free VPN service" and execute scri...
MIchael K
04:44 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
Most of you are more experienced at this than me so please be tolerant if this is a dumb question.
I added a Fir...
Tom Hebert
04:10 AM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
I second Justins message / question. pfSense is completely unusable after 2.4.4 initial release. With filterdns not w... Robert Gijsen
03:52 PM pfSense Packages Bug #9665 (Feedback): acme.sh deleting A record for domain along with TXT record for _acme-challenge
This should be fixed in ACME pkg version 0.6 which will be up as soon as it builds. Jim Pingle
10:37 AM Bug #9674 (Resolved): hidden OpenVPN settings are validated and written to file
I had two instances where configurations not visible on the OpenVPN server creation window were affecting saving the ... Wayne Marsh
07:12 AM pfSense Packages Feature #7794 (Resolved): FRR pkg pfsense no metric-type option in OSPF redistribute section of web-interface
Jim Pingle
02:39 AM pfSense Packages Feature #7794: FRR pkg pfsense no metric-type option in OSPF redistribute section of web-interface
Tried latest stable 2.4.4-p3 with 6.0.2, everything is fine, I can assign metric type on any types of redistributed r... Constantine Kormashev
07:12 AM pfSense Packages Feature #7792 (Resolved): FRR pkg pfsense can not wok as ABR with stub areas (no stub area bit)
Jim Pingle
04:15 AM pfSense Packages Feature #7792: FRR pkg pfsense can not wok as ABR with stub areas (no stub area bit)
Tried on latest stable 2.4.4-p3 with 6.0.2, it works fine, stub areas are handled by cisco router without issue. Constantine Kormashev
05:10 AM Bug #9669: dhcrelay stops working after certain time
Thanks, I'll try it out and report back in a few of days. Luki TJ
02:06 AM pfSense Packages Bug #8811: in pfblockerng when change Rule Order generates duplicate all rules.
I experienced this bug in an even worse manner. It duplicated all rules until my pfSense installation crashed with an... Jens Rauch

08/05/2019

10:39 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
Also experiencing this issue on 2.4.4-p2 and now 2.4.4-p3. If FQDNs are remove the table updates correctly. Due to ... Justin J
04:39 PM Revision a264f870: Instead of restarting pkgs, add an IPsec reload hook they can use instead. Fixes #9668
Jim Pingle
04:25 PM pfSense Docs Correction #9673 (Closed): Feedback on Installing and Upgrading — Download Installation Media
*Page:* https://docs.netgate.com/pfsense/en/latest/book/install/download-installer-image.html
*Feedback:*
Custo...
Doug McIntire
04:01 PM pfSense Docs Correction #9672 (Closed): Feedback on Backup and Recovery — Using the AutoConfigBackup Package
*Page:* https://docs.netgate.com/pfsense/en/latest/backup/autoconfigbackup.html
*Feedback:*
Page needs to be up...
Doug McIntire
03:43 PM pfSense Docs Correction #9671 (Closed): Feedback on Hardware — Hardware Selection
*Page:* https://docs.netgate.com/pfsense/en/latest/hardware/selection.html
*Feedback:*
"The SG-1000 firewall is...
Doug McIntire
03:33 PM Revision 15701e03: Restart packages at the end of rc.newipsecdns. Fixes #9668
Not an ideal solution but it does ensure that FRR routes function after
an IPsec event.
Jim Pingle
03:31 PM pfSense Docs Correction #9670 (Closed): Feedback on Backup and Recovery
*Page:* https://docs.netgate.com/pfsense/en/latest/backup/index.html
*Feedback:*
Reference to pfSense Gold Subs...
Doug McIntire
12:29 PM Bug #9669: dhcrelay stops working after certain time
commit:f427d68dbca5ed9941b3bc01be1c4d81417c134f is the one for RELENG_2_4_4 Jim Pingle
12:07 PM Bug #9669: dhcrelay stops working after certain time
Thank you for the quick response.
I can try out the Patch, but the issue is to minor to switch to a development re...
Luki TJ
07:16 AM Bug #9669 (Feedback): dhcrelay stops working after certain time
Can you test this, at least temporarily, on a 2.5.0 snapshot? Changes were made for #9466 which might affect this beh... Jim Pingle
06:34 AM Bug #9669: dhcrelay stops working after certain time
Edit:
Found some other reports on the Forum:
https://forum.netgate.com/topic/136135/pfsense-2-4-4-dhcp-relay-i...
Luki TJ
06:19 AM Bug #9669 (Duplicate): dhcrelay stops working after certain time
dhcrelay service stops working after a few days runtime of the process.
I have one host connected to igb5.8 (opt1) w...
Luki TJ
11:53 AM Bug #9668: Running /etc/rc.newipsecdns breaks FRR BGP on VTI interfaces
Second solution is better but still not ideal. Rather than restarting all packages, when IPsec is reloaded via rc.new... Jim Pingle
10:40 AM Bug #9668 (Feedback): Running /etc/rc.newipsecdns breaks FRR BGP on VTI interfaces
Applied in changeset commit:15701e03e36051907a23ddbe5ab04f42c94c0944. Jim Pingle
10:35 AM Bug #9668: Running /etc/rc.newipsecdns breaks FRR BGP on VTI interfaces
Not an FRR issue. The IPsec interface goes away and comes back, and it never latches back on. FRR needs to be restart... Jim Pingle
03:36 AM Bug #9668: Running /etc/rc.newipsecdns breaks FRR BGP on VTI interfaces
Confirmed same behavior on latest 2.5.0 snapshots. Chris Linstruth
03:03 AM Bug #9668 (Resolved): Running /etc/rc.newipsecdns breaks FRR BGP on VTI interfaces
Running /etc/rc.newipsecdns breaks FRR BGP on VTI interfaces
Create a simple FRR BGP session across an IPsec VTI
...
Chris Linstruth
07:19 AM Bug #9666 (Rejected): RADIUS Accounting Failed
There is not enough information here for a valid bug report. This site is not for support or diagnostic discussion.
...
Jim Pingle
12:28 AM Bug #9666 (Rejected): RADIUS Accounting Failed
Radius Accounting failure after update. No problem with previous version (2.4.4-P2) Sher Louie Sioteco
05:49 AM Bug #9634: rc.newwanipv6 is called although dhcp6c should discard Request messages
Seems to work just fine.
(I had to disable the periodic reset of the PPPoE-(WAN-)Interface for the test to work, bec...
Karl Klempner
03:00 AM Bug #9667 (Duplicate): Dynamic DNS is not updated when used with a Multi WAN gateway group
Hi.
I have recently upgraded my pfSense installation from a custom Supermicro server (old 2.1 version) to a NetGat...
Damien Gombault

08/04/2019

04:00 PM pfSense Packages Bug #9665 (Resolved): acme.sh deleting A record for domain along with TXT record for _acme-challenge
I was trying to set up a LetsEncrypt certificate for my domain using Linode's v4 DNS API. I was able to generate the ... Ronnie Thomas

08/03/2019

10:00 AM Bug #9664 (New): DynDNS and Dual-wan problem with CloudFlare (works with No-Ip)
I have a simple setup with dual-wan links and dynamic IPs. I use a No-ip Round Robin setup like this... F. D.Castel
06:26 AM Bug #9663 (Resolved): panic on boot when IPv6 option "Do not wait for a RA" is enabled
When pfsense reboots, it hangs in a boot loop because of a kernel panic.
It is reproducable that it occurs when the...
Michael Geiger

08/02/2019

04:24 AM Feature #1682: second MAC address for one IP address
Just tested this on the most recent release (2.4.4-RELEASE-p3) and it is not a problem anymore to have the same IP an... Adrian Zaugg
03:02 AM pfSense Packages Bug #9662 (New): PfblockerNG do not update after pfsense reboot and wait for next cron task
After rebooting pfsense, pfblockerNG do not launch cron process to update and wait for next cron time.
While next ...
Laurent BONNIN

08/01/2019

10:18 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
Netgate SG-4860 running 2.4.4-RELEASE-p3 (amd64). At least twice I've experienced issues, I assume involving filterd... Art Manion
06:44 AM Feature #9661 (Resolved): Increase the number of DHCP/DHCPv6 NTP server options to three (or more)
It is considered a general best practice to use at least three NTP servers to help identify "falsetickers" (bad clock... Paul Moore

07/31/2019

08:16 AM pfSense Packages Bug #9619: FRR - Prefix Lists
thank you for your willingness to find out what i could have meant,
but really my problem was:
i really could not u...
Jarek Nowak
07:13 AM pfSense Packages Bug #9619: FRR - Prefix Lists
Jarek Nowak wrote:
> Also i did not ask for you validating my rules, if so your answer would be wrong because allowi...
Jim Pingle
02:12 AM pfSense Packages Bug #9619: FRR - Prefix Lists
Jim Pingle wrote:
> The first rule is wrong because a prefix list must contain prefixes, thus it should be @0.0.0.0/...
Jarek Nowak
07:16 AM Bug #9659 (Not a Bug): Failed to remount in single user mode when trying to reset password
You are using ZFS, those instructions are for UFS. You might have some other unrelated issue here, but this site is n... Jim Pingle
02:36 AM Bug #9659 (Not a Bug): Failed to remount in single user mode when trying to reset password
We were using pfSense CE 2.4.4. Since we accidentally
forgot our console admin password, we followed the instruction...
Jarry Shaw
05:50 AM Bug #9660 (Resolved): Syslogd keeps using old IP address after interface IP address change
- Have syslog configured to send log messages using a particular LAN interface
- Check Diagnostics > Sockets, you se...
Anonymous
05:19 AM Bug #9658: Gateway monitor IPs are being put into the routing table
In scenario 1, the firewall is sending traffic out to interfaces it's not supposed to do.
In scenario 2, the monit...
Anonymous

07/30/2019

07:05 PM pfSense Packages Bug #9655: NUT missing from netgate UI
Wow ... yes it is; thank you! ;) Richard Davis
07:01 AM pfSense Packages Bug #9655: NUT missing from netgate UI
Its in your Screenshot as "UPS". Flole Systems
12:58 PM Bug #9561: PPPoe 6RD broken in 2.5
Created a pull request to FreeBSD-src to apply the 6RD changes to 2.5 Ronald Schellberg
12:56 PM Bug #9649: IPv6 6RD Tunnel
Created a pull request to FreeBSD-src to apply the 6RD changes to 2.5 Ronald Schellberg
12:15 PM Bug #9658 (Not a Bug): Gateway monitor IPs are being put into the routing table
This is by design. It has to be that way, or it can't be sure that the monitor address will ping via the correct inte... Jim Pingle
11:17 AM Bug #9658 (Not a Bug): Gateway monitor IPs are being put into the routing table
As the subject says, fpsense puts the IP addresses that are configured as monitor IPs for gateways in the routing tab... Anonymous
11:47 AM Feature #9393: Improved support for USB interfaces that may not always be present
See: https://forum.netgate.com/topic/141347/option-to-hot-plug-some-interfaces Steve Wheeler
10:03 AM pfSense Packages Bug #9657 (Feedback): STunnel fails to generate an rc script
Should hopefully be fixed in pkg version 5.50. I removed one way it could have failed unexpectedly, potentially fixed... Jim Pingle
08:00 AM pfSense Packages Bug #9657 (Resolved): STunnel fails to generate an rc script
In some circumstances the STunnel package fails to generate a default certificate as part on it's install script and ... Steve Wheeler
07:21 AM Bug #9656 (Rejected): DHCPv6 Leases Allowed Memory Size Exhausted
There isn't enough information here for a proper bug report.
For assistance in solving problems, please post on th...
Jim Pingle
06:46 AM Bug #9656 (Rejected): DHCPv6 Leases Allowed Memory Size Exhausted
Hi, I have encountered a bug with the DHCPv6 Leases page under Status in pfSense.
The page crashes after a while of ...
Obel Net
07:16 AM Bug #9357 (Resolved): rc.newwanipv6 called regardless of REASON
Jim Pingle
06:52 AM Bug #9357: rc.newwanipv6 called regardless of REASON
Hi Karl,
thanks for pointing this out! In that case this is fixed in 2.4.4-p3 and it was simply not marked fixed h...
Flole Systems
06:39 AM Bug #9357: rc.newwanipv6 called regardless of REASON
Version 2.4.4-p3 has the following dhcp6c_wan_script.sh which should already ignore the RENEW reason:... Karl Klempner
06:47 AM Bug #9634: rc.newwanipv6 is called although dhcp6c should discard Request messages
I am now testing the following, modified /var/etc/dhcp6c_wan_script.sh:... Karl Klempner

07/29/2019

06:50 PM pfSense Packages Bug #9655: NUT missing from netgate UI
I've tried uninstalling, then installing, and "reinstalling" without success:
*Reinstallation log:*...
Richard Davis
07:17 AM pfSense Packages Bug #9655 (Not a Bug): NUT missing from netgate UI
You just need to reinstall the package. Somehow it isn't fully installed, and there isn't enough information here to ... Jim Pingle
05:50 PM Revision 38809d47: Fix copyright message years to reflect BSDP -> ESF -> Netgate
Renato Botelho
05:44 PM Bug #9362: rc.dyndns.update: Cloudflare DDNS with proxy enabled doesn't work at all
Nathan Hand wrote:
> Underlying problem is /etc/inc/dyndns.class line 799. The value of dnsProxied is passed directl...
Arian K.
11:58 AM Revision f83416bd: Normalize some copyright messages
Renato Botelho
10:57 AM Bug #9649: IPv6 6RD Tunnel
Ronald Schellberg wrote:
> Aaron Unpublished wrote:
> > IPv6 6rd doesn't work on any 2.5.X versions at the moment. ...
Aaron Unpublished

07/28/2019

07:37 PM Bug #9362: rc.dyndns.update: Cloudflare DDNS with proxy enabled doesn't work at all
Underlying problem is /etc/inc/dyndns.class line 799. The value of dnsProxied is passed directly to Cloudflare.
<p...
Nathan Hand
03:37 PM Bug #9649: IPv6 6RD Tunnel
Aaron Unpublished wrote:
> IPv6 6rd doesn't work on any 2.5.X versions at the moment.
>
> Have cable internet. ...
Ronald Schellberg
03:20 PM pfSense Packages Bug #9655 (Not a Bug): NUT missing from netgate UI
After installing the nut package from the package manager on a new netgate system with the built-in theme, the NUT se... Richard Davis
02:53 PM Bug #9654 (New): After reboot, the DNS resolver must be restarted before it will advertise the ipv6 DNS address of the router.
When pfsense ipv6 is configured with DHCPv6 disabled and RA in "Unmanaged" mode, then after reboot, until the resolve... Rick Coats
02:20 PM Bug #7209: Something is seriously wrong with firewall aliases
I just hit this bug today on a fully updated 2.4.4-p3 firewall.
There was an IP Alias named "h_whitelist" containi...
→ luckman212
09:36 AM Feature #9653 (Rejected): Assign Alias from MAC address
No, aliases are for pf and it does not support filtering by MAC address. Jim Pingle
04:14 AM Feature #9653: Assign Alias from MAC address
Also, allows me to to assign ipv6 address alias when I have dynamic ipv6 gateway Dean Attewell
04:11 AM Feature #9653 (Rejected): Assign Alias from MAC address
Can you change Alias assignment to use MAC addresses as well as IP addresses?
So I can have a Xbox which dynamically...
Dean Attewell

07/27/2019

05:07 PM pfSense Packages Bug #9652 (Resolved): Squid Proxy Server /var/squid/lib/ssl_db directory not found in squid.inc
When using the Squid Proxy Server package and Enabling SSL filtering in pfSense 2.5.0, I create an internal-CA and as... Brett Vernor
11:37 AM pfSense Docs Correction #9651: Feedback on Services — DHCP — Configuring the DHCPv6 Server
Ugh.
It looks like the range here should be changed to FC07:1010:1010:*FF00*:: to FC07:1010:1010:FFF0:: (16 /60s) ...
Chris Linstruth
11:35 AM pfSense Docs Correction #9651 (Resolved): Feedback on Services — DHCP — Configuring the DHCPv6 Server
*Page:* https://docs.netgate.com/pfsense/en/latest/dhcp/dhcpv6-server.html
*Feedback:*
For example, if FC07:101...
Chris Linstruth
07:14 AM Bug #9650 (New): IPv6 connection drops (ir-)regular on Kabelvodafone (German cable ISP)...
*Background information*
Kabel Vodafone is the successor of Kabeldeutschland, among other services they offer Busine...
Ingo-Stefan Schilling
06:44 AM Bug #9649 (Resolved): IPv6 6RD Tunnel
IPv6 6rd doesn't work on any 2.5.X versions at the moment.
Have cable internet. Upgraded to the 2.5 and it brok...
Aaron Unpublished

07/25/2019

08:03 PM Revision 57b2f317: Only redirects the user to the default page if no specific page page was set in the querystring
bechaire
04:44 PM Bug #9541 (Resolved): Non-admin user with admin rights is given the wrong URL for the user manager
On 20190725-0909, unable to reproduce the bad behavior. Anonymous
04:37 PM Bug #9611 (Resolved): PHP error on fresh 2.5.0 install or after factory reset
Anonymous
04:37 PM Bug #9611: PHP error on fresh 2.5.0 install or after factory reset
On 20190725-0909, the error is no longer present, new install and resets both work as expected. Anonymous
04:35 PM Feature #9620 (Resolved): User privilege to manage integrated switch
On 20190725-0909, the Switch options are present and work as expected. Anonymous
10:04 AM pfSense Packages Feature #9648: Multiple node Sync HAProxy configuration to backup CARP members via XMLRPC.
XMLRPC is not designed to be used with more than one node. It does, on occasion, but only by accident. Jim Pingle
10:00 AM pfSense Packages Feature #9648 (New): Multiple node Sync HAProxy configuration to backup CARP members via XMLRPC.
We have a cluster of 3x PFSense Firewalls running in 3 AZs on AWS.
FW-A (AZ-A) is configured to sync to FW-B (AZ-B...
Frikkie Botha
04:37 AM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
I think I have a similar problem.
My inbound rule did not work with an FQDN in the Alias. (Whitelist for source addr...
Peter van der Kleij

07/24/2019

09:47 AM Bug #9646: OpenSSL 1.1.1 does not list engines for AES-NI or BSD crypto
I can confirm this, but it is not specific to OpenVPN.
OpenSSL 1.1.1 doesn't list AES-NI or the BSD crypto dev, ev...
Jim Pingle
07:25 AM Bug #9646 (Resolved): OpenSSL 1.1.1 does not list engines for AES-NI or BSD crypto
Cannot select BSD Crypto Device under OPENVPN clients - Hardware Crypto, it only has No Hardware Crypto Acceleration. Vance Emerson
08:13 AM Bug #9647 (Resolved): hn0: driver does not support altq
As subject says, hn0 on 2.5.0 does not support ALTQ.
You get error after traffic shaper wizard starts to reload rule...
Greg M
08:13 AM Bug #9643: Limiters do not function properly on 2.5 snapshots
Hmmm OK, I have Hyper-V, 2.5.0 and pppoe.
But weird is, that on when applied on IN direction on LAN it works ok.
Greg M
07:09 AM Bug #9643: Limiters do not function properly on 2.5 snapshots
The two cannot be related. ALTQ is not used for limiters.
I have also seen a similar situation on 2.5 where limite...
Jim Pingle
01:20 AM Bug #9643: Limiters do not function properly on 2.5 snapshots
Hi again.
I restored config on 2.4.4-p3 and this are working just fine there.
I believe this on is related to h...
Greg M
07:10 AM Bug #8954: hn0: driver does not support altq
Please open a new issue with specific error messages and reference this one there. Jim Pingle
01:21 AM Bug #8954: hn0: driver does not support altq
Restored to 2.4.4-p3 and output is: hw.hn.use_if_start: 1
Clean install 2.5.0 snapshot: hw.hn.use_if_start: 0
Greg M

07/23/2019

03:39 PM Revision 84a5e2db: Revert "Disable snort3 on armv7. It's broken"
This reverts commit 987377b0c968f588997d111d5d4bc88293550d3b. Renato Botelho
01:33 PM Revision 9c763eb4: Make sure TSC is disabled on armv7
Renato Botelho
09:09 AM Bug #9645: "Bypass firewall rules for traffic on the same interface" does not work as expected
Perhaps the order or the length of the filters?
Or a race condition (https://lists.freebsd.org/pipermail/freebsd-net...
Grischa Zengel
08:38 AM Bug #9645 (Not a Bug): "Bypass firewall rules for traffic on the same interface" does not work as expected
Your manual rule is functionally identical to the automatic rule. Something else must have changed.
There is no bu...
Jim Pingle
07:19 AM Bug #8954: hn0: driver does not support altq
Hello!
This one is back in 2.5.0 snapshots.
Greg M

07/22/2019

08:46 PM Bug #9645: "Bypass firewall rules for traffic on the same interface" does not work as expected
Here are my rules for this interface:... Grischa Zengel
08:38 PM Bug #9645 (Not a Bug): "Bypass firewall rules for traffic on the same interface" does not work as expected
I have to use asymmetric routing. P1 (default gateway) routes to P2 on the same subnet. ICMP redirect doesn't work be... Grischa Zengel
07:04 PM Bug #9450: Multiwan gateway group fail-over not working as expected (possible race condition)
Adding these log snippets. They are groups of dpinger gateway logs followed by the system logs for the corresponding ... Chris Linstruth
04:09 PM Bug #9577: radvd send_ra_forall failed on interface / can't join ipv6-allrouters
Greg M wrote:
> Now I don`t have above any more but I have this (but everything is working just fine):
>
IPv6 fo...
Manuel Piovan
07:47 AM Bug #9577: radvd send_ra_forall failed on interface / can't join ipv6-allrouters
Now I don`t have above any more but I have this (but everything is working just fine):
Jul 22 14:44:54 radvd 406...
Greg M
02:09 PM pfSense Docs Correction #9644 (Closed): Feedback on Network Address Translation — Accessing Port Forwards from Local Networks
*Page:* https://docs.netgate.com/pfsense/en/latest/nat/accessing-port-forwards-from-local-networks.html
*Feedback:...
Steve Wheeler
10:05 AM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
Rudolf Mayerhofer wrote:
> As a follow up: With 30 seconds resolve interval things are still working fine one month ...
Eduard Rozenberg
07:17 AM Bug #9643 (Closed): Limiters do not function properly on 2.5 snapshots
Hi all!
Discussion here: https://forum.netgate.com/topic/145091/quick-question-about-limiters
I think there is ...
Greg M

07/21/2019

03:53 PM Feature #6626: Support for IPv6 firewall entries with dynamic delegated prefix and static host address
A global variable with the current delegated IPv6 prefix in CIDR form, which could be used in firewall aliases would ... Michael Smith
11:40 AM Feature #9642: Add DDNS support for dynv6.com
Correction from above:
To update an A record use the following url:
https://ipv4.dynv6.com/api/update?hostname=yo...
Isaac McDonald
11:33 AM Feature #9642 (Resolved): Add DDNS support for dynv6.com
Dynv6.com (https://dynv6.com/) provides dynamic DNS for A and AAAA records free of charge. The API is documented here... Isaac McDonald
11:20 AM Bug #9641: Dynamic DNS cannot update AAAA records on 6rd tunnel interfaces bound to PPPoE interfaces
I inadvertently opened this ticket while I was still in the process of creating it. Please disregard the original sub... Isaac McDonald
11:15 AM Bug #9641 (Resolved): Dynamic DNS cannot update AAAA records on 6rd tunnel interfaces bound to PPPoE interfaces
I get the following error when trying to update the AAAA record for a 6rd tunnel interface:
_/services_dyndns_edit...
Isaac McDonald

07/19/2019

01:38 PM pfSense Packages Bug #9640 (Feedback): FRR redistribution route maps not functional
Fix is in FRR pkg version 0.6.2, which will be available shortly. Jim Pingle
01:34 PM pfSense Packages Bug #9640 (Resolved): FRR redistribution route maps not functional
Setting a route map on the redistribution options does not work.
In vtysh, doing a 'show' on the route map says OS...
Jim Pingle
09:47 AM Bug #9295: IPv6 PD does not work with PPPOE (Server & Client)
Seems like IPv6 is not on the priority list of the currently active devs, or nobody fully understands it. There are q... Flole Systems
07:40 AM Feature #4881: Allow NPt to use dynamic IPv6 networks
Any update here? We need dynamic Prefix support for IPv6 Multi WAN. Car F

07/18/2019

10:47 PM Bug #8235: The browser must support cookies to login
I have the same problem under different circumstances. I bought a new firewall to upgrade hardware. Pfsense web ui wo... Bob Frank
08:49 PM Feature #6414: SSHD listening on multiple ports
You can port forward now in a handful of clicks, it's simple and not at all complicated. Listening on multiple ports ... Jim Pingle
08:47 PM Feature #6414: SSHD listening on multiple ports
Jim Pingle wrote:
> Never expose SSH to WAN. Security by obscurity is not obscurity.
The purpose of this is to we...
Ben L
08:29 PM Feature #6414 (Rejected): SSHD listening on multiple ports
Never expose SSH to WAN. Security by obscurity is not obscurity.
And if you use key-only auth, the rest doesn't ma...
Jim Pingle
08:04 PM Feature #6414: SSHD listening on multiple ports
One use case for this is exposing ssh on the WAN on a non-standard high port so as to minimise exposure to random dri... Ben L
12:59 PM Feature #9639 (Resolved): Cloudflare DDNS "API Token"
Request to add support for new Cloudflare API Token to allow for managed access and permissions for DDNS updates.
> ...
theodore adams
12:06 PM Revision 987377b0: Disable snort3 on armv7. It's broken
Renato Botelho
11:57 AM Bug #9634: rc.newwanipv6 is called although dhcp6c should discard Request messages
The entire script is broken, even RENEW should be ignored and just REBIND should actually matter. See #9357 for a pat... Flole Systems
09:18 AM pfSense Docs Correction #9638 (Resolved): Feedback on High Availability — Configuring High Availability
*Page:* https://docs.netgate.com/pfsense/en/latest/highavailability/configuring-high-availability.html
*Feedback:*...
Danilo Zrenjanin
09:11 AM Bug #9295: IPv6 PD does not work with PPPOE (Server & Client)
Sadly nobody is taking care of handling this bug... My ticket is 6 month old now. Dirk Steingäßer
08:49 AM Bug #9295: IPv6 PD does not work with PPPOE (Server & Client)
Do I get this bug right?
If my upstream WAN connection is PPPoE and I try to delegate prefixes via DHCPv6 it won't w...
Pim Pish
08:42 AM pfSense Docs Correction #9637 (Resolved): Feedback on High Availability — Example Redundant Configuration
*Page:* https://docs.netgate.com/pfsense/en/latest/book/highavailability/example-redundant-configuration.html
*Fee...
Danilo Zrenjanin
07:33 AM Bug #9636 (Not a Bug): uninstall packages
That sounds like a problem with your config or environment. I can't reproduce it here.
For assistance in solving p...
Jim Pingle
07:23 AM Bug #9636 (Not a Bug): uninstall packages
if i try to uninstall any package
Package Removal
Please wait while the update system initializes
nothing else...
Manuel Piovan
03:35 AM Feature #6240: vxlan driver
+1 Max Green

07/17/2019

08:20 PM Bug #9561: PPPoe 6RD broken in 2.5
Doesn't appear that "pfSense patch stf_6rd.diff", ticket 7272 (commit cb59ac304d30d5009537d7de0429792fb33d3db0 which ... Ronald Schellberg
06:22 PM pfSense Packages Bug #9635 (Resolved): lldpd (and probably ladvd) doesn't work on units with an integrated switch
It appears the GUI configuration doesn't probably figure out what interface is selected. For example,
No matter wh...
Brendon Baumgartner

07/16/2019

04:10 PM pfSense Packages Bug #5168: squid doesn't function during/after HA failover
Zeev Zalessky wrote:
> Hello,
>
> any updates with this issue?
> i have 200 vlans on my firewall and adding 200...
Adam Gibson
06:45 AM pfSense Packages Feature #9521: Upgrade to HAProxy 1.9
haproxy 2.0 is available in ports 2019Q3 Torben Hørup

07/15/2019

03:59 PM Bug #9634 (Resolved): rc.newwanipv6 is called although dhcp6c should discard Request messages
pfsense sends DHCPv6 Request messsages to ff02::1:2 on its WAN interface at an interval of about 7 seconds. As this i... Karl Klempner
01:52 PM Feature #9633 (New): PPPoE/L2TP Server Status Page
MPD includes a built-in web server that can be used to poll status information. There is also a telnet console, but t... Jim Pingle
06:25 AM Bug #9632: DynDNS not updating IP address for DNSExit
2.4.4-RELEASE-p3 (amd64) built on Wed May 15 18:53:44 EDT 2019 FreeBSD 11.2-RELEASE-p10
Jay Murphy
06:22 AM Bug #9632 (Resolved): DynDNS not updating IP address for DNSExit
When using the DNSExit dynamic DNS service, the IP address changes and the "Save & Force Update" button is clicked, t... Jay Murphy
 

Also available in: Atom