Project

General

Profile

Activity

From 05/04/2020 to 06/02/2020

06/02/2020

08:25 PM Revision dba74e12: Fix Google Cloud Platform spelling
(cherry picked from commit 8a162959a3107f607722024356f788f610ac7fdf) Steve Beaver
08:25 PM Revision 107a8042: Deect Azure and differentiate from Hyper-V by looking at hte bios version
(cherry picked from commit 1279a7ac6890386a4224b6f7300e47cadfd6dbe7) Steve Beaver
08:25 PM Revision 123ac7a8: Fixed #10621. Identify Amazon AWS instances without breaking Hyper-V
(cherry picked from commit 6f552d6a5294bda42b5b205351c972892e9c135e) Steve Beaver
08:25 PM Revision 242f8d8d: Fixed #10621. Identify Amazon AWS instances
(cherry picked from commit f3df1d3eaa564da1d1b2c535a59ec269a9edab0f) Steve Beaver
07:34 PM Revision 8a162959: Fix Google Cloud Platform spelling
Steve Beaver
07:31 PM Revision 1279a7ac: Deect Azure and differentiate from Hyper-V by looking at hte bios version
Steve Beaver
06:31 PM Bug #10624 (Resolved): Memory leak in Unbound with Python module and DHCP lease registration active
Issue reported and diagnosed on forums here: Was able to see evidence of this on SG-1100 and SG-3100.
https://for...
Adrien Carlyle
06:04 PM Revision 6f552d6a: Fixed #10621. Identify Amazon AWS instances without breaking Hyper-V
Steve Beaver
05:56 PM Revision f3df1d3e: Fixed #10621. Identify Amazon AWS instances
Steve Beaver
02:55 PM Bug #10623: Wrong Route configured for GIF interface on VLAN on LAGG
To add to this: I did select the WAN Interface in the GIF Configuration, so I would expect it to use my selected inte... Flole Systems
02:53 PM Bug #10623 (Resolved): Wrong Route configured for GIF interface on VLAN on LAGG
I am using a VLAN on a LAGG for WAN connectivity. When I configure a GIF, there is a static route forcing traffic to ... Flole Systems
01:05 PM Feature #10621 (Feedback): Update system.inc/system_identify_specific_platform() update to accommodate AWS, Azure and GCP
Applied in changeset commit:f3df1d3eaa564da1d1b2c535a59ec269a9edab0f. Anonymous
12:11 PM Feature #10621 (Resolved): Update system.inc/system_identify_specific_platform() update to accommodate AWS, Azure and GCP
The function system_identify_specific_platform() identifies the platform we are running on, but it needs to be update... Anonymous
10:25 AM Bug #10607 (Resolved): Remote syslog for "General Authentication Events" using wrong selectors
Jim Pingle
10:25 AM Bug #10607: Remote syslog for "General Authentication Events" using wrong selectors
Makes complete sense, thanks for clarifying. And appreciate all the help! Russell Morris
10:21 AM Bug #10607: Remote syslog for "General Authentication Events" using wrong selectors
auth and authpriv are facilities, not process names, so that would not work. It's correct as it is. That section isn'... Jim Pingle
09:57 AM Bug #10607: Remote syslog for "General Authentication Events" using wrong selectors
Hi,
2.5.0 got updated today (or late yesterday) ... :-). So I installed, and it works - thanks! Just one minor thi...
Russell Morris
09:57 AM Bug #8686: IPsec VTI: Assigned interface firewall rules are never parsed
That is certainly worth testing but we've had problems flipping that in the past (See #2993, #2636, and several forum... Jim Pingle
12:55 AM Bug #8686: IPsec VTI: Assigned interface firewall rules are never parsed
Is this related:
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=232522
filtertunnel sysctls seem to be 0 in pf...
Ari Suutari
09:32 AM Bug #9476: pfSense 2.4.x sending ARP replies with non-CARP source MAC address
This is a problem for cable modem setups in particular. Many providers are willing to issue multiple IPs to allow CA... Marc H

06/01/2020

09:15 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
Gavin Stewart wrote:
> This is confirmed.
>
> I am able to replicate the failure in a test VM, using my instructi...
Gavin Stewart
08:18 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
Donn Lasher wrote:
> Same problem here - 2.4.5-RELEASE (amd64)
This is confirmed.
I am able to replicate the f...
Gavin Stewart
08:43 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
I disabled IPv6 from the WAN interface as I don't use it anyways.
Now I get this in the logs:
Seems possibly r...
Marc J
03:45 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
I don't have two identical consoles with identical online games to test, but just testing with a upnp client I see th... Jim Pingle
02:54 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
According to one of our other developers, the @(name)@ syntax is resolved by pfctl so it isn't in the API. It uses @i... Jim Pingle
02:22 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
I don't know how that might be expressed in the ioctl/API, unfortunately. I've posed the question to some of our othe... Jim Pingle
04:38 PM Revision c7df496c: Adjusted freedns v2 API var name to be more readable
Ricky Burgin
02:44 PM Revision f9981994: Include platform name in update check JSON
Steve Beaver
02:33 PM Revision 12a3708e: Include platform name in update check JSON
Steve Beaver
02:00 PM Revision e07f6851: NAT Reflection timeout set fix. Issue #10591
(cherry picked from commit b8d9968cf44bc171c0b3eb020a72589d6c85d94e) Viktor Gurov
02:00 PM Revision bfa5b809: Merge pull request #4333 from vktg/reflectiontimeoutfix
Renato Botelho
01:51 PM pfSense Packages Feature #10618 (Pull Request Review): Set sysDescr the same as bsnmpd unless overriden with net-snmp
Jim Pingle
11:59 AM pfSense Packages Feature #10618 (Resolved): Set sysDescr the same as bsnmpd unless overriden with net-snmp
The current behaviour breaks detection with SNMP NMS' where it will show as a generic FreeBSD box.
https://github....
Ben Hughes
01:49 PM pfSense Packages Feature #10619 (Pull Request Review): Various FRR enhancements
Jim Pingle
12:01 PM pfSense Packages Feature #10619: Various FRR enhancements
Github PR: https://github.com/pfsense/FreeBSD-ports/pull/869 Ben Hughes
12:00 PM pfSense Packages Feature #10619 (Resolved): Various FRR enhancements
Started off tidying up the BFD integrating in #835 and found a few other things to tidy up.
1. Extend #10441 to be...
Ben Hughes
01:41 PM pfSense Docs Correction #10593 (Closed): Feedback on Third Party Software and pfSense — Configure BIND as an RFC 2136 Dynamic DNS Server
Thanks! This has been merged. Jared Dillard
11:38 AM Revision 49d54787: Add support for freeDNS DynDNS v2 API refs #10617
Ricky Burgin
10:02 AM Bug #10613 (Pull Request Review): cleanup status_queues.php code
Jim Pingle
10:01 AM pfSense Packages Bug #10146 (Pull Request Review): squid4 obsolete options
Jim Pingle
09:58 AM pfSense Packages Bug #5168 (Pull Request Review): squid doesn't function during/after HA failover
Jim Pingle
09:57 AM Bug #9641 (Pull Request Review): Dynamic DNS cannot update AAAA records on 6rd tunnel interfaces bound to PPPoE interfaces
Jim Pingle
09:01 AM Bug #10591 (Feedback): Cannot set a value for NAT Reflection timeout
PR has been merged. Thanks! Renato Botelho
06:40 AM Feature #10617: freeDNS Dynamic DNS API v2 Support
Github PR URL: https://github.com/pfsense/pfsense/pull/4344 Ricky Burgin
06:31 AM Feature #10617 (Resolved): freeDNS Dynamic DNS API v2 Support
This adds support for freeDNS (afraid.org)'s DynDNS service's more recent API version, which hosts a IPv6 only endpoi... Ricky Burgin
06:31 AM Bug #10614: Unable to update packages due to missing/invalid certs
hi everyone,
first off all you need open this file /usr/local/share/cert/ca-root-nss.txt
and you need the delet...
sezer h
06:30 AM Bug #10616: Out of date CA root store - FreeDNS (DynDNS) not working anymore
hi everyone,
first off all you need open this file /usr/local/share/cert/ca-root-nss.txt
and you need the dele...
sezer h

05/31/2020

09:47 PM pfSense Docs New Content #10311: Default net.link.ifqmaxlen value leads to packet loss under load in OpenVPN
Tried simple setup of PFSense 2.4.5 (without bridges, just TUN adapter) on VPS server.
Same effect - 20-30 mbit O...
Alexey Ab
03:33 PM Bug #10616 (Rejected): Out of date CA root store - FreeDNS (DynDNS) not working anymore
This is not a bug in the pfSense firewall software. The FreeDNS https server is misconfigured and is offering an expi... Chris Linstruth
01:09 PM Bug #10616: Out of date CA root store - FreeDNS (DynDNS) not working anymore
Same Problem for pfBlockerNG, while updating Blocking Lists:
@[ EasyList ] Downloading update . cURL Error: 60
...
Johannes Wanink
12:14 PM Bug #10616 (Rejected): Out of date CA root store - FreeDNS (DynDNS) not working anymore
DynDNS FreeDNS is not working anymore. I get the following errors in the logs:
@Curl error occurred: SSL certifica...
Johannes Wanink

05/30/2020

03:50 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
Same problem here - 2.4.5-RELEASE (amd64)... Donn Lasher
02:06 PM Revision b362e8c2: Cleanup status_queues.php code. Issue #10613
Viktor Gurov
12:26 PM Bug #10614 (Resolved): Unable to update packages due to missing/invalid certs
This was a server side issue and has been resolved. Jim Pingle
09:20 AM Bug #10614 (Resolved): Unable to update packages due to missing/invalid certs
Fresh pfSense 2.4.5-RELEASE installation. The package manager in the web interface states "Unable to retrieve packag... alzee bum
11:12 AM Feature #10615 (Closed): Allow to load kernel from previous release
It would be nice to add /boot/kernel.prev to enable kernel boot from a previous release for emergency/testing cases.
...
Viktor Gurov
09:07 AM Bug #10613: cleanup status_queues.php code
https://github.com/pfsense/pfsense/pull/4343 Viktor Gurov
09:06 AM Bug #10613 (Resolved): cleanup status_queues.php code
remove old/unused code from status_queues.php
see
https://github.com/pfsense/pfsense/pull/4330#pullrequestreview-...
Viktor Gurov
08:47 AM pfSense Packages Bug #10146: squid4 obsolete options
https://wiki.squid-cache.org/ConfigExamples/Intercept/SslBumpExplicit#Troubleshooting:
_NO_SSLv2 is relevant only fo...
Viktor Gurov
06:43 AM pfSense Packages Bug #5168: squid doesn't function during/after HA failover
https://github.com/pfsense/FreeBSD-ports/pull/867
This is mainly for Transparent mode and IPv6 squid configuration...
Viktor Gurov
06:11 AM Revision 30466aef: Allow to use 6RD/6to4 interfaces for DynDNS. Fixes #9641
Viktor Gurov
01:16 AM Bug #9641: Dynamic DNS cannot update AAAA records on 6rd tunnel interfaces bound to PPPoE interfaces
Fix:
https://github.com/pfsense/pfsense/pull/4342
Viktor Gurov

05/29/2020

11:31 PM pfSense Packages Feature #10612 (Resolved): Add pfSense package for Zeek (formerly Bro) Network Security Monitor
PR: https://github.com/pfsense/FreeBSD-ports/pull/866 Prosper Doko
09:24 PM Feature #2983: DHCPD: Add vendor-class-identifier and MAC-OIDs
I second the need for this feature. Ben Tyger
08:22 PM Revision fb477a9d: Fixed whitespace issues as requested by jim-p in the review.
Csoban Kesmarki
05:38 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
I don't know the equivalent of using '(re0)' with the ioctl() API. any pointer will be appreciated.
could you plea...
Thomas BERNARD
01:34 PM Revision bae04c37: Floating rules 6RD and 6to4 interface. Fixes #7142
Viktor Gurov
01:00 PM pfSense Packages Bug #10611 (Resolved): FRR applies file permissions to missing files
When FRR starts it tries to apply file permissions to all the conf files for it's daemons. Including those that are n... Steve Wheeler
12:41 PM Bug #10610 (Resolved): Package upgrade or reinstall hangs indefintely on the console
Installing or upgrading FRR from the CLI hangs indefinitely when FRR is enabled and configured.
At some point duri...
Jim Pingle
11:49 AM pfSense Packages Bug #10444 (Resolved): FRR will not start in 2.4.5 aarch64
Same here on SG-1100, services start and I am seeing neighbors and routes exchanged. Jim Pingle
11:47 AM pfSense Packages Bug #10444: FRR will not start in 2.4.5 aarch64
This looks good in 0.6.5. Service starts as expected.
Tested an SG-1100 running 2.4.5p1.
Steve Wheeler
10:37 AM pfSense Packages Bug #10444: FRR will not start in 2.4.5 aarch64
Please re-test with pfSense-pkg-frr 0.6.5 / frr7-7.3.1 to make sure problem persists Renato Botelho
11:06 AM pfSense Packages Bug #10573 (Resolved): Netgate_Coreboot_Upgrade cannot write to flash in 2.4.5
Jim Pingle
11:04 AM pfSense Packages Bug #10573: Netgate_Coreboot_Upgrade cannot write to flash in 2.4.5
This works correctly in the 0.28 package.
Tested on an SG-4860 in a 2.4.5p1 snapshot.
!Selection_849.png!
Steve Wheeler
10:50 AM Bug #7142: IPv6: Floating rules on 6rd enabled WAN interfaces doesn't get bound to wan_stf
Viktor Gurov wrote:
> Fix:
> https://github.com/pfsense/pfsense/pull/4341
Wow.. two 6rd fixes in two days, you'r...
Kewin Christensen
08:54 AM Bug #7142 (Pull Request Review): IPv6: Floating rules on 6rd enabled WAN interfaces doesn't get bound to wan_stf
Jim Pingle
08:37 AM Bug #7142: IPv6: Floating rules on 6rd enabled WAN interfaces doesn't get bound to wan_stf
Fix:
https://github.com/pfsense/pfsense/pull/4341
Viktor Gurov
10:26 AM Revision 5fff62d9: Do not halt on configuration file not found error. Implements #10556
Viktor Gurov
10:25 AM Bug #10351 (Resolved): Saving IPSEC connection breaks FRR BGP on VTI interfaces
This appears to be doing as much as it can. There may be other similar/related issues but this specific case appears ... Jim Pingle
10:19 AM Bug #9634 (Resolved): rc.newwanipv6 is called although dhcp6c should discard Request messages
Confirmed as resolved Jim Pingle
07:13 AM Bug #9634: rc.newwanipv6 is called although dhcp6c should discard Request messages
Daryl Morse wrote:
> Jim Pingle wrote:
> > By taking action we aren't technically discarding the message. It should...
Jim Pingle
10:03 AM Todo #10609 (Resolved): Fix for CVE-2020-12762 (CVSS 3: 7.8) - json-c integer overflow and out-of-bounds write
New version is present in the staging repo. Jim Pingle
08:20 AM Todo #10609 (Feedback): Fix for CVE-2020-12762 (CVSS 3: 7.8) - json-c integer overflow and out-of-bounds write
Version 0.14 cherry-picked Renato Botelho
06:37 AM Todo #10609 (Resolved): Fix for CVE-2020-12762 (CVSS 3: 7.8) - json-c integer overflow and out-of-bounds write
Running "pkg audit -F" on a 2.4.5-RELEASE box yields:
Fetching vuln.xml.bz2: 100% 853 KiB 873.2kB/s 00:01
...
e 1/1
06:28 AM Revision 4fa69727: 6RD and 6to4 interface MTU set fix. Issue #6377
Viktor Gurov
05:07 AM pfSense Packages Bug #10502: LLDP spamming errors on Netgate XG-7100
So maybe we can track this issue https://github.com/vincentbernat/lldpd/issues/394 and till it (or if it will not) fi... DRago_Angel [InV@DER]
04:53 AM pfSense Packages Bug #10502: LLDP spamming errors on Netgate XG-7100
DRago_Angel [InV@DER] wrote:
> Additionally LLDPd with active NDP (enabled and forced) throw errors if chosen interf...
Viktor Gurov
04:27 AM Bug #9471: GIF tunnel not added to interface group after reboot
no such issue on 2.4.5-p1,
I added the GIF, GRE, VTI, and OPT1 interface to the group of interfaces and can see them...
Viktor Gurov
02:43 AM Bug #10317 (Resolved): SMTP notifications validating SSL when option disabled
works as expected on 2.4.5-p1 - no SSL errors if 'Validate SSL/TLS' checkbox is not set Viktor Gurov
12:43 AM pfSense Packages Bug #10608 (Closed): Update squid port to 4.11-p2
Current pfSense ports squid version 4.10 contains a bug that may cause a crash when users navigate the Internet,
See...
Viktor Gurov

05/28/2020

11:43 PM Bug #9634: rc.newwanipv6 is called although dhcp6c should discard Request messages
Jim Pingle wrote:
> Daryl Morse wrote:
> > Jim Pingle wrote:
> > > The intent of the patch was to not run rc.newwa...
Daryl Morse
07:59 PM Bug #9634: rc.newwanipv6 is called although dhcp6c should discard Request messages
Daryl Morse wrote:
> Jim Pingle wrote:
> > The intent of the patch was to not run rc.newwanipv6 and the "without RA...
Jim Pingle
07:21 PM Bug #9634: rc.newwanipv6 is called although dhcp6c should discard Request messages
Jim Pingle wrote:
> The intent of the patch was to not run rc.newwanipv6 and the "without RA" path wasn't doing that...
Daryl Morse
06:10 PM Revision e2119c73: Correct selectors for remote auth logs. Fixes #10607
Jim Pingle
06:09 PM Revision c472f9a1: Reindex users before performing XMLRPC auth. Fixes #10585
The users may have changed between XMLRPC calls, so take that into
account.
Jim Pingle
01:49 PM Bug #10607: Remote syslog for "General Authentication Events" using wrong selectors
Sounds great, thanks! And appreciate all the help!
Russell Morris
01:38 PM Bug #10607: Remote syslog for "General Authentication Events" using wrong selectors
It will be in the next 2.5.0 snapshot that includes it, so as soon as the build happens, likely later today. Jim Pingle
01:22 PM Bug #10607: Remote syslog for "General Authentication Events" using wrong selectors
Thanks! Sorry, but a dumb question ... how to know when this will show up in an "official" build (to install, and con... Russell Morris
01:20 PM Bug #10607 (Feedback): Remote syslog for "General Authentication Events" using wrong selectors
Applied in changeset commit:e2119c732291143e0e0eff4f2aa1be70554b6315. Jim Pingle
01:08 PM Bug #10607 (Resolved): Remote syslog for "General Authentication Events" using wrong selectors
When "General Authentication Events" is selected, the remote syslog line uses "*.*" and not "auth.*;authpriv.*". This... Jim Pingle
01:15 PM Bug #10585 (Feedback): auth.inc: Exception calling XMLRPC method restore_config_section #-1 : Authentication failed: Invalid username or password
Applied in changeset commit:c472f9a103be09a023141207ed2d2dc94dd3002e. Jim Pingle
01:12 PM Bug #10588: syslog (remote) receiving DHCP logging, even when disabled
NP, thanks!
Russell Morris
01:11 PM Bug #10588: syslog (remote) receiving DHCP logging, even when disabled
OK, I was able to reproduce the problem with the auth log, I moved it over to #10607 -- it may be what caused the pro... Jim Pingle
12:58 PM Feature #6377 (Pull Request Review): 6rd ipv6 tunnel: MTU settings not editable and not correlated to interface MTU (hardcoded to 1280)
Jim Pingle
11:01 AM Feature #6377: 6rd ipv6 tunnel: MTU settings not editable and not correlated to interface MTU (hardcoded to 1280)
https://github.com/pfsense/pfsense/pull/4340 Viktor Gurov
10:06 AM pfSense Packages Bug #10606: Snort Inline stopped working after upgrade to FreeBSD 12.1 (network traffic blocked after heavy load randomly)
You might post on the IDS/IPS category of the forum to catch the snort developer's attention there. Similar issues ha... Jim Pingle
10:02 AM pfSense Packages Bug #10606 (New): Snort Inline stopped working after upgrade to FreeBSD 12.1 (network traffic blocked after heavy load randomly)
Snort Inline stopped working after upgrade to FreeBSD 12.1 (network traffic blocked after heavy load randomly).
Ne...
David Rupprechter
10:01 AM pfSense Packages Feature #10605 (Resolved): Add certificates from Trusted Store to Squid cert store
PfSense 2.5 has the 'add to Trust Store' feature #4068, which allows you to add pfSense certificates to /etc/ssl/cert... Viktor Gurov
08:49 AM Feature #10603 (Pull Request Review): Handle -c commands with arguments in rc.initial
Jim Pingle
08:47 AM pfSense Docs Correction #10604 (Resolved): Feedback on System Monitoring — Monitoring Bandwidth Usage
PR merged Jim Pingle
12:57 AM pfSense Docs Correction #10604: Feedback on System Monitoring — Monitoring Bandwidth Usage
fix:
https://github.com/pfsense/docs/pull/130
Viktor Gurov
08:46 AM pfSense Docs Correction #10598 (Resolved): Feedback on Cellular Wireless — Known Working 3G-4G Modems
PR merged Jim Pingle
08:13 AM Bug #9246 (Closed): dhcp configuration v4/v6 ignores VLAN priority configuration
This is correct behavior,
see https://redmine.pfsense.org/issues/7425#note-21:
Bob Gray wrote:
> In 2.4.4-RELEA...
Viktor Gurov
06:46 AM Revision 71465708: Setting host-uniq for PPPoE. Implements #10597
Viktor Gurov
04:44 AM Bug #6579 (Resolved): IPv6 CARP VIPs lost upon config sync where they include non-significant zeros
works as expected on 2.4.5-p1 HA pair,
I can set fc00:3::512/64, fc00:003::512/64, fc00:0003::0512/64, etc. CARP VIP...
Viktor Gurov
04:40 AM Bug #3896 (Resolved): ipv6 pppoe ISP with static adress
Resolved in #7598 Viktor Gurov
04:34 AM Bug #7822 (Closed): pppoe gui ivp6 set to none still enables in conf
Duplicate of #7386 Viktor Gurov
01:55 AM Feature #7618: Add support for user-supplied Host-Uniq tag and handle PADM messages in Netgraph PPPoE
> We’ll pull the support for this in as soon as FreeBSD accepts it. (It’s too big to carry.)
Accepted: https://githu...
Viktor Gurov
01:07 AM Revision 0cf9ffc2: rc.initial: handle -c command with arguments
before this change rc.initial only passes the first -c parameter.
instead passing every parameter allows you to run c...
Emanuel Rietveld

05/27/2020

08:14 PM Feature #10603: Handle -c commands with arguments in rc.initial
Pull request submitted https://github.com/pfsense/pfsense/pull/4339 Emanuel Rietveld
08:10 PM Feature #10603: Handle -c commands with arguments in rc.initial
Patch attached. Emanuel Rietveld
08:05 PM Feature #10603 (Resolved): Handle -c commands with arguments in rc.initial
Following #4422 rc.initial now handles a -c parameter consisting of a single command with no arguments.
With this ...
Emanuel Rietveld
08:11 PM pfSense Docs Correction #10604 (Resolved): Feedback on System Monitoring — Monitoring Bandwidth Usage
*Page:* https://docs.netgate.com/pfsense/en/latest/monitoring/monitoring-bandwidth-usage.html
*Feedback:*
ntopng ...
Paighton Bisconer
07:44 PM pfSense Packages Bug #10602 (Resolved): Dashboard->Traffic Graphs bandwidth designations on hover pop-ups
The scales are reporting Mbytes/sec but the pop-up is using the Mbits/sec designation: Mb/s. Needs to be corrected ... Randall Barth
07:42 PM pfSense Packages Bug #10601 (New): Dashboard->Traffic Graphs Scale is capped for outbound
The WAN out and LAN in scales are capped at 1 Mbyte/sec. They should adjust scale range as do the WAN in and LAN out. Randall Barth
03:32 PM Bug #10430: Captive Portal shows 404 post login after upgrade to 2.4.5
"After authentication Redirection URL" works for me when I have the client load the portal login page and login. Afte... Jim Pingle
12:15 PM Bug #10430: Captive Portal shows 404 post login after upgrade to 2.4.5
Hi, Jim, I can confirm that something must have changed, possibly during the upgrade, between the two settings "Pre-a... simon lock
03:13 PM Feature #10556 (Pull Request Review): Change action on 'XML configuration file not found' error
Jim Pingle
08:55 AM Feature #10556: Change action on 'XML configuration file not found' error
With this PR it goes forward and shows a console menu that allow you to make a factory reset for example:
https://gi...
Viktor Gurov
03:08 PM pfSense Packages Feature #10600: Add support for pfBlockerNG "Action list" feature
It would be cool if you add both flows. Thank you guys. And about HAproxy Reload Integration it better to be done as ... DRago_Angel [InV@DER]
03:04 PM pfSense Packages Feature #10600 (New): Add support for pfBlockerNG "Action list" feature
Some other plugins that can use pfBlockerNG native aliases can need additional reload/restart action to load new IPs ... DRago_Angel [InV@DER]
03:03 PM Feature #10597 (Pull Request Review): Setting host-uniq for PPPoE
Jim Pingle
04:18 AM Feature #10597: Setting host-uniq for PPPoE
https://github.com/pfsense/pfsense/pull/4337 Viktor Gurov
01:27 AM Feature #10597 (Resolved): Setting host-uniq for PPPoE
https://forum.netgate.com/topic/153911/setting-host-uniq-for-pppoe:
"My ISP uses the host-uniq part of the PPPoE PAD...
Viktor Gurov
02:48 PM pfSense Packages Feature #9793 (Pull Request Review): Add support for HAProxy ACLs "src -f /ipalias.lst" to use pfBlockerNG IP Alias Native
Jim Pingle
01:24 PM pfSense Packages Feature #9793: Add support for HAProxy ACLs "src -f /ipalias.lst" to use pfBlockerNG IP Alias Native
Ok, thanks DRago_Angel [InV@DER]
12:15 PM pfSense Packages Feature #9793: Add support for HAProxy ACLs "src -f /ipalias.lst" to use pfBlockerNG IP Alias Native
it would be nice to use "hitless-reloads" with 'action list'
Please create a new redmine issue for this
Viktor Gurov
11:43 AM pfSense Packages Feature #9793: Add support for HAProxy ACLs "src -f /ipalias.lst" to use pfBlockerNG IP Alias Native
Tested this patch, it works as expected, thanks!
Could you please advice what the best|correct way(command) to recre...
DRago_Angel [InV@DER]
11:24 AM pfSense Packages Feature #9793: Add support for HAProxy ACLs "src -f /ipalias.lst" to use pfBlockerNG IP Alias Native
Yep, this fine. And yes, I understand what this commit adds, thanks =)
Will try to test it now.
DRago_Angel [InV@DER]
11:04 AM pfSense Packages Feature #9793: Add support for HAProxy ACLs "src -f /ipalias.lst" to use pfBlockerNG IP Alias Native
This PR adds support for the URL Table alias type, and it can be not only the pfBlockerNG URL, but also a list on you... Viktor Gurov
10:39 AM pfSense Packages Feature #9793: Add support for HAProxy ACLs "src -f /ipalias.lst" to use pfBlockerNG IP Alias Native
Hi Viktor,
I speak with @bbcan177 about this initially and tested changing files on filesystem. Reloading of SrcIPs ...
DRago_Angel [InV@DER]
03:30 AM pfSense Packages Feature #9793: Add support for HAProxy ACLs "src -f /ipalias.lst" to use pfBlockerNG IP Alias Native
Allows to use URL Table type alias:
https://github.com/pfsense/FreeBSD-ports/pull/865
Viktor Gurov
02:44 PM Bug #9450 (Pull Request Review): Multiwan gateway group fail-over not working as expected (possible race condition)
Proposed fix PR: https://github.com/pfsense/pfsense/pull/4336 Jim Pingle
02:44 PM Bug #10546 (Pull Request Review): Gateways removed from routing groups based on low alert thresholds
Proposed fix PR: https://github.com/pfsense/pfsense/pull/4336 Jim Pingle
01:34 PM pfSense Packages Feature #10599 (Rejected): Add support for hitless-reloads of HAproxy config
HAproxy allows reload configs without restart of service via socket command: https://www.haproxy.com/blog/hitless-rel... DRago_Angel [InV@DER]
01:33 PM Revision 658b4b7f: Do not halt on configuration file not found error. Implements #10556
Viktor Gurov
06:13 AM Bug #9643: Limiters do not function properly on 2.5 snapshots
not working for me either
2.5.0.a.20200522.0732
I need to disable the floating rule to make internet work again
Manuel Piovan
02:01 AM pfSense Docs Correction #10598: Feedback on Cellular Wireless — Known Working 3G-4G Modems
https://github.com/pfsense/docs/pull/129 Viktor Gurov
01:51 AM pfSense Docs Correction #10598 (Resolved): Feedback on Cellular Wireless — Known Working 3G-4G Modems
*Page:* https://docs.netgate.com/pfsense/en/latest/cellular/known-working-3g-4g-modems.html
*Feedback:*
add Sie...
Viktor Gurov

05/26/2020

10:04 PM Bug #10588: syslog (remote) receiving DHCP logging, even when disabled
OK, never mind on 2) ... I think ... LOL. I believe that's my mis-read of the logic in the configuration file. But I ... Russell Morris
09:40 PM Bug #10588: syslog (remote) receiving DHCP logging, even when disabled
Posted the question to the forum, like you suggested - let's see if anyone has seen similar issues. But also, doing s... Russell Morris
08:47 PM Bug #10588: syslog (remote) receiving DHCP logging, even when disabled
Hi,
BTW, I just stumbled on to the fact that pfSense seems to be sending duplicate remote syslog messages for all ...
Russell Morris
08:21 AM Bug #10588: syslog (remote) receiving DHCP logging, even when disabled
OK, will do. And the comment about the *.* was just my thinking ... :-). It still holds that the button is deselected... Russell Morris
08:12 AM Bug #10588 (Not a Bug): syslog (remote) receiving DHCP logging, even when disabled
The "*.*" lines are fine as they are filtered on the process name from the line(s) above them ("!name").
There isn...
Jim Pingle
06:38 PM Revision 40ce94b4: Status / Queues root queue bandwidth calculation fix. Issue #3381
Viktor Gurov
06:35 PM Revision b85557f4: DynDNS with gateway group restart on failover event. Issue #9435
Viktor Gurov
04:50 PM Bug #10586: IPv6 interfaces seem to have hardcoded Link Local Address
It seemed that Issue 9998 was just changing the method of hard coding to an alias. At least that is what the fix see... Rick Coats
07:50 AM Bug #10586 (Duplicate): IPv6 interfaces seem to have hardcoded Link Local Address
This is already being discussed on #9998 Jim Pingle
02:51 PM Revision a3021603: Add REQUEST back to dhcp6c without RA path. Issue #9634
(cherry picked from commit 19fe32b0fe32faf290ea2b74c005c165579277bf) Jim Pingle
02:50 PM Revision 19fe32b0: Add REQUEST back to dhcp6c without RA path. Issue #9634
Jim Pingle
01:52 PM pfSense Docs Correction #10593: Feedback on Third Party Software and pfSense — Configure BIND as an RFC 2136 Dynamic DNS Server
https://ftp.isc.org/isc/bind9/cur/9.16/CHANGES:... Viktor Gurov
12:59 PM Bug #10383: Additional interfaces do not survive a reboot before the setup wizard has been run
This also happens if you restore a config from the CLI after defaulting. To regain access via other interfaces for ex... Steve Wheeler
10:16 AM Bug #10585: auth.inc: Exception calling XMLRPC method restore_config_section #-1 : Authentication failed: Invalid username or password
> - In the previous code the global variable $debug, is not used and it could disappear.
It may not be used direct...
Jim Pingle
09:54 AM Bug #9634 (New): rc.newwanipv6 is called although dhcp6c should discard Request messages
The intent of the patch was to not run rc.newwanipv6 and the "without RA" path wasn't doing that, it was running rtso... Jim Pingle
09:44 AM Bug #9634: rc.newwanipv6 is called although dhcp6c should discard Request messages
The patch is to adhere to the standard: DHCPv6 "clients MUST discard any received Request messages". If fixing that r... Karl Klempner
09:43 AM Bug #10595 (Rejected): RADIUS authentication server incorrectly processing "Accept" messages
I can't reproduce this here. There must be some other factor about your configuration or environment causing the pack... Jim Pingle
09:39 AM Bug #10594 (Pull Request Review): add QLogic 10 Gigabit Ethernet driver (qlxgb) to the ALTQ-capable list
Jim Pingle
09:39 AM Bug #10592 (Pull Request Review): DigitalOcean DNS update adds new DNS record instead of update
Jim Pingle
09:35 AM pfSense Docs Correction #9651 (Resolved): Feedback on Services — DHCP — Configuring the DHCPv6 Server
PR Merged Jim Pingle
09:34 AM pfSense Docs Correction #10262 (Resolved): Feedback on High Availability — Configuring High Availability
PR Merged Jim Pingle
09:31 AM Bug #10591 (Pull Request Review): Cannot set a value for NAT Reflection timeout
Jim Pingle
09:30 AM Bug #9435 (Pull Request Review): Dynamic DNS Update events do not occur after certain failover event cases
Jim Pingle
09:26 AM Bug #10589 (Pull Request Review): interfaces_staticarp_configure() doesnt need to disable staticarp on boot
Jim Pingle
08:21 AM Bug #3381 (Pull Request Review): LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues
Jim Pingle
08:15 AM Bug #3488 (Pull Request Review): Deleting an interface doesn't delete associated shaper queues
Jim Pingle
08:13 AM Feature #885 (Pull Request Review): Show gateway/group IPs on mouseover
Jim Pingle
07:59 AM Bug #3924 (Pull Request Review): Renaming limiters removes them from firewall rules
Jim Pingle
07:57 AM Bug #1353 (Pull Request Review): Number of queues possible
Jim Pingle

05/25/2020

11:37 PM Bug #9634: rc.newwanipv6 is called although dhcp6c should discard Request messages
The description says, "pfsense sends DHCPv6 Request messsages to ff02::1:2 on its WAN interface at an interval of abo... Daryl Morse
09:58 PM Revision b117552c: Update system_advanced_notifications.php
John Kap
08:31 PM Revision a036763d: Add qlxgb to ALTQ-capable list. Issue #10594
Viktor Gurov
06:44 PM Bug #10595 (Rejected): RADIUS authentication server incorrectly processing "Accept" messages
The internal RADIUS authentication mechanism is failing to acknowledge received "Accept" messages from a RADIUS serve... Nathan Dragun
04:41 PM Revision d5e1cbd6: Redmine Issue: https://redmine.pfsense.org/issues/10592
Csoban Kesmarki
03:56 PM pfSense Packages Bug #10476 (Resolved): Services - Acme - Certificates using loopia API
resolved in the latest acme pkg 0.6.8:... Viktor Gurov
03:32 PM Bug #10594: add QLogic 10 Gigabit Ethernet driver (qlxgb) to the ALTQ-capable list
https://github.com/pfsense/pfsense/pull/4335 Viktor Gurov
03:28 PM Bug #10594 (Resolved): add QLogic 10 Gigabit Ethernet driver (qlxgb) to the ALTQ-capable list
according to:
https://www.freebsd.org/cgi/man.cgi?query=altq&apropos=0&sektion=4&manpath=FreeBSD+11.3-RELEASE&arch=d...
Viktor Gurov
03:19 PM Bug #8545: LACP can't be established on QLogic NetXtreme II BCM57810 NICs
see #8324 and https://redmine.pfsense.org/issues/8324
Viktor Gurov
03:19 PM Bug #8324: bxe cards require promisc for OSPF
same issue with LACP - #8545
see https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=213606
Viktor Gurov
01:01 PM pfSense Docs Correction #10593 (Closed): Feedback on Third Party Software and pfSense — Configure BIND as an RFC 2136 Dynamic DNS Server
*Page:* https://docs.netgate.com/pfsense/en/latest/book/thirdparty/configure-bind-for-rfc2136.html
*Feedback:*
...
Viktor Gurov
12:46 PM Bug #10592: DigitalOcean DNS update adds new DNS record instead of update
Fix tested on pfSense 2.4.5 with successfully working on IPv4 and IPv6 NS records. Csoban Kesmarki
11:46 AM Bug #10592: DigitalOcean DNS update adds new DNS record instead of update
Draft pull request created to resolve this: https://github.com/pfsense/pfsense/pull/4334
Testing in live pfsense 2.4.5.
Csoban Kesmarki
11:38 AM Bug #10592 (Resolved): DigitalOcean DNS update adds new DNS record instead of update
The DigitalOcean API lists NS records in pages, 20 per page.
The pfSense Dynamic DNS update only downloads the first...
Csoban Kesmarki
12:11 PM Feature #10412: DHCPv6 Static Entries are not updated on external DDNS server
Side note: I'm using this modified configuration on my 2.4.5 as a patch since 4/02/2020 and updates my bind9 with all... Csoban Kesmarki
12:09 PM Bug #10390: Fix DigitalOcean Dynamic DNS client for IPv6
A note for testing: I'm using this modified code on my 2.4.5 as a patch since 3/29/2020 without any issue. Csoban Kesmarki
10:20 AM Bug #10591: Cannot set a value for NAT Reflection timeout
Move to 2.5.0 Renato Botelho
04:22 AM pfSense Docs Correction #9651: Feedback on Services — DHCP — Configuring the DHCPv6 Server
https://github.com/pfsense/docs/pull/128 Viktor Gurov
01:54 AM pfSense Docs Correction #10262: Feedback on High Availability — Configuring High Availability
https://github.com/pfsense/docs/pull/127 Viktor Gurov
01:47 AM pfSense Docs Correction #10567: Feedback on Cellular Wireless — Known Working 3G-4G Modems
https://github.com/pfsense/docs/pull/126 Viktor Gurov

05/24/2020

08:45 PM Revision b8d9968c: NAT Reflection timeout set fix. Issue #10591
Viktor Gurov
03:46 PM Bug #10591: Cannot set a value for NAT Reflection timeout
fix:
https://github.com/pfsense/pfsense/pull/4333
Viktor Gurov
11:41 AM Bug #10591 (Resolved): Cannot set a value for NAT Reflection timeout
It's not possible to set a value for 'Reflection Timeout' in the Network Address Translation section of System > Adva... Steve Wheeler
02:44 PM pfSense Packages Bug #10502: LLDP spamming errors on Netgate XG-7100
Additionally LLDPd with active NDP (enabled and forced) throw errors if chosen interfaces are parent or child of VLAN... DRago_Angel [InV@DER]
04:27 AM pfSense Packages Bug #10502: LLDP spamming errors on Netgate XG-7100
From github:
Sorry for late reply,
Yep, I have lagg on SPF+ ix0 & ix1 for reductant connection.
In the UI I select...
DRago_Angel [InV@DER]
02:14 PM Bug #9435: Dynamic DNS Update events do not occur after certain failover event cases
https://github.com/pfsense/pfsense/pull/4332 Viktor Gurov
01:49 PM Revision 402012d9: Limiters/queues rename/delete fix. Issue #3924
Viktor Gurov
11:19 AM Bug #7915: CBQ Child queue set bandwidth does not apply correctly
see https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=155736:
_Unfortunately it seems that borrowing does not work w...
Viktor Gurov
11:16 AM Bug #6431 (Resolved): Cannot set queue bandwidth (CBQ)
pfSense 2.4.5 has the "Bandwidth" field and the "Borrow from other queues when available" checkbox Viktor Gurov
10:35 AM Bug #10589: interfaces_staticarp_configure() doesnt need to disable staticarp on boot
Link to Pull Request: https://github.com/pfsense/pfsense/pull/4331 Jonas Christoffersen
10:10 AM Bug #10589 (Resolved): interfaces_staticarp_configure() doesnt need to disable staticarp on boot
When interfaces are created staticarp is not enabled on them.
Therefore we dont need to disable staticarp on an inte...
Jonas Christoffersen
10:16 AM pfSense Packages Bug #10590 (Closed): pfBlockerNG: Invalid argument supplied for foreach()
Dear
I received this crash report today on my router. Maybe this should be checked....
Kevin Holvoet
08:40 AM Bug #3381: LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues
Ignat Esso wrote:
> Further to this, the " Borrow from other queues when available" doesn't work when you go 1 level...
Viktor Gurov
12:29 AM Bug #3488: Deleting an interface doesn't delete associated shaper queues
should be fixed by https://github.com/pfsense/pfsense/pull/4328 Viktor Gurov

05/23/2020

05:17 PM Revision ad4021d6: Show gateway/group IPs on mouseover. Implements #885
Viktor Gurov
12:18 PM Feature #885: Show gateway/group IPs on mouseover
https://github.com/pfsense/pfsense/pull/4329 Viktor Gurov
12:00 PM Bug #10588 (Not a Bug): syslog (remote) receiving DHCP logging, even when disabled
Hi,
I have DHCP logging disabled (for remote), and not "Everything" selected - yet my remote logs are getting a lo...
Russell Morris
09:13 AM Bug #3924: Renaming limiters removes them from firewall rules
Thanks! I just did that to myself multiple times yesterday! Steve Russell
08:50 AM Bug #3924: Renaming limiters removes them from firewall rules
https://github.com/pfsense/pfsense/pull/4328 Viktor Gurov
06:27 AM Bug #1353: Number of queues possible
PRIQ also doesn't allow the use of the same priority for more than one queue:... Viktor Gurov
05:12 AM pfSense Packages Feature #9315: Add Package: dnscrypt-proxy
And Nginx can be used as DoH server with common DNS server as upstream which can be localhost unbound server. One min... DRago_Angel [InV@DER]
02:09 AM Bug #8434 (Resolved): Chelsio T4/T5 CXGBE drivers not loaded as ALTq capable in the PfSense UI
cxl is in the altq capable list on 2.4.5 / 2.5:
https://github.com/pfsense/pfsense/blob/d2abe7c919eaf0c40b911278b96f...
Viktor Gurov
01:00 AM Feature #10587 (Resolved): UPnP/NAT-PMP STUN configuration options
miniupnp allow to use external STUN server to learn WAN IP address in case of NAT 1:1,
this may be useful for double...
Viktor Gurov

05/22/2020

09:06 PM Bug #9634: rc.newwanipv6 is called although dhcp6c should discard Request messages
Jim Pingle wrote:
> This appears to be working OK. The generated script matches the new code, and I no longer see an...
Daryl Morse
05:06 PM Bug #10586 (Duplicate): IPv6 interfaces seem to have hardcoded Link Local Address
The link-local address of each non-WAN interface seems to be hard coded to fe80::1:1. This causes a problem when mul... Rick Coats
03:10 PM Bug #10373 (Resolved): Incorrect copyright year
Looks good on the parts relevant to 2.4.5-p1. Jim Pingle
02:04 PM Bug #10463 (Resolved): The ng_etf module is missing from base in armv6 and aarch64
aarch64 is also OK.... Jim Pingle
01:03 PM Bug #10463: The ng_etf module is missing from base in armv6 and aarch64
Module is in armv6 kernel now. Still need to check aarch64.... Jim Pingle
01:32 PM Bug #10585 (Resolved): auth.inc: Exception calling XMLRPC method restore_config_section #-1 : Authentication failed: Invalid username or password
Hi:
I opened a discussion on this problem in the forum:
https://forum.netgate.com/topic/152604/exception-calling...
Abelardo Acosta Moyano
01:05 PM Bug #10584 (New): SG-3100 with M.2: shutdown instead of reboot
after installing pfSense 2.4.5 on M.2 drive, appliance goes to shutdown instead of reboot on '/sbin/reboot', '/sbin/s... Viktor Gurov
01:04 PM Bug #10420 (Resolved): Miscellaneous page with pre-existing RAM disks config can't be saved
Calculation is correct on 2.4.5-p1 internal testing snapshot. RAM disk space is accounted for properly and used space... Jim Pingle
12:56 PM Todo #10564 (Resolved): Update pkg to 1.13.x
System picked up pkg-1.13.2 during the upgrade, upgrade went fine, still works after. Seems OK to me. Can reopen if o... Jim Pingle
10:41 AM Todo #10564 (Feedback): Update pkg to 1.13.x
done Renato Botelho
12:45 PM Revision 65abee14: Welcome pfSense-2.4.5-RELEASE-p1
Renato Botelho
12:36 PM Bug #10414 (Resolved): Very high CPU usage of pfctl and more causing very high load and a hardly usable internet connection
Both Hyper-V and Proxmox look good on our internal testing snapshots. Both test systems have 4 CPUs. Same systems fro... Jim Pingle
12:08 PM pfSense Packages Bug #10573 (Feedback): Netgate_Coreboot_Upgrade cannot write to flash in 2.4.5
New flashrom fails with `-p internal:ich_spi_force=yes`. It should be fixed on version 0.28 Renato Botelho
10:14 AM pfSense Packages Feature #8727 (Pull Request Review): Clone button in cron pkg
Jim Pingle
09:11 AM pfSense Packages Feature #8727: Clone button in cron pkg
https://github.com/pfsense/FreeBSD-ports/pull/864 Viktor Gurov
10:12 AM Feature #1984 (Pull Request Review): Allow CP Voucher submission via URL so they can be distributed as QR code
Jim Pingle
08:03 AM Feature #1984: Allow CP Voucher submission via URL so they can be distributed as QR code
This PR allow the submission of voucher via such URL:... Viktor Gurov
09:59 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Thomas BERNARD wrote:
> @jim
> you can already have a look at what I've done :
> https://github.com/miniupnp/miniu...
Jim Pingle
09:54 AM Feature #2146 (Pull Request Review): Allow concurrent logins when using vouchers
We can try this but I seem to remember a problem with this in the past. If I recall correctly it was issues with how ... Jim Pingle
05:07 AM Feature #2146: Allow concurrent logins when using vouchers
https://github.com/pfsense/pfsense/pull/4325 Viktor Gurov
09:52 AM Feature #10583 (Pull Request Review): status.php: Add L2TP VPN configuration
Jim Pingle
03:41 AM Feature #10583: status.php: Add L2TP VPN configuration
https://github.com/pfsense/pfsense/pull/4324 Viktor Gurov
03:39 AM Feature #10583 (Resolved): status.php: Add L2TP VPN configuration
Add /var/etc/l2tp-vpn/mpd.conf with 'redacted' l2tp shared secret and radius secret Viktor Gurov
09:50 AM Bug #9437 (Pull Request Review): Captive Portal Bandwidth Limiter application issue (Credentials Vs. MacAddr Validation)
Jim Pingle
12:10 AM Bug #9437: Captive Portal Bandwidth Limiter application issue (Credentials Vs. MacAddr Validation)
see also #9311
fix:
https://github.com/pfsense/pfsense/pull/4322
Viktor Gurov
09:48 AM Bug #9933 (Pull Request Review): Captive Portal + Voucher not keeping auto-added "Pass-through MAC Auto Entry"
Jim Pingle
09:45 AM Bug #9311 (Pull Request Review): Captive Portal continues to limit per-user bandwidth when not enabled
Jim Pingle
12:10 AM Bug #9311: Captive Portal continues to limit per-user bandwidth when not enabled
see also #9437 Viktor Gurov
09:45 AM Bug #3039 (Pull Request Review): New vouchers doesn't sync with CARP slave
Jim Pingle
09:43 AM Bug #10569 (Pull Request Review): Sanitize ACME passwords
Jim Pingle
09:37 AM pfSense Docs Correction #9305 (Resolved): Feedback on Virtual LANs (VLANs) — pfSense VLAN Configuration
PR Merged. Jim Pingle
09:37 AM pfSense Docs Correction #9637 (Resolved): Feedback on High Availability — Example Redundant Configuration
PR Merged. Jim Pingle
09:35 AM pfSense Packages Feature #9874 (Pull Request Review): safesearch enforcing
Jim Pingle
09:26 AM Feature #8952 (Resolved): Dynamic DNS Copy Button
works as expected
tested on 2.5.0.a.20200520.0846
Viktor Gurov
08:40 AM Revision ef1bc81d: status.php: Add L2TP VPN configuration. Implements #10583
Viktor Gurov
07:19 AM Feature #10321: URL/URL Table alias with IDN hostnames
this feature allows to use IDN hostnames in files pointed to by the URL/URL Table alias,
to use IDN hostnames in ali...
Viktor Gurov
05:10 AM Feature #9432 (Closed): Block additional Captive Portal Logins
Duplicate of #2146
see https://github.com/pfsense/pfsense/pull/4325
Viktor Gurov
03:55 AM Bug #8092 (Resolved): Captive Portal Allowed MAC bandwidth changes
no such issue on 2.4.5 or 2.5
after changing the bandwidth, pipe successfully recreated with the new values
https...
Viktor Gurov

05/21/2020

08:36 PM Feature #10581: Provide ability to disable nginx access logging to remote syslog server
And to try to help, make this easier if possible. Some info here,
https://forum.netgate.com/topic/153755/disable-ngi...
Russell Morris
06:07 PM Revision aa63a2e2: Captive Portal keep Pass-through MAC Auto Entry. Issue #9933
Viktor Gurov
05:20 PM Revision d2abe7c9: Improve handling of an empty IPsec phase1 tag. Fixes #10580
Also fixes another PHP error after config upgrade which behaved in a
similar way.
Jim Pingle
04:47 PM Revision 08d9f432: Fix #10525: Move locale directories to proper name
Renato Botelho
04:46 PM Revision 70b71447: Fix #10525: Move locale directories to proper name
Renato Botelho
04:23 PM pfSense Packages Bug #9139: telegraf: add ping for default gateway(s)
The current ping plugin works well for pinging external IPs, but it would be really nice if the local gateway(s) were... Ryan Jaeb
04:21 PM Revision 183964bd: Captive Portal per-user bandwidth input validation fix. Issue #9311
Viktor Gurov
02:24 PM Feature #10321 (Resolved): URL/URL Table alias with IDN hostnames
IDN URL is accepted, though without a known file hosted on an IDN host it's difficult to confirm it works 100%. It wo... Jim Pingle
01:56 PM Bug #10346 (Resolved): DHCPv6 service Dynamic DNS errors
1) The code now supports IPv6 addresses in the DNS server field(s).
2) The domain key is properly validated now
3) ...
Jim Pingle
01:48 PM Feature #10412 (Resolved): DHCPv6 Static Entries are not updated on external DDNS server
Directive is present in the configuration, service runs without errors. Jim Pingle
01:37 PM Bug #8054 (Resolved): DHCP server accepts trailing dot in domain names, DNS resolver adds another and breaks
The trailing dot is no longer allowed in input on the fields in question which would result in an error. Jim Pingle
01:23 PM Bug #10540: is_process_running can generate error for empty process
Thanks for the fix. Orion Poplawski
01:20 PM Bug #10540 (Resolved): is_process_running can generate error for empty process
The pgrep error no longer appears when querying an invalid service. Jim Pingle
01:22 PM Bug #9632 (Resolved): DynDNS not updating IP address for DNSExit
New URL is present in the code, no direct way to test without an account. Jim Pingle
01:21 PM Bug #10390 (Resolved): Fix DigitalOcean Dynamic DNS client for IPv6
New code is present. No direct way to test without an account, but the logic looks sound. Jim Pingle
01:18 PM Bug #8256 (Resolved): IPv6 IP Alias VIP not added to Interface Network Macros
IPv6 IP Alias VIP subnet is now present in interface network macros. Jim Pingle
01:12 PM Bug #9933: Captive Portal + Voucher not keeping auto-added "Pass-through MAC Auto Entry"
https://github.com/pfsense/pfsense/pull/4323 Viktor Gurov
12:54 PM Bug #10525 (Resolved): Chinese (taiwan) / HK Translation using incorrect identifier on 2.4.5
The identifiers now match the language files on the filesystem, and changing to the language works as expected.
Un...
Jim Pingle
11:55 AM Bug #10525 (Feedback): Chinese (taiwan) / HK Translation using incorrect identifier on 2.4.5
Applied in changeset commit:70b7144719d4ba6782bdd4f90af51ed736c9008e. Renato Botelho
09:39 AM Bug #10525 (In Progress): Chinese (taiwan) / HK Translation using incorrect identifier on 2.4.5
There is still some discrepancy here.
For HK the GUI is setting zh_Hans_HK and for TW the GUI is setting zh_Hant_T...
Jim Pingle
12:30 PM Bug #10580 (Feedback): PHP error when restoring to 2.5.0
Applied in changeset commit:d2abe7c919eaf0c40b911278b96f9bab4fa0be45. Jim Pingle
09:37 AM Bug #9311: Captive Portal continues to limit per-user bandwidth when not enabled
This fix clears <bwdefaultdn> and <bwdefaultup> if <peruserbw> is disabled:
https://github.com/pfsense/pfsense/pull/...
Viktor Gurov
09:35 AM Revision 6fee2381: Sanitize ACME passwords. Issue #10569
Viktor Gurov
09:33 AM pfSense Packages Bug #10444: FRR will not start in 2.4.5 aarch64
Jim Pingle wrote:
> Luiz told me he'd work on this
Any news on this? Really looking forward to getting my bgp ba...
Zachary McGibbon
09:15 AM Bug #3039: New vouchers doesn't sync with CARP slave
fix:
https://github.com/pfsense/pfsense/pull/4150
Viktor Gurov
06:02 AM Feature #10467: Email alert functionality for system health
+ as well voting for configurable buildin SMTP notifications by types/monitors. This needed specially when pfSense mo... DRago_Angel [InV@DER]
05:42 AM pfSense Docs Correction #10582 (Closed): Feedback on Services — DNS — Blocking DNS Queries to External Resolvers
*Page:* https://docs.netgate.com/pfsense/en/latest/recipes/dns-block-external.html
*Feedback:*
Step #4 instruct...
Jesse Sheidlower
04:37 AM Bug #10569: Sanitize ACME passwords
https://github.com/pfsense/pfsense/pull/4321 Viktor Gurov
03:42 AM pfSense Docs Correction #9637: Feedback on High Availability — Example Redundant Configuration
https://gitlab.netgate.com/docs/pfSense-book/-/merge_requests/3 Viktor Gurov
03:38 AM pfSense Packages Feature #10500: Build HAProxy Package with buildin Prometheus exporter
If someone need how-to, I wrote it here: https://www.reddit.com/r/PFSENSE/comments/gns3qr/haproxy_20_prometheus_monit... DRago_Angel [InV@DER]
03:10 AM pfSense Packages Feature #10500: Build HAProxy Package with buildin Prometheus exporter
OK:... Viktor Gurov
03:17 AM pfSense Packages Bug #9635 (Resolved): lldpd (and probably ladvd) doesn't work on units with an integrated switch
tested on SG-1100 and XG-7100 - works as expected, lldpd uses the correct interfaces for integrated switches instead ... Viktor Gurov
01:29 AM pfSense Packages Feature #9874: safesearch enforcing
Minor WebGUI fix:
https://github.com/pfsense/FreeBSD-ports/pull/863
Viktor Gurov
12:52 AM Bug #10558: Multicast daemons work at boot, but fail if restarted
Same result here. After a restart of the service it fails. After that if you reboot it still fails to start.
Now I ...
Maarten Hendrix

05/20/2020

07:50 PM Feature #10581: Provide ability to disable nginx access logging to remote syslog server
FYI, a snippet from the start of my /var/etc/syslog.d/pfSense.conf file (remote-hostname replaced for security). Not ... Russell Morris
03:14 PM Feature #10581 (New): Provide ability to disable nginx access logging to remote syslog server
Hi,
It would be helpful to be able to disable nginx access logging, to a remote syslog server - reduce the bandwid...
Russell Morris
07:29 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
@jim
you can already have a look at what I've done :
https://github.com/miniupnp/miniupnp/pull/455
Thomas BERNARD
03:47 PM Bug #10576 (Resolved): Update unbound to mitigate CVE-2020-12662
Jim Pingle
03:47 PM Bug #10576: Update unbound to mitigate CVE-2020-12662
New version is offered on 2.4.5:... Jim Pingle
08:24 AM Bug #10576 (Feedback): Update unbound to mitigate CVE-2020-12662
Done Renato Botelho
01:40 AM Bug #10576 (Resolved): Update unbound to mitigate CVE-2020-12662
Unbound is vulnerable to a new type of DNS amplification attack dubbed NXNSAttack.
* "CVE-2020-12662":https://nlne...
znerol znerol
03:26 PM Bug #10568 (Resolved): Sanitize FreeRADIUS user password
Fine on 2.4.5-p1 via gitsync:... Jim Pingle
07:40 AM Bug #10568 (Feedback): Sanitize FreeRADIUS user password
PR has been merged. Thanks! Renato Botelho
03:21 PM Bug #10574: nginx flooding syslog, but "Web Server Log" disabled
No problem, that makes sense. Thanks! Russell Morris
03:20 PM Bug #10574: nginx flooding syslog, but "Web Server Log" disabled
Probably not terribly difficult but not trivial, you'd have to setup the right directives to exclude things from the ... Jim Pingle
03:15 PM Bug #10574: nginx flooding syslog, but "Web Server Log" disabled
OK, perfect - thanks! New feature created, here: https://redmine.pfsense.org/issues/10581.
And do you know, is the...
Russell Morris
09:39 AM Bug #10574: nginx flooding syslog, but "Web Server Log" disabled
It's currently in a closed state so no worries about closing it out. You can certainly drop a link here to the new on... Jim Pingle
09:38 AM Bug #10574: nginx flooding syslog, but "Web Server Log" disabled
Sure, will do - NP! Let me created it, add a link here (OK?), then close this "bug" out. Russell Morris
07:16 AM Bug #10574: nginx flooding syslog, but "Web Server Log" disabled
It would be better to make a fresh one since fixing this one would involve editing/changing all of the info to match ... Jim Pingle
05:52 AM Bug #10574: nginx flooding syslog, but "Web Server Log" disabled
Hmmm ... I don't seem to be able to change this from a Bug to a Feature Request - is that just me, or do I need to en... Russell Morris
05:51 AM Bug #10574: nginx flooding syslog, but "Web Server Log" disabled
Hi,
Ahh, OK - that makes sense. I wondered based on the wording. Thanks for clarifying!
Yes, it would be great...
Russell Morris
03:21 PM Feature #6228: Please provide a means for IGMPv3 and MLDv2 support
According to the IGMP Proxy documentation, it supports IGMPv3 on the WAN side only - _just because FreeBSD already su... Jens Leinenbach
03:11 PM pfSense Docs Correction #10578 (Resolved): Feedback on Cellular Wireless — Known Working 3G-4G Modems
PR merged Jim Pingle
01:14 PM pfSense Docs Correction #10578: Feedback on Cellular Wireless — Known Working 3G-4G Modems
https://github.com/pfsense/docs/pull/124 Viktor Gurov
12:29 PM pfSense Docs Correction #10578 (Resolved): Feedback on Cellular Wireless — Known Working 3G-4G Modems
*Page:* https://docs.netgate.com/pfsense/en/latest/cellular/known-working-3g-4g-modems.html
Huawei ME909u-521 4G/L...
Viktor Gurov
03:07 PM Bug #10580 (Resolved): PHP error when restoring to 2.5.0
When testing #10458 I tried using a 2.5.0 base to restore a configuration with revision 17.4 containing this IPsec co... Jim Pingle
02:57 PM Bug #10558: Multicast daemons work at boot, but fail if restarted
I concur: I just tried to restart the service via Status/Services and it fails. Jens Leinenbach
02:16 PM Bug #10558: Multicast daemons work at boot, but fail if restarted
It might be that it only runs the first time after a reboot and anything that triggers the service to restart may mak... Jim Pingle
02:04 PM Bug #10558: Multicast daemons work at boot, but fail if restarted
That indeed looks like it started again.
Will it still work after a reboot or do i need to disable it every time i ...
Maarten Hendrix
01:53 PM Bug #10558: Multicast daemons work at boot, but fail if restarted
Maarten Hendrix wrote:
> Looks the same indeed:
> [...]
I disabled the service and the debug mode, updated pfsen...
Jens Leinenbach
03:35 AM Bug #10558: Multicast daemons work at boot, but fail if restarted
Looks the same indeed:... Maarten Hendrix
03:28 AM Bug #10558: Multicast daemons work at boot, but fail if restarted
Maarten Hendrix wrote:
> I tested with PIMD because it does a similar job.
> I tested with it installed and without...
Jens Leinenbach
02:55 PM Bug #10458 (Resolved): Config update error: /etc/inc/upgrade_config.inc:5492
No errors restoring a config with rev 17.4 containing the bad section to 2.4.5. Jim Pingle
12:41 PM pfSense Packages Bug #10579 (Rejected): Blinkled segfaults with SEGV_MAPERR
Hello,
blinkled seem to segfault on my pfSense....
Kacper Boström
12:39 PM Revision 6f9c63cd: Sanitize FreeRADIUS passwords. Fixes #10568
(cherry picked from commit e8bf78f2bac413d86f2646669fda823f6502293e) Viktor Gurov
12:39 PM Revision a88b841b: Merge pull request #4319 from vktg/sanitizeradius
Renato Botelho
12:38 PM Revision 1d045b3e: Build HAProxy Package with buildin Prometheus exporter. Implement #10500
(cherry picked from commit b7e6b62e8eadbef3b1d1c1ff88cbe7448aaa62e2) Viktor Gurov
12:38 PM Revision 662a8d3b: Merge pull request #4320 from vktg/buildhaproxypromex
Renato Botelho
10:45 AM pfSense Packages Feature #10500 (Resolved): Build HAProxy Package with buildin Prometheus exporter
Jim Pingle
10:30 AM pfSense Packages Feature #10500: Build HAProxy Package with buildin Prometheus exporter
Tested, build-in exporter works. Thank you. DRago_Angel [InV@DER]
07:41 AM pfSense Packages Feature #10500 (Feedback): Build HAProxy Package with buildin Prometheus exporter
PR has been merged. Thanks! Renato Botelho
10:44 AM Feature #1205: VPN: User-based / Group-based firewall rules
It has also seen some recent fixes and has some pending enhancements: #9206 #10454 Jim Pingle
10:42 AM Feature #1205: VPN: User-based / Group-based firewall rules
https://docs.netgate.com/pfsense/en/latest/book/openvpn/controlling-client-parameters-via-radius.html Jim Pingle
10:39 AM Feature #1205: VPN: User-based / Group-based firewall rules
Jim Pingle wrote:
> This has been in place since pfSense 2.1. It uses the same syntax as cisco inacl/outacl, for exa...
Christoph Haas
10:38 AM Bug #10492 (Resolved): LDAP groups conflict in privileges
Confirmed problem on stock 2.4.5 and confirmed fix after gitsync. The admin user (id=0) and members of the "admins" g... Jim Pingle
10:10 AM Bug #10577: intel x553 (c3000 chipset) loading x520 driver
here is upload the system.log and files of the system without the x520 card installed.
Peter Martens
09:35 AM Bug #10577: intel x553 (c3000 chipset) loading x520 driver
There still isn't enough info to say what might be happening, this basically boils down to "it doesn't work" with no ... Jim Pingle
09:09 AM Bug #10577: intel x553 (c3000 chipset) loading x520 driver
the unit works normally on 1gb without the x520 card. but when the card is installed the unit stops working.
the x52...
Peter Martens
07:13 AM Bug #10577 (Feedback): intel x553 (c3000 chipset) loading x520 driver
Can you try that on a 2.5.0 snapshot?
The "speed" in the screenshots you show isn't relevant. The ix driver is cap...
Jim Pingle
06:45 AM Bug #10577 (Not a Bug): intel x553 (c3000 chipset) loading x520 driver
We have an supermicro (SYS-5019A-FTN4) based on the c3000 serie cpu (atom C3758) with 2.4.5-RELEASE pfsense on the sy... Peter Martens
09:26 AM Feature #9985: Build virtio_console.ko
See #9877 for info about the state of qemu-guest-agent Jim Pingle
09:25 AM Feature #9877: QEMU Guest Agent
It looks like that port has not been added to FreeBSD yet. The linked PR shows they added some code to the main qemu ... Jim Pingle
09:12 AM Bug #10414: Very high CPU usage of pfctl and more causing very high load and a hardly usable internet connection
I was able to replicate this to a lesser extent on Proxmox VE (6.2-4) as well, with a 4-core VM. Similar setup to the... Jim Pingle
07:44 AM pfSense Packages Bug #10572 (Feedback): STARTTLS option is ignored
PR has been merged. Thanks! Renato Botelho

05/19/2020

11:35 PM Bug #10574 (Not a Bug): nginx flooding syslog, but "Web Server Log" disabled
The checkbox controls errors, not the access log. And the access logging is only sent to remote syslog servers, not l... Jim Pingle
09:29 PM Bug #10574 (Not a Bug): nginx flooding syslog, but "Web Server Log" disabled
Hi,
I have the "Web Server Log" disabled ("If this is checked, errors from the web server process for the GUI or C...
Russell Morris
02:57 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Thomas BERNARD wrote:
> thanks, so
> [...]
> is the additional pf rule that need to be created for outbound traffi...
Jim Pingle
02:38 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
thanks, so... Thomas BERNARD
09:38 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Thomas BERNARD wrote:
> unfortunately it shows that everything is OK when the external port is mapped to the same in...
Jim Pingle
01:08 PM Revision 6dee908b: Revert "Disable rust on suricata for aarch64"
This reverts commit b52e3cb736148ed826908cb76e8da9982f8c3a6e. Renato Botelho
11:52 AM pfSense Packages Bug #10573 (Resolved): Netgate_Coreboot_Upgrade cannot write to flash in 2.4.5
The adi_flash_util binary appears to be handing bad parameters to flashrom in pfSense 2.4.5.
It can read the flash...
Steve Wheeler
10:16 AM pfSense Packages Bug #10572 (Pull Request Review): STARTTLS option is ignored
Jim Pingle
08:46 AM pfSense Packages Bug #10572: STARTTLS option is ignored
https://github.com/pfsense/FreeBSD-ports/pull/862 Viktor Gurov
08:44 AM pfSense Packages Bug #10572 (Feedback): STARTTLS option is ignored
STARTTLS option ($usetls or "-ZZ") is never used as arg for _basic_ldap_auth_ Viktor Gurov
10:12 AM pfSense Packages Feature #10570: OpenVPN Export for iOS should use .ovpn12 for certs and private key
If we change anything at all, it should only affect the Viscosity bundle export format. Nothing else.
If Apple uti...
Jim Pingle
03:04 AM pfSense Packages Feature #10570 (New): OpenVPN Export for iOS should use .ovpn12 for certs and private key
https://forum.netgate.com/topic/144204/openvpn-export-for-ios-should-use-ovpn12-for-certs-and-private-key:
Have a ...
Viktor Gurov
10:08 AM Bug #10568 (Pull Request Review): Sanitize FreeRADIUS user password
Jim Pingle
01:33 AM Bug #10568: Sanitize FreeRADIUS user password
Fix:
https://github.com/pfsense/pfsense/pull/4319
Viktor Gurov
01:25 AM Bug #10568 (Resolved): Sanitize FreeRADIUS user password
fields to sanitize:
<varuserspassword>
<varsqlconfpassword>
<varsqlconf2password>
<varmodulesldappassword>
<varm...
Viktor Gurov
10:07 AM pfSense Docs Correction #10567 (Resolved): Feedback on Cellular Wireless — Known Working 3G-4G Modems
PR merged. Jim Pingle
12:59 AM pfSense Docs Correction #10567: Feedback on Cellular Wireless — Known Working 3G-4G Modems
https://github.com/pfsense/docs/pull/123 Viktor Gurov
09:55 AM Bug #9643: Limiters do not function properly on 2.5 snapshots
Hi.
Same behavior on Proxmox/KVM - pfSense 2.5.0.a.20200518.1031 with vtnet driver.
Any update on this?
Thanks!
Gyula Kelemen
09:43 AM Bug #10566: password for OpenDNS (under DynDNS) not being passed correctly
Does it work if you put the password in with the @&@ changed to &@amp;@?
Change this:...
Jim Pingle
08:55 AM Revision b7e6b62e: Build HAProxy Package with buildin Prometheus exporter. Implement #10500
Viktor Gurov
08:39 AM pfSense Packages Feature #10500: Build HAProxy Package with buildin Prometheus exporter
Kilian Ries wrote:
> I'm also interested in the haproxy prometheus exporter - if you need a tester just let me know....
DRago_Angel [InV@DER]
07:34 AM pfSense Packages Feature #10500: Build HAProxy Package with buildin Prometheus exporter
I'm also interested in the haproxy prometheus exporter - if you need a tester just let me know... Kilian Ries
04:06 AM pfSense Packages Feature #10500: Build HAProxy Package with buildin Prometheus exporter
Hi @Viktor can I test it on my pfsense 2.4.5? And if yes - then how? I have System Patcher but doesn't know if it can... DRago_Angel [InV@DER]
03:57 AM pfSense Packages Feature #10500: Build HAProxy Package with buildin Prometheus exporter
https://github.com/pfsense/pfsense/pull/4320 Viktor Gurov
06:32 AM Revision e8bf78f2: Sanitize FreeRADIUS passwords. Fixes #10568
Viktor Gurov
05:58 AM Bug #7386 (Resolved): IPv6 not disabled in mpd.conf w/ IPv6 GUI option set to 'disabled'
tested with PPP and PPPoE interfaces on 2.5.0.a.20200518.1031 Viktor Gurov
05:54 AM Feature #10538 (Resolved): DNS/Ping/Traceroute IDN support
works as expected on 2.5.0.a.20200518.1031 Viktor Gurov
05:52 AM Bug #10537 (Resolved): wrong link on diag_dns.php
tested on 2.5.0.a.20200518.1031 - OK Viktor Gurov
05:47 AM Bug #7255 (Resolved): Firewall alias FQDN field rejects IDNs (Internationalized domain names)
editing, resolving, import/export - all works as expected
pfSense 2.5.0.a.20200518.1031
Viktor Gurov
04:26 AM pfSense Packages Feature #10571: Add zabbix-proxy50 and zabbix-agent50 packages
sorry, tried search before create ticket and doesn't saw this one. DRago_Angel [InV@DER]
04:15 AM pfSense Packages Feature #10571 (Rejected): Add zabbix-proxy50 and zabbix-agent50 packages
duplicate of #10557 Viktor Gurov
04:09 AM pfSense Packages Feature #10571 (Rejected): Add zabbix-proxy50 and zabbix-agent50 packages
Hi, there is some days ago was been released new version of Zabbix LTS 5.0, could you please add packages for it to p... DRago_Angel [InV@DER]
04:18 AM pfSense Packages Feature #10557: Add Zabbix 5.0 LTS (agent and proxy) packages
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=246447 Viktor Gurov
04:11 AM Revision c68acc14: Set the default ICMP data payload size to 1 in dpinger probes.
This fixes the dropping of the ICMP probes in some broken routers/ISPs.
There is no increase of the packet size on ...
Luiz Souza
04:09 AM Revision ea0d5cbe: Set the default ICMP data payload size to 1 in dpinger probes.
This fixes the dropping of the ICMP probes in some broken routers/ISPs.
There is no increase of the packet size on ...
Luiz Souza
02:29 AM Bug #10569 (Resolved): Sanitize ACME passwords
All <dns_***_key>, <dns_***_password>, <dns_***_secret>, <dns_***_token>, <dns_***_pwd> and <dns_***_pw> fields must ... Viktor Gurov

05/18/2020

11:59 PM pfSense Docs Correction #10567 (Resolved): Feedback on Cellular Wireless — Known Working 3G-4G Modems
*Page:* https://docs.netgate.com/pfsense/en/latest/cellular/known-working-3g-4g-modems.html
*Feedback:*
Add Hua...
Viktor Gurov
06:03 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Thank you very much, Thomas. I emailed the captures to you.
For what it's worth, I did have both PC's showing "Ope...
Connor Ness
05:42 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Connor Ness wrote:
> If you need me to check anything else, I may not be able to until tomorrow. Hopefully this he...
Thomas BERNARD
05:28 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
I can test this right now. I currently have two PCs unable to play Call of Duty together behind a pfSense 2.4.4-RELEA... Connor Ness
02:59 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Dakota Marshall wrote:
> At this point, what is needed to try and further troubleshoot this issue? I will be more th...
Thomas BERNARD
12:48 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
I've been watching this bug for the past 2 years and am excited that there is some traction on it. Though I'm very di... Dakota Marshall
12:17 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
I removed the irrelevant comments made after the warning and locked their account. Further comments unrelated to the ... Jim Pingle
11:26 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Joel S wrote:
> Jim Pingle wrote:
> > Joel,
> >
> > Please stop. That kind of unhelpful dialog is unproductive a...
Thomas BERNARD
10:39 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
We have not enough precise details on the issue :
What AddPortMapping requests the XBoxes are doing and what traffic...
Thomas BERNARD
10:02 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Thomas BERNARD wrote:
> I have seen no detailed description of the problem (AddPortMapping requests from the console...
Jim Pingle
09:26 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Joel,
Please stop. That kind of unhelpful dialog is unproductive and not welcome here, and is getting in the way o...
Jim Pingle
07:16 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Thomas BERNARD wrote:
> Hello, I'm miniupnp main author.
>
> The user Joel S came from here to open an issue on h...
Joel S
03:20 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Hello, I'm miniupnp main author.
The user Joel S came from here to open an issue on https://github.com/miniupnp/mi...
Thomas BERNARD
05:56 PM Bug #10566 (Closed): password for OpenDNS (under DynDNS) not being passed correctly
When utilizing the dynDNS service to update a WAN IP on the OpenDNS, the password was not accepted even though it was... Frank Graffagnino
04:36 PM Revision 146b0a43: Enforce saving logins across reboots when captive portal HA is enabled
Redmine #97 A FL
04:36 PM Revision f2708fe6: Do not remove captive portal zones on backup node if captive portal HA sync is disabled
Fix #9303 A FL
04:36 PM Revision 8e770b88: Reset in-use/expired vouchers on backup node if vouchers are reset on master node.
Redmine #8809 A FL
04:36 PM Revision 6960993d: Remove non captive-portal logs from Local4 syslog facility.
Various logs are recorded in local4 in HA situation. They should not be recorded here.
Redmine #97
A FL
04:36 PM Revision c392f1f5: Write vouchers public key and config in /var/db/ on backup node
Fix #8807 A FL
04:36 PM Revision 0eae38cd: Refresh connected users on primary when becoming master node.
Redmine #97 A FL
04:36 PM Revision 6bfb5b9e: Forward in-use/expired vouchers to the other node when performing a voucher expiration
Redmine #97 A FL
04:36 PM Revision 896889e9: Do not save in-use vouchers to config.
Saving in use/expired vouchers to XML config does trigger an ACB Save and has many undesirable effects in HA situatio... A FL
04:36 PM Revision 318e3f81: Forward in-use/expired vouchers to the other node when performing a voucher auth.
Redmine #97 A FL
04:36 PM Revision 78784180: Forward "Disconnect all" to the other node
Redmine #97 A FL
04:36 PM Revision 4a778ba9: Forward an user disconnection to the other node
Redmine #97 A FL
04:36 PM Revision 24600471: Forward an user connection to the backup node
Redmine #97 A FL
04:36 PM Revision 13164061: Do not perform RADIUS accounting/prune operations when node is in backup mode
Implement Redmine #97 A FL
04:35 PM Revision f72a37e7: Backup node : fetch user list and in-use/expired vouchers from master node.
Implement Redmine #97 A FL
04:35 PM Revision 06ef0830: Create a new page dedicated to backward sync
Implement Redmine #97 A FL
04:33 PM Revision 65a51647: Fix backward vouchers synchronization
Redmine #7972 A FL
02:42 PM Revision a0e4148c: Merge pull request #4306 from vktg/hidearmnetboot
Renato Botelho
02:42 PM Revision 3e1da340: Merge pull request #4304 from vktg/aliasclone
Renato Botelho
02:41 PM Revision 3215d564: Merge branch 'master' into aliasclone
Renato Botelho
02:38 PM Revision 5cd0ec9d: Merge pull request #4311 from vktg/dyndnscopy
Renato Botelho
02:37 PM Revision eeb38d3e: Merge pull request #4312 from vktg/dynv6
Renato Botelho
02:37 PM Revision 0d1adbeb: Merge pull request #4309 from vktg/idndnslookup
Renato Botelho
02:35 PM Revision 1c17a5fa: Merge pull request #4316 from vktg/idnalias
Renato Botelho
02:32 PM Revision 38247b49: is_proccess_running empty proc fix. Issue #10540
(cherry picked from commit 050e18cf3b37e67eda2a16b07f86217421f5b582) Viktor Gurov
02:32 PM Revision e724b5a8: Merge pull request #4318 from vktg/isprocfix
Renato Botelho
02:30 PM Bug #10565 (Rejected): WAN_DHCP6 Stuck Pending / Unknown
There isn't enough information to suggest it's a bug. Around that time is when the base OS moved to FreeBSD 12.1-STAB... Jim Pingle
12:35 PM Bug #10565 (Rejected): WAN_DHCP6 Stuck Pending / Unknown
Around May 8th, updated pfSense test system running development snapshot. Was working fine before update. After updat... Daryl Morse
02:30 PM Revision 341fa0b7: Merge pull request #4308 from xrm/master
Renato Botelho
10:40 AM Feature #2358: NAT64 support
Is it possible that anyone here is skilled in packaging?
Would it be possible for someone to make a Tayga package ...
Brandon Jackson
10:32 AM Todo #10564 (Resolved): Update pkg to 1.13.x
In order to avoi any possible problems of building metadata with more recent pkg than installed on supported systems,... Renato Botelho
10:24 AM Bug #4765: NAT Reflection (Pure NAT) rules not setup for traffic originating from same subnet as final destination
I know this is an old issue, but I am hitting the same problem as the OP here.
I followed up on the thread as well.....
Charles Ross
09:56 AM pfSense Packages Feature #10479 (Feedback): Keep settings after deinstall option
PR has been merged. Thanks! Renato Botelho
09:56 AM pfSense Packages Bug #9635 (Feedback): lldpd (and probably ladvd) doesn't work on units with an integrated switch
PR has been merged. Thanks! Renato Botelho
09:42 AM Feature #10374 (Feedback): Add ARM32/64 network booting support to dhcpd
PR has been merged. Thanks! Renato Botelho
09:42 AM Feature #6908 (Feedback): Alias copy, sort, search/replace functions
PR has been merged. Thanks! Renato Botelho
09:39 AM Feature #8952 (Feedback): Dynamic DNS Copy Button
PR has been merged. Thanks! Renato Botelho
09:38 AM Feature #9642 (Feedback): Add DDNS support for dynv6.com
PR has been merged. Thanks! Renato Botelho
09:37 AM Feature #10538 (Feedback): DNS/Ping/Traceroute IDN support
PR has been merged. Thanks! Renato Botelho
09:35 AM Bug #7255 (Feedback): Firewall alias FQDN field rejects IDNs (Internationalized domain names)
PR has been merged. Thanks! Renato Botelho
09:34 AM Feature #6228: Please provide a means for IGMPv3 and MLDv2 support
FreeBSD seems to support MLDv2 since version 8R as per https://www.freebsd.org/releases/8.0R/relnotes.html
"The IG...
Loh Phat
09:32 AM Bug #10540 (Feedback): is_process_running can generate error for empty process
PR has been merged. Thanks! Renato Botelho
09:31 AM Feature #10392 (Feedback): GRE: Tunnels cannot have IPv6 and IPv4 addresses at the same time
PR has been merged. Thanks! Renato Botelho
09:15 AM Feature #10563 (Rejected): Update Traffic Shaper Wizard Services
The traffic shaper wizard services list works on lists of ports, and most if not all those are web-based services whi... Jim Pingle

05/17/2020

07:52 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Jim Pingle wrote:
>
> pf is capable of doing this kind of NAT, it's the same kind of NAT rules people set manuall...
Joel S
07:40 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Jim Pingle wrote:
>
> pf is capable of doing this kind of NAT, it's the same kind of NAT rules people set manually...
Joel S
04:35 PM Bug #5999: IPv6 IP Alias prevents Track Interface from working with DHCPv6 and RA
Jim Pingle wrote:
> If it is "simple" and "not difficult", we would happily accept a pull request to fix the issue.
...
Rick Coats
06:39 AM Bug #10558: Multicast daemons work at boot, but fail if restarted
I tested with PIMD because it does a similar job.
I tested with it installed and without it installed. Both the same...
Maarten Hendrix
06:12 AM Bug #10558: Multicast daemons work at boot, but fail if restarted
Maarten Hendrix wrote:
> Problem:
> IGMPProxy (and PIMD) will not start after pfSense update on 05-02-2020.
Does...
Jens Leinenbach
01:51 AM Feature #10563: Update Traffic Shaper Wizard Services
And PLEASE don't forget Twitch and other upload heavy streaming services. tag wolf
01:49 AM Feature #10563 (Rejected): Update Traffic Shaper Wizard Services
Please update traffic shaper wizard's services/games to relevant services/games such as:
(just a few examples. but I...
tag wolf

05/15/2020

06:38 PM Revision f607e45c: L2TP server secret is not base64 encoded. Fixes #10527
(cherry picked from commit b3a226f0c6b6d110a1c1d8d8da8550782ea866fb) Jim Pingle
06:37 PM Revision b3a226f0: L2TP server secret is not base64 encoded. Fixes #10527
Jim Pingle
04:19 PM Bug #10558: Multicast daemons work at boot, but fail if restarted
I also did a full reinstall. Nothing changed. Maarten Hendrix
12:02 PM Bug #10558: Multicast daemons work at boot, but fail if restarted
Still same today:... Maarten Hendrix
03:55 PM pfSense Docs Correction #10562 (Resolved): Feedback on L2TP VPN — L2TP with IPsec
*Page:* https://docs.netgate.com/pfsense/en/latest/recipes/l2tp-ipsec.html
*Feedback:*
I struggle with this sig...
Grant ZoBell
02:16 PM Bug #8987 (Resolved): Web GUI main page very slow to load if wan interface is enabled but not connected.
Dashboard loads in a reasonable amount of time with the WANs disconnected. Looks much better to me. Jim Pingle
02:07 PM Feature #7704 (Resolved): Destination port range "Any" in Port Forward UI doesn't work
Rule is now formed correctly and functions as expected. Jim Pingle
01:53 PM Bug #10499 (Resolved): Dark theme Auto-complete popup field has dark text on dark background
When using the dark theme, the autocomplete drop-down now has a light background and text is easy to read. Jim Pingle
01:52 PM pfSense Packages Bug #7654 (Resolved): Can't use a LDAP search filter containing an accent
Supplied string is saved as expected and without error. Jim Pingle
01:50 PM Bug #10527 (Resolved): L2TP shared secret is ignored
Working correctly now after a gitsync. Jim Pingle
01:45 PM Bug #10527 (Feedback): L2TP shared secret is ignored
Applied in changeset commit:b3a226f0c6b6d110a1c1d8d8da8550782ea866fb. Jim Pingle
01:19 PM Bug #10527 (In Progress): L2TP shared secret is ignored
This doesn't work. The secret has base64_decode run on it, but the secret was not stored with base64 encoding, so the... Jim Pingle
01:46 PM Bug #10460 (Resolved): OpenVPN does not add IPv6 prefix to unbound DNS resolver
OpenVPN IPv6 tunnel network is now added to DNS Resolver ACLs automatically. Jim Pingle
01:39 PM Bug #10531 (Resolved): L2TP client not able to use shared secret
Shared secret is now correctly populated in the client configuration and the client can connect to a server with a ma... Jim Pingle
01:20 PM Bug #10247 (Resolved): Duplicate Outbound NAT entries when creating L2TP server
L2TP server subnet(s) are only listed once in outbound NAT now. Jim Pingle
01:17 PM Bug #4866 (Resolved): L2TP server are restarted after adding/modifying L2TP users (mpd.secret)
mpd process is no longer restarted after making changes to users.
Also confirmed that changing a password while it...
Jim Pingle
01:12 PM Bug #10211 (Resolved): Limiters ECN input validation problem
No errors with this configuration now. When ECN is checked, a RED limiter has @ecn@ in the rule. When unchecked, it i... Jim Pingle
01:07 PM Bug #10368 (Resolved): OpenVPN server no definition of protocol to use (udp4)
Protocol is now in client remote statements and they are connecting to servers as expected. Jim Pingle
11:30 AM Bug #10359 (Resolved): Require State Filter setting breaks filter rule link to associated states
Works as expected now. Filtered states are displayed when following the link from the rules list. Jim Pingle
11:11 AM pfSense Packages Feature #10500 (Pull Request Review): Build HAProxy Package with buildin Prometheus exporter
Jim Pingle
10:57 AM pfSense Packages Feature #10500: Build HAProxy Package with buildin Prometheus exporter
https://github.com/pfsense/FreeBSD-ports/pull/861 Viktor Gurov
10:59 AM Bug #9634 (Resolved): rc.newwanipv6 is called although dhcp6c should discard Request messages
This appears to be working OK. The generated script matches the new code, and I no longer see any logged messages abo... Jim Pingle
10:24 AM Bug #10508 (Resolved): Backup does not skip all RRD data
With an existing @<rrddata>@ section in the backup, now backups are generated without the tag entirely (skip RRD chec... Jim Pingle
08:35 AM pfSense Packages Bug #9635 (Pull Request Review): lldpd (and probably ladvd) doesn't work on units with an integrated switch
Jim Pingle
08:34 AM pfSense Packages Bug #10502 (Pull Request Review): LLDP spamming errors on Netgate XG-7100
Jim Pingle
07:58 AM Bug #10155: sshguard is not compatible with RFC 5424 log format
sshguard has added support for this log format in their repo, but it has not yet been released. Something to watch ou... Jim Pingle
07:54 AM pfSense Docs Correction #10561 (Closed): Feedback on Installing and Upgrading — Upgrade Troubleshooting
Jim Pingle
07:42 AM pfSense Docs Correction #10561: Feedback on Installing and Upgrading — Upgrade Troubleshooting
https://github.com/pfsense/docs/pull/122 Viktor Gurov
06:01 AM pfSense Docs Correction #10561 (Closed): Feedback on Installing and Upgrading — Upgrade Troubleshooting
*Page:* https://docs.netgate.com/pfsense/en/latest/install/upgrade-troubleshooting.html
Need to update links to 2....
Viktor Gurov
07:48 AM Bug #10560 (Not a Bug): Connection fails connecting to (my) OpenVPN instance.
This is working fine for myself and others, so it's almost certainly a problem in your config or environment and not ... Jim Pingle
05:27 AM Bug #10560: Connection fails connecting to (my) OpenVPN instance.
And with "the same options" I mean if I use the same command line as is used (I modified the script to print out all ... Stefan Smietanowski
05:19 AM Bug #10560: Connection fails connecting to (my) OpenVPN instance.
Obviously meant pfSense 2.5.0 and not OpenVPN 2.5.0 ... Stefan Smietanowski
05:17 AM Bug #10560 (Duplicate): Connection fails connecting to (my) OpenVPN instance.
When connecting using either OpenVPN Connect on Android using client certificate + username/password or OpenVPN clien... Stefan Smietanowski
03:54 AM pfSense Docs Correction #10559 (Resolved): Feedback on User Management — Granting Users Access to SSH
*Page:* https://docs.netgate.com/pfsense/en/latest/recipes/ssh-access.html
"Enable SSH via webGUI" section is outd...
Viktor Gurov

05/14/2020

03:51 PM Bug #10558: Multicast daemons work at boot, but fail if restarted
After running that and restarting the pfSense box, IGMPProxy still won't start.... Maarten Hendrix
03:23 PM Bug #10558 (Feedback): Multicast daemons work at boot, but fail if restarted
If you have been tracking 2.5.0 snapshots since before early May, first make sure that igmpproxy gets reinstalled for... Jim Pingle
02:52 PM Bug #10558 (Resolved): Multicast daemons work at boot, but fail if restarted
Problem:
IGMPProxy (and PIMD) will not start after pfSense update on 05-02-2020.
Error message:...
Maarten Hendrix
02:44 PM Bug #10416 (Resolved): dhcrelay command line options not properly configured for some DHCP failover scenarios
@dhcrelay@ is running with the expected options now, using @-i@ when an interface is detected as both upstream and do... Jim Pingle
02:42 PM Feature #10341 (Resolved): Exclude unsupported interfaces from DHCP Relay
Unsupported interfaces are no longer offered as choices. Jim Pingle
02:20 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
Yep. Same issue. Today got locked out again out of all our sites. My workaround is to use a personal VPN to force my ... Eduard Rozenberg
02:01 PM Revision dc062b76: Correct regex to remove redundant RRD tags from backup. Fixes #10508
While here, improve regex so it does not leave extra whitespace/blank
lines in the resulting backup.
(cherry picked ...
Jim Pingle
02:00 PM Revision 4213d677: Correct regex to remove redundant RRD tags from backup. Fixes #10508
While here, improve regex so it does not leave extra whitespace/blank
lines in the resulting backup.
Jim Pingle
01:19 PM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
Looking at this again on 2.5.0, now that it's on strongSwan 5.8.4. I do not see any of my VMs with multiple overlappi... Jim Pingle
10:53 AM Bug #10305 (Resolved): Using special character in Schedules description
GUI looks good with the supplied test string. Descriptions show the expected string, and when editing the schedule, t... Jim Pingle
10:50 AM Bug #9259 (Resolved): User with "Deny Config Write" privilege is not fully prevented from creating accounts
Unable to reproduce the problem after the latest commit. Jim Pingle
10:50 AM Feature #4629 (Resolved): Rules Floating tab doesn't display interfaces
Interface column is present in floating rules list and contains the interfaces selected for the rules. Jim Pingle
10:49 AM Bug #9320 (Resolved): Outbound NAT and multiple IPSEC IPs for mobile warriors
per-user IPsec subnets are now present in automatic outbound NAT rules. Jim Pingle
10:46 AM Bug #10542 (Resolved): Exclamation marks in the description field of a floating rule result in a filter reload error.
Description with @\@ is rejected as expected. Without that character, the description is accepted and works. Jim Pingle
10:43 AM Feature #9985 (Resolved): Build virtio_console.ko
Option is present in the kernel.... Jim Pingle
10:42 AM Feature #8289 (Resolved): OpenVPN - configurable username as common name
Option is present in the GUI and works as expected when set to either state (checked or unchecked). Jim Pingle
10:40 AM Feature #10348 (Resolved): Add localhost to NTP Interfaces
Localhost is present in the interface list, can be selected, and is in the configuration when chosen. ntpd is bound t... Jim Pingle
10:38 AM Bug #9334 (Resolved): bogus dialogue on Limiter deletion
Only one prompt with the expected warning now. Jim Pingle
10:37 AM Bug #10418 (Resolved): IPsec VTI address/mask selection not functional
Can now set the type to Network and select a specific mask if necessary. When loading the saved value, the type is se... Jim Pingle
10:33 AM Feature #10221 (Resolved): Update DH group warnings to say that group 5 is also weak
Group 5 is now visible in the warnings. Jim Pingle
10:32 AM Bug #7725 (Resolved): Support for iwm
Device appears to be present in the kernel.... Jim Pingle
10:15 AM pfSense Packages Bug #4497 (Resolved): Using a specific password within FreeRADIUS user management causes pfSense to restore a backup!
Field is CDATA escaped in the config. Password @W!f!4c3ss.@ was saved without error and present in the config after. Jim Pingle
10:13 AM Feature #9891 (Resolved): QLogic 10 Gigabit Ethernet driver (qlxgb)
Appears to be present in the kernel.... Jim Pingle
10:05 AM Feature #10293 (Resolved): DNS flag day - EDNS buffer size recommendation
Expected value is present in the config by default in automatic mode and selecting an option manually is reflected pr... Jim Pingle
10:03 AM Feature #10455 (Resolved): status.php: Add upgrade_log.latest.txt
Output is present as expected in status.php Jim Pingle
10:03 AM Bug #10424 (Resolved): status.php: Calls using pkg should use pkg-static
Output is present as expected in status.php, and verified in the source that it is using @pkg-static@. Jim Pingle
10:02 AM Todo #10423 (Resolved): status.php: Add kernel modules
Output is present as expected in status.php Jim Pingle
10:02 AM Feature #10350 (Resolved): Add OpenVPN configuration file(s) to status.php file
Output is present as expected in status.php Jim Pingle
10:02 AM Todo #10349 (Resolved): status.php: Sanitize ldapbindpass and ldap_pass
Fields are in the list to sanitize. Jim Pingle
09:59 AM Feature #6600 (Resolved): DHCP Server - Primary DDNS Address won't accept IPv6 address
Input is accepted and the resulting config appears to be correct. No errors from DHCP. Jim Pingle
09:56 AM Bug #10200 (Resolved): DHCPv6 domain-search list not sent to clients
Correct option is present now. Jim Pingle
09:49 AM Feature #10448 (Resolved): DHCPv6 RA - show default values in certain fields
Defaults are visible and have the expected values. Jim Pingle
09:48 AM Bug #10264 (Resolved): Gateways created at the console do not apply the naming convention used in the GUI
Gateway created from the console is now @<interface name>GW@ which matches the default GUI name style. Jim Pingle
09:45 AM Bug #10509 (Resolved): unable to remove CA private key
Works now. Can edit a CA and blank out the private key, and when saved it is removed as expected. Jim Pingle
09:10 AM Bug #10508 (Feedback): Backup does not skip all RRD data
Applied in changeset commit:4213d677f6e665d1b391066c27c17155d8da1699. Jim Pingle
09:02 AM Bug #10508: Backup does not skip all RRD data
The old code doesn't appear to have ever worked properly as it was. I pushed some changes to the regex which make it ... Jim Pingle
08:59 AM Bug #10508 (In Progress): Backup does not skip all RRD data
Jim Pingle
08:40 AM pfSense Packages Bug #10502: LLDP spamming errors on Netgate XG-7100
https://github.com/pfsense/FreeBSD-ports/pull/860 Viktor Gurov
08:39 AM pfSense Packages Bug #9635: lldpd (and probably ladvd) doesn't work on units with an integrated switch
https://github.com/pfsense/FreeBSD-ports/pull/860 Viktor Gurov
05:17 AM pfSense Packages Bug #9635 (New): lldpd (and probably ladvd) doesn't work on units with an integrated switch
After I manually changed it to:
>
> After I manually changed it to:
> /usr/local/sbin/lldpd -l -I 'lagg0.4089' -C...
Viktor Gurov
08:02 AM Bug #10554 (Not a Bug): private internet access vpn
There isn't any general problem here, it's specific to your config, provider, or environment. This site is not for su... Jim Pingle
08:01 AM Bug #10555 (Rejected): port forwarding via mac address
No. NAT is handled by pf, and pf doesn't work at L2.
You could assign a static address for a specific MAC, put tha...
Jim Pingle
07:52 AM Feature #10556: Change action on 'XML configuration file not found' error
We already have some code that could handle this, which restores the last good backup when invalid XML is detected. I... Jim Pingle
02:38 AM Feature #10556 (Resolved): Change action on 'XML configuration file not found' error
After a shutdown/filesystem error I got on boot:... Viktor Gurov
06:45 AM pfSense Packages Feature #10557: Add Zabbix 5.0 LTS (agent and proxy) packages
The latest FreeBSD ports version is 4.4.7:
http://pkg.freebsd.org/freebsd:12:x86:64/latest/All/zabbix44-agent-4.4.7....
Viktor Gurov
05:31 AM pfSense Packages Feature #10557 (Resolved): Add Zabbix 5.0 LTS (agent and proxy) packages
New release from zabbix. Please add this new version.
https://www.zabbix.com/rn/rn5.0.0
Pim Janssen
05:11 AM Revision 050e18cf: is_proccess_running empty proc fix. Issue #10540
Viktor Gurov
01:22 AM Bug #8343: Gateway Routes (Default Routes) not removed in Kernel when removed from GUI
on 2.4.5 this is true only for dynamically assigned gateways (WAN_DHCP),
manually added gateways are correctly remov...
Viktor Gurov
12:54 AM Bug #9806 (Resolved): Undefined variables in filter.inc openvpn aliases section
tested on 2.5.0.a.20200512.2320
after fixing and deleting dead code everything works fine
Viktor Gurov

05/13/2020

11:15 PM Bug #10555 (Rejected): port forwarding via mac address
would it be possible to port forward via mac address, or create aliases via mac address, which ports can already be f... natalie sharpe
09:18 PM Bug #10553: Gateway Groups Tier 2 fail dropping states on Tier 1 connection
Hi Jim,
Is dpinger aware of the gateway groups tiers?
The states should only be dropped if the active tier is d...
Daniel Subert
12:39 PM Bug #10553 (Not a Bug): Gateway Groups Tier 2 fail dropping states on Tier 1 connection
That's the expected behavior currently. There is no way to have it only kill states for connections on a specific WAN... Jim Pingle
08:50 PM Bug #10554 (Not a Bug): private internet access vpn
when using private internet access vpn provider, configured through open vpn, if the wan interface goes down so does ... natalie sharpe
08:04 PM Revision e93936ef: L2TP secret description fix. Issue #10531
(cherry picked from commit 9623ec5b2396392cde38231e21cb5d6746928bcf) Viktor Gurov
08:04 PM Revision e6edb571: Merge pull request #4305 from vktg/l2tpsecretdescr
Jim Pingle
07:54 PM Revision ccc94f0a: DynDNS DNSExit URL fix. Issue #9632
Adapted from 4f79a07e7aaa2eba78f73758573483c18b7ed4f9 Jim Pingle
07:53 PM Revision 2ec06184: Merge pull request #4310 from vktg/dnsexitfix
Jim Pingle
07:45 PM Revision bdd27096: Merge pull request #4307 from vktg/dnslinksfix
Jim Pingle
07:45 PM Revision 7cca4879: Fw rule description input validation. Issue #10542
(cherry picked from commit 82f088390fc90c9ee0b90714c496a73817157a4b) Viktor Gurov
07:44 PM Revision f5bd39e5: Merge pull request #4313 from vktg/fwruledescrvalid
Jim Pingle
03:46 PM Bug #10508 (New): Backup does not skip all RRD data
This doesn't appear to be working. Added some dummy RRD tags to a config and they are still there when downloading a ... Jim Pingle
03:05 PM Bug #10531 (Feedback): L2TP client not able to use shared secret
PR merged Jim Pingle
02:56 PM Bug #9632 (Feedback): DynDNS not updating IP address for DNSExit
PR merged, and a similar change made on RELENG_2_4_5 since the commit didn't apply cleanly to cherry-pick. Jim Pingle
02:52 PM Bug #10537 (Feedback): wrong link on diag_dns.php
This doesn't apply to 2.4.5-p1, it was introduced as part of a PR that didn't get picked back. I merged the PR but on... Jim Pingle
02:48 PM Bug #10542 (Feedback): Exclamation marks in the description field of a floating rule result in a filter reload error.
PR merged Jim Pingle
12:56 PM Bug #10414: Very high CPU usage of pfctl and more causing very high load and a hardly usable internet connection
Testing a kernel with the original fix taken out (so r345177 restored), and the new fix applied, it still look good t... Jim Pingle
12:40 PM Bug #10540 (Pull Request Review): is_process_running can generate error for empty process
Jim Pingle
03:45 AM Bug #10540: is_process_running can generate error for empty process
https://github.com/pfsense/pfsense/pull/4317 Viktor Gurov
12:40 PM pfSense Docs Correction #10543 (Closed): Feedback on User Management and Authentication — User Management
Closing as this looks good. Thanks Damon! Jared Dillard
12:35 PM pfSense Docs Correction #9461 (Closed): Feedback on Services — DNS — Configuring the DNS Resolver
Jim Pingle
06:24 AM pfSense Docs Correction #9461: Feedback on Services — DNS — Configuring the DNS Resolver
A warning here about network stoppage/pausing while unbound is reloaded might be helpful.
Steve Russell
03:49 AM pfSense Docs Correction #9461: Feedback on Services — DNS — Configuring the DNS Resolver
https://github.com/pfsense/docs/pull/121 Viktor Gurov

05/12/2020

10:54 PM Bug #10553 (Not a Bug): Gateway Groups Tier 2 fail dropping states on Tier 1 connection
Symptom:
State drops occurring incorrectly in certain fail-over conditions
Setup:
Gateway Group with 2 gateways ...
Daniel Subert
04:10 PM Bug #10414: Very high CPU usage of pfctl and more causing very high load and a hardly usable internet connection
Luke Hamburg wrote:
> Thx Luiz! this is the commit, right?
> https://github.com/pfsense/FreeBSD-src/commit/6c7a5a8e...
Luiz Souza
04:00 PM Revision ea12b607: Alias IDN hostnames support. Issue #7255
Viktor Gurov
10:52 AM pfSense Packages Bug #10552 (Resolved): Typo in OpenBGPD's settings page
There's a typo in OpenBGPD's settings page. Below "General Options" it says "Router IP" when in fact it should be say... Tim Wolter
10:16 AM Bug #10551 (Duplicate): gateway group not restoring the higher tier gateway
Not knowing the technical details, it's unclear to me if this is related to this bug,
https://redmine.pfsense.org/...
Dee D
10:15 AM Bug #7255 (Pull Request Review): Firewall alias FQDN field rejects IDNs (Internationalized domain names)
Jim Pingle
09:50 AM Bug #7255: Firewall alias FQDN field rejects IDNs (Internationalized domain names)
https://github.com/pfsense/pfsense/pull/4316 Viktor Gurov
09:08 AM Bug #10200: DHCPv6 domain-search list not sent to clients
No, wait, such an option doesn't even exist. So should the text box be removed completely from the UI? Magnus Holmgren
08:55 AM Bug #10200: DHCPv6 domain-search list not sent to clients
Same thing with @option domain-name@, I'm pretty sure. Has that been fixed too?
Magnus Holmgren
07:29 AM Bug #10550 (Duplicate): Network interface mismatch after removing USB LTE modem
Duplicate of #9393 Jim Pingle
03:05 AM Bug #10550 (Duplicate): Network interface mismatch after removing USB LTE modem
How to reproduce:
1) Setup the USB LTE modem interface (ue0)
2) Reboot the appliance and remove the USB modem
3)...
Viktor Gurov
06:27 AM pfSense Docs Correction #9305: Feedback on Virtual LANs (VLANs) — pfSense VLAN Configuration
https://gitlab.netgate.com/docs/pfSense-book/-/merge_requests/2 Viktor Gurov

05/11/2020

09:22 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Jim Pingle wrote:
>
> pf is capable of doing this kind of NAT, it's the same kind of NAT rules people set manually...
Joel S
09:19 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Cameron O wrote:
> So is the pf-based miniupnpd just missing some internal or API feature that's in the netfilter-ba...
Jim Pingle
08:56 PM Revision 4594c689: RADIUS authentication via shell/ssh. Implement #10545
Viktor Gurov
08:28 PM Revision 46764785: Update user index after making changes. Fixes #9259
(cherry picked from commit e6c79cd3aafdbd25971a62103b51584335523e33) Jim Pingle
08:27 PM Revision e6c79cd3: Update user index after making changes. Fixes #9259
Jim Pingle
07:22 PM Bug #10414: Very high CPU usage of pfctl and more causing very high load and a hardly usable internet connection
Imported markj@ fix to 2.5.0
https://svnweb.freebsd.org/base?view=revision&revision=360903
Renato Botelho
01:47 PM Bug #10414: Very high CPU usage of pfctl and more causing very high load and a hardly usable internet connection
A proposed fix: https://reviews.freebsd.org/D24803 Jim Pingle
03:35 PM Bug #9259 (Feedback): User with "Deny Config Write" privilege is not fully prevented from creating accounts
Applied in changeset commit:e6c79cd3aafdbd25971a62103b51584335523e33. Jim Pingle
03:28 PM Bug #9259 (Confirmed): User with "Deny Config Write" privilege is not fully prevented from creating accounts
OK, with those exact steps I can reproduce it, but only if I start without any other users. There must be some other ... Jim Pingle
02:45 AM Bug #9259: User with "Deny Config Write" privilege is not fully prevented from creating accounts
Hello Jim,
The issue with this problem is that even in my case, I could not reproduce the issue 100% of the time. ...
Martin VENÇON
01:22 PM Feature #9544: Enable ``ROUTE_MPATH`` multipath routing
There are four known issues with RADIX_MPATH in FreeBSD, three of which can lead to a panic:
https://bugs.freebsd....
Jim Pingle
01:13 PM Feature #9544: Enable ``ROUTE_MPATH`` multipath routing
Still seeing reports of instability after moving to 12.1-STABLE. For example: https://forum.netgate.com/topic/153418/... Jim Pingle
09:46 AM pfSense Docs Correction #10543: Feedback on User Management and Authentication — User Management
That's fine. I mentioned it mostly to show that I had done my due diligence as a new issue reporter :)
Thanks for...
Damon McDougall
09:00 AM pfSense Docs Correction #10543 (Feedback): Feedback on User Management and Authentication — User Management
The book source isn't public. I've updated the syntax to fix the note.
Thanks!
Jim Pingle
09:34 AM Feature #10545 (Pull Request Review): RADIUS authenticated users should be able to log in via ssh
Jim Pingle
08:26 AM Feature #10545: RADIUS authenticated users should be able to log in via ssh
pam_radius is part of the base system
https://github.com/pfsense/pfsense/pull/4315
Viktor Gurov
09:04 AM Bug #10544 (Pull Request Review): It's not possible to add a user to group operator using the gui
Need to think on this a bit. It seems OK from a technical point of view, but security-wise, I'm not so certain. It ma... Jim Pingle
08:57 AM Bug #10542 (Pull Request Review): Exclamation marks in the description field of a floating rule result in a filter reload error.
Jim Pingle
08:54 AM Bug #10540: is_process_running can generate error for empty process
Since that can only happen by manually running an command with an invalid service name, it would be nice to address b... Jim Pingle
08:51 AM pfSense Packages Feature #10479 (Pull Request Review): Keep settings after deinstall option
Jim Pingle
08:50 AM pfSense Docs Correction #9638 (Resolved): Feedback on High Availability — Configuring High Availability
Jim Pingle
08:49 AM pfSense Docs Correction #10371 (Resolved): Update flow control tuning doc for chelsio
Jim Pingle
08:47 AM pfSense Docs Correction #10145 (Resolved): Feedback on Packages — Installing FreeBSD Packages
Jim Pingle
08:46 AM pfSense Docs Correction #9380 (Resolved): Feedback on Cache / Proxy — Tuning the Squid Package
Jim Pingle
08:45 AM pfSense Docs Correction #10534 (Resolved): Feedback on Cellular Wireless — Known Working 3G-4G Modems
Jim Pingle
08:44 AM Feature #9642 (Pull Request Review): Add DDNS support for dynv6.com
Jim Pingle
08:43 AM Feature #8952 (Pull Request Review): Dynamic DNS Copy Button
Jim Pingle
08:41 AM Bug #9632 (Pull Request Review): DynDNS not updating IP address for DNSExit
Jim Pingle
01:54 AM Feature #9165: only IPs can be added to sshguard whitelist
Semi-correct for me, as restart of sshguard or reboot will fix the situation without deeper knowledge of the "issue".... Stefan Beckers

05/10/2020

08:10 PM pfSense Packages Feature #10547 (New): Add package addrwatch. Addrwatch is like arpwatch but works with ipv4 and ipv6
From the developer website:
> This is a tool similar to arpwatch. It main purpose is to monitor network and log di...
Rick Coats
06:27 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
I bought the SG-3100 because I wanted to have the BiS router for epic gaming moments
Turns out one of the "feature...
Star Jesus
02:22 PM Revision 491217a6: Feature #10392: Improved/unified wording, removed link3, fixed empty() vs !== bug, fixed upgrade code. Increased config to 20.3.
sebastian nielsen
02:10 PM Bug #10546 (Resolved): Gateways removed from routing groups based on low alert thresholds
In a Multi-WAN failover scenario, individual gateways are added and removed from gateway groups based on dpinger alar... Vladimir Voskoboynikov
06:36 AM Feature #10545 (Resolved): RADIUS authenticated users should be able to log in via ssh
RADIUS authenticated users are unable to access the cli via ssh.
pam_radius module needed
see https://www.freeb...
Viktor Gurov

05/09/2020

07:20 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
Hi, I'm also interested in this issue and really glad to see there's an active effort to get it resolved. Thanks Joel... Cameron O
05:30 PM Revision 82f08839: Fw rule description input validation. Issue #10542
Viktor Gurov
01:10 PM Bug #10544: It's not possible to add a user to group operator using the gui
Here's a pull request that implements my fix: "#4314":https://github.com/pfsense/pfsense/pull/4314 Craig Leres
01:05 PM Bug #10544 (New): It's not possible to add a user to group operator using the gui
I wanted to create a backup user that could dump the filesystem. I used the gui to create group operator which create... Craig Leres
12:32 PM Bug #10542: Exclamation marks in the description field of a floating rule result in a filter reload error.
The '\' character is not allowed in the Description field.
All other special characters are OK
Fix:
https://gith...
Viktor Gurov
11:19 AM Bug #10542 (Resolved): Exclamation marks in the description field of a floating rule result in a filter reload error.
Some characters such as "/!\" in a floating rule description produce an error when the filter is reloaded.
Steps t...
Léa Al
12:13 PM pfSense Docs Correction #10543: Feedback on User Management and Authentication — User Management
I tried to find the pfSense book source code in the 'pfsense' organisation on GitHub so that I could simply contribut... Damon McDougall
12:09 PM pfSense Docs Correction #10543 (Closed): Feedback on User Management and Authentication — User Management
*Page:* https://docs.netgate.com/pfsense/en/latest/book/usermanager/user-management.html
*Feedback:*
Looks like...
Damon McDougall
10:02 AM Revision 96b2a66a: DynDNS dynv6.com support. Issue #9642
Viktor Gurov
10:00 AM pfSense Packages Feature #10541 (Feedback): Squid failover and load balancing
https://forum.netgate.com/topic/97328/work-in-progress-squid-failover-and-load-balancing-for-pfsense:
I'm seeking a ...
Viktor Gurov
09:42 AM Bug #10540 (Resolved): is_process_running can generate error for empty process
When running svc status for an unknown service you get:... Orion Poplawski
09:16 AM Revision 08a0e055: DynDNS copy button. Issue #8952
Viktor Gurov
08:57 AM pfSense Packages Feature #10479: Keep settings after deinstall option
also remove /usr/local/etc/raddb on package uninstall:
https://github.com/pfsense/FreeBSD-ports/pull/859
Viktor Gurov
08:51 AM pfSense Packages Bug #10445: BIND crashed when added RPZ. rpz is not a master or slave zone.
I found that the issue was occurring for me because the *response-policy* setting was defined in the global *options*... Brandon Rock
08:42 AM pfSense Docs Correction #9638: Feedback on High Availability — Configuring High Availability
https://github.com/pfsense/docs/pull/120 Viktor Gurov
08:42 AM Revision 4f79a07e: DynDNS DNSExit URL fix. Issue #9632
Viktor Gurov
08:12 AM pfSense Docs Correction #10371: Update flow control tuning doc for chelsio
https://github.com/pfsense/docs/pull/119 Viktor Gurov
07:56 AM pfSense Docs Correction #10145: Feedback on Packages — Installing FreeBSD Packages
https://github.com/pfsense/docs/pull/118 Viktor Gurov
07:46 AM pfSense Docs Correction #9380: Feedback on Cache / Proxy — Tuning the Squid Package
http://www.squid-cache.org/Doc/config/range_offset_limit/:... Viktor Gurov
06:15 AM pfSense Docs Correction #10534: Feedback on Cellular Wireless — Known Working 3G-4G Modems
https://github.com/pfsense/docs/pull/116 Viktor Gurov
05:04 AM Feature #9642: Add DDNS support for dynv6.com
https://github.com/pfsense/pfsense/pull/4312 Viktor Gurov
04:18 AM Feature #8952: Dynamic DNS Copy Button
https://github.com/pfsense/pfsense/pull/4311 Viktor Gurov
03:44 AM Bug #9632: DynDNS not updating IP address for DNSExit
https://github.com/pfsense/pfsense/pull/4310 Viktor Gurov
03:00 AM pfSense Packages Bug #10522 (Resolved): Telegraf, Netstat fails (missing lsof)
Good:... Viktor Gurov
02:16 AM Bug #3736 (Resolved): No static IPv6 address for WAN interface in Dashboard for PPPoE+static IPv6
no such issue on 2.4.5 and 2.5
all OK
Viktor Gurov
01:40 AM Feature #9165: only IPs can be added to sshguard whitelist
Stefan Beckers wrote:
> The new sshguard list feature (see #8864) does only allow addition of IP addresses. I do hav...
Viktor Gurov
01:30 AM Bug #3128 (Resolved): Active voucher status not restored from backup
no such issue on 2.4.5 and 2.5
active vouchers status successfully restored
Viktor Gurov

05/08/2020

07:51 PM pfSense Packages Bug #10503: Flapping any GW in multi-WAN influences restating all IPsec tunnels in FRR which leads to dropping all IPsec VTI static routes and related BGP issues
Working around the issue by splitting FRR from Vti
- Add new VIPs to Local host. (one to each side , do not use th...
Alhusein Zawi
04:41 PM Revision e8e3fd22: Feature #10392: Removed IPv4/IPv6 selection. Added code for configuration migration on upgrade.
sebastian nielsen
02:04 PM Feature #8511 (Resolved): Dynamic DNS: Cloudflare Add TTL option
resolved in 2.4.5
see https://redmine.pfsense.org/issues/10196
Viktor Gurov
02:04 PM Bug #5826 (Closed): Auto-exclude LAN address feature only works for the LAN interface
Closing in favor of #3329 -- The PR linked above is already mentioned there and solves this issue as well. Jim Pingle
02:00 PM Bug #5826: Auto-exclude LAN address feature only works for the LAN interface
https://github.com/pfsense/pfsense/pull/4230 Viktor Gurov
01:23 PM Bug #10414: Very high CPU usage of pfctl and more causing very high load and a hardly usable internet connection
Luke,
From what we can tell, pf is doing a ton of smp rendezvous zeroing per-CPU counters. The described "hang" s...
Jim Thompson
01:19 PM Revision c8a39f1b: DNS/Ping/Traceroute IDN support. Issue #10538
Viktor Gurov
12:57 PM Revision 337cacac: diag_ping.php input validation fix. Issue #10537
Viktor Gurov
11:12 AM Bug #10539: OpenVPN incorrect validation of common name with external case-insensitive directory
Yep I know that not all LDAP providers are case insensitive, but most - is. And still even with case sensitive login ... DRago_Angel [InV@DER]
11:07 AM Bug #10539: OpenVPN incorrect validation of common name with external case-insensitive directory
We can maybe add a warning about it, but that is 100% a problem with the authentication server and OpenVPN itself. Th... Jim Pingle
10:35 AM Bug #10539: OpenVPN incorrect validation of common name with external case-insensitive directory
You mean there is no way to change way how username validated to (regex|case-insensitive) or change (strip|convert to... DRago_Angel [InV@DER]
08:31 AM Bug #10539 (Not a Bug): OpenVPN incorrect validation of common name with external case-insensitive directory
That's an issue in OpenVPN internally. You could disable username-as-common-name (checkbox in 2.5.0 or 2.4.5-p1) whic... Jim Pingle
08:26 AM Bug #10539: OpenVPN incorrect validation of common name with external case-insensitive directory
Possible fix addition:
In 1 and 2 common names must be all converted for example to lowercase before check - this wi...
DRago_Angel [InV@DER]
08:23 AM Bug #10539 (Not a Bug): OpenVPN incorrect validation of common name with external case-insensitive directory
Now Common Name is case-sensetive validation field.
With Local Authorization it works fine as Unix local users are c...
DRago_Angel [InV@DER]
10:33 AM Revision 5cb09a31: Feature #10392: GRE: Tunnels cannot have IPv6 and IPv4 addresses at the same time
sebastian nielsen
09:26 AM Feature #10392 (Pull Request Review): GRE: Tunnels cannot have IPv6 and IPv4 addresses at the same time
Jim Pingle
08:14 AM Feature #10392: GRE: Tunnels cannot have IPv6 and IPv4 addresses at the same time
Pull request for GRE part: https://github.com/pfsense/pfsense/pull/4308 Sebas tian
04:39 AM Feature #10392: GRE: Tunnels cannot have IPv6 and IPv4 addresses at the same time
I have implemented the necessary changes for GRE interfaces (and tested them with my setup – seems to be working). I ... Sebas tian
09:21 AM Feature #10538 (Pull Request Review): DNS/Ping/Traceroute IDN support
Jim Pingle
08:21 AM Feature #10538: DNS/Ping/Traceroute IDN support
https://github.com/pfsense/pfsense/pull/4309 Viktor Gurov
08:19 AM Feature #10538 (Resolved): DNS/Ping/Traceroute IDN support
Add support for IDN hostnames on the DNS/Ping/Traceroute diagnostics pages. Viktor Gurov
09:19 AM Bug #10537 (Pull Request Review): wrong link on diag_dns.php
Jim Pingle
07:58 AM Bug #10537: wrong link on diag_dns.php
https://github.com/pfsense/pfsense/pull/4307 Viktor Gurov
07:47 AM Bug #10537 (Resolved): wrong link on diag_dns.php
After resolving the DNS name, you can see at the bottom of the page:
More Information
Ping
Traceroute
If you cl...
Viktor Gurov
07:28 AM pfSense Packages Bug #10536 (Not a Bug): Haproxy doesnt start and exits with error Lua init: table index is nil
That has to be something in your configuration, it's not a problem with the package in general. This site is not for ... Jim Pingle
04:42 AM pfSense Packages Bug #10536 (Not a Bug): Haproxy doesnt start and exits with error Lua init: table index is nil
I have just downgraded my SG-3100 from 2.4.5 to 2.4.4-p3 (due to the blocking cpu causing a bit lag.) I made a backup... Hector Sanchez

05/07/2020

04:08 PM Revision 9623ec5b: L2TP secret description fix. Issue #10531
Viktor Gurov
01:17 PM Bug #9259: User with "Deny Config Write" privilege is not fully prevented from creating accounts
I can't reproduce that problem. I've tried creating an account, deleting an account, various other actions, but nothi... Jim Pingle
04:40 AM Bug #9259: User with "Deny Config Write" privilege is not fully prevented from creating accounts
Hello,
I experienced the same issue described here, and the last changes that you have made did not fix the proble...
Martin VENÇON
12:57 PM Bug #10414: Very high CPU usage of pfctl and more causing very high load and a hardly usable internet connection
Thx Luiz! this is the commit, right?
https://github.com/pfsense/FreeBSD-src/commit/6c7a5a8e69762db2ac0bc465f37c8f04a...
→ luckman212
09:54 AM Bug #10414: Very high CPU usage of pfctl and more causing very high load and a hardly usable internet connection
Fix committed.
Snapshots with this fix will be available soon (for general testing).
Luiz Souza
12:50 PM Feature #10392: GRE: Tunnels cannot have IPv6 and IPv4 addresses at the same time
In that case it should be fairly easy to add that to the GUI by splitting it into separate IPv4 and IPv6 options. It ... Jim Pingle
12:16 PM Feature #10392: GRE: Tunnels cannot have IPv6 and IPv4 addresses at the same time
I manually executed ... Sebas tian
10:49 AM Feature #10374 (Pull Request Review): Add ARM32/64 network booting support to dhcpd
Jim Pingle
05:33 AM Feature #10374: Add ARM32/64 network booting support to dhcpd
Show/hide ARM32/64 booting options on pressing "Display Advanced" button:
https://github.com/pfsense/pfsense/pull/4306
Viktor Gurov
10:46 AM Bug #10531 (Pull Request Review): L2TP client not able to use shared secret
Jim Pingle
05:26 AM Bug #10531: L2TP client not able to use shared secret
description fix:
https://github.com/pfsense/pfsense/pull/4305
Viktor Gurov
10:31 AM Revision 5cb27937: Hide ARM32/64 network booting options. Issue #10374
Viktor Gurov
10:27 AM Feature #10504: Make LACP timeout PDU transmission speed configurable
It seems to be indicated by the flags value:... Jim Pingle
07:27 AM Feature #10504 (Resolved): Make LACP timeout PDU transmission speed configurable
works fine on 2.5.0.a.20200506.1402
but I still don't know how to see the current LACP timeout mode,
no any info...
Viktor Gurov
08:21 AM Feature #10535 (Duplicate): Additional options to add to the dhcpd v4 and v6 configuration files
Duplicate of #5080 Jim Pingle
04:10 AM Feature #10535 (Duplicate): Additional options to add to the dhcpd v4 and v6 configuration files
As of right now the gui for the DHCP server (both v4 and v6) does allow for a limited number of global options. For e... Bogdan P
05:01 AM Bug #10240: Incorrect interface assignment after switching from PPPoE
Jim Pingle wrote:
> There was a similar problem in the past ( #1420 ) but this doesn't seem like quite the same issu...
Viktor Gurov
12:24 AM pfSense Docs Correction #10534 (Resolved): Feedback on Cellular Wireless — Known Working 3G-4G Modems
*Page:* https://docs.netgate.com/pfsense/en/latest/cellular/known-working-3g-4g-modems.html
*Feedback:*
Add ZTE...
Viktor Gurov

05/06/2020

05:09 PM Revision 4b41d250: L2TP client Shared Secret option. Issue #10531
(cherry picked from commit 8e267d3bc59a9d89cf74aa7616566e44b9c5bd69) Viktor Gurov
05:09 PM Revision 041bdc8b: Merge pull request #4303 from vktg/l2tpclientsecret
Renato Botelho
05:09 PM Revision e1f791a0: L2TP VPN shared secret. Issue #10527
(cherry picked from commit 8651a4a4f6923f05f73e65e8647804ad4621565c) Viktor Gurov
05:09 PM Revision ccf9a98a: Merge pull request #4302 from vktg/l2tpsecret
Renato Botelho
05:02 PM Revision 8651a4a4: L2TP VPN shared secret. Issue #10527
Viktor Gurov
04:53 PM Revision 8e267d3b: L2TP client Shared Secret option. Issue #10531
Viktor Gurov
04:12 PM Revision 6978b39e: Alias clone feature. Issue #6908
Viktor Gurov
02:10 PM Todo #10533 (Resolved): Change default domain for new installations from "localdomain" to "home.arpa"
"RFC 8375":https://tools.ietf.org/html/rfc8375 sets aside "home.arpa" for "non-unique use in residential home network... Jim Pingle
01:22 PM pfSense Packages Feature #9874 (Resolved): safesearch enforcing
pfBlockerNG 2.2.5_32
works as expected
Viktor Gurov
01:09 PM pfSense Packages Feature #9833: ACME: add ability to use custom ACME server
I'll add my voice to this request. I just set up a local step-ca ACME server and would love to use it with pfSense. Michael Long
12:53 PM Feature #9985 (Feedback): Build virtio_console.ko
Renato manually merged the PR Jim Pingle
12:26 PM Feature #9985: Build virtio_console.ko
https://github.com/pfsense/FreeBSD-src/pull/30 Viktor Gurov
12:10 PM Bug #10531 (Feedback): L2TP client not able to use shared secret
PR has been merged. Thanks! Renato Botelho
09:12 AM Bug #10531 (Pull Request Review): L2TP client not able to use shared secret
Jim Pingle
04:10 AM Bug #10531: L2TP client not able to use shared secret
some ISPs use this
Fix:
https://github.com/pfsense/pfsense/pull/4303
Viktor Gurov
01:22 AM Bug #10531 (Resolved): L2TP client not able to use shared secret
It is not possible to use Shared Secret by L2TP client,
no such field in WebGUI
http://mpd.sourceforge.net/doc5/m...
Viktor Gurov
12:09 PM Bug #10527 (Feedback): L2TP shared secret is ignored
PR has been merged. Thanks! Renato Botelho
11:43 AM Feature #9891 (Feedback): QLogic 10 Gigabit Ethernet driver (qlxgb)
Added to kernel Renato Botelho
10:45 AM Feature #6908 (Pull Request Review): Alias copy, sort, search/replace functions
Jim Pingle
09:58 AM Feature #6908: Alias copy, sort, search/replace functions
Alias copy/clone:
https://github.com/pfsense/pfsense/pull/4304
Viktor Gurov
10:33 AM pfSense Packages Todo #10528 (Resolved): OpenVPN client export - 2.4.9
All done and tested. Exported installer is 2.4.9 and it works (installs, connects, etc) as expected. Jim Pingle
09:57 AM pfSense Packages Todo #10528 (In Progress): OpenVPN client export - 2.4.9
Jim Pingle
08:54 AM Bug #1773 (Resolved): wrong URL is displayed for web interface access at console for DHCP
no such issue on 2.4.4-p3 + Viktor Gurov
08:13 AM Bug #10532: Mobile PSK users don't have 'mobile-userpool' section
It may be as easy as removing the EAP check at source:src/etc/inc/ipsec.inc#L1596 -- but non-EAP users were also excl... Jim Pingle
05:08 AM Bug #10532: Mobile PSK users don't have 'mobile-userpool' section
some on 2.4.5... Viktor Gurov
04:43 AM Bug #10532 (Resolved): Mobile PSK users don't have 'mobile-userpool' section
I don't see the 'mobile-userpool' section for PSK users, only for EAP:... Viktor Gurov
07:49 AM Feature #8775: Use SRV record for LDAP Authentication
unchanged since 2018:
https://bugs.php.net/bug.php?id=76757
Viktor Gurov
07:30 AM Feature #3907 (Resolved): OpenVPN widget connected client count display
> The Dashboard widget's title is "Server TCP:1194 Client connections". Could it be changed so it counts how much cli... Viktor Gurov
07:17 AM Bug #3038 (Resolved): CARP master not stopping slave's Captive portal
no such issue on 2.5.0.a.20200505.2130
start/stop works fine on both nodes
Viktor Gurov
01:07 AM Bug #10493: filter_get_vpns_list() issues
it can also reduce the scope of #7815 Viktor Gurov
12:37 AM Feature #10340 (Resolved): IPsec Mobile GUI Improvement (Dashboard and Status > IPsec > Leases)
OK on 2.5.0.a.20200505.0238
TODO: IPsec widget option to select default tab (Overview/Tunnels/Mobile)
Viktor Gurov

05/05/2020

06:06 PM Revision c1fc5d87: DHCP Relay: Account for dual-role interfaces. Fixes #10416
Based on a patch from John Steele on the Redmine issue
(cherry picked from commit a76e61149b79fe2892f6083454a563b860...
Jim Pingle
06:05 PM Revision a76e6114: DHCP Relay: Account for dual-role interfaces. Fixes #10416
Based on a patch from John Steele on the Redmine issue Jim Pingle
03:47 PM Bug #8686: IPsec VTI: Assigned interface firewall rules are never parsed
Re-tested this since we have a new base OS on 2.5.0. Unfortunately, this still behaves the same way on 12.1-STABLE:
...
Jim Pingle
03:08 PM Revision 01f5db26: Merge pull request #4300 from vktg/lagginputvalfix
Renato Botelho
02:19 PM Revision e27e8e91: Allow 0 for IPsec P1 reauth/rekey/over. Fixes #10529
Jim Pingle
01:55 PM Revision 88f3d1a3: Fix #10525: Handle Chinese (Hong Kong / Taiwan) locale rename
Renato Botelho
01:53 PM Revision 249a0757: Fix #10525: Handle Chinese (Hong Kong / Taiwan) locale rename
Renato Botelho
01:15 PM Bug #10416 (Feedback): dhcrelay command line options not properly configured for some DHCP failover scenarios
Applied in changeset commit:a76e61149b79fe2892f6083454a563b860a035ab. Jim Pingle
01:04 PM Bug #10416 (In Progress): dhcrelay command line options not properly configured for some DHCP failover scenarios
I couldn't get the patch to work as-is, the downstream list always ended up empty, but I found a variation which appe... Jim Pingle
12:12 PM Bug #10527: L2TP shared secret is ignored
https://github.com/pfsense/pfsense/pull/4302 Viktor Gurov
05:30 AM Bug #10527 (Resolved): L2TP shared secret is ignored
Shared secret on vpn_l2tp.php page is never used,
I don't see any code that uses it, and there is no "set l2tp secre...
Viktor Gurov
10:28 AM pfSense Packages Bug #10522: Telegraf, Netstat fails (missing lsof)
Thanks very much for the quick action! Russell Morris
10:14 AM pfSense Packages Bug #10522 (Feedback): Telegraf, Netstat fails (missing lsof)
PR has been merged. Thanks! Renato Botelho
08:22 AM pfSense Packages Bug #10522 (Pull Request Review): Telegraf, Netstat fails (missing lsof)
Jim Pingle
05:14 AM pfSense Packages Bug #10522: Telegraf, Netstat fails (missing lsof)
correct, see https://github.com/influxdata/telegraf/blob/master/plugins/inputs/net/NETSTAT_README.md:... Viktor Gurov
10:08 AM Feature #10504 (Feedback): Make LACP timeout PDU transmission speed configurable
PR has been merged. Thanks! Renato Botelho
09:58 AM Feature #4038 (Pull Request Review): Button to clear the arp cache
Jim Pingle
05:04 AM Feature #4038: Button to clear the arp cache
https://github.com/pfsense/pfsense/pull/4301 Viktor Gurov
09:56 AM Bug #10530 (New): Convert config version to be based on product version
Today config version is incremented numerically and is agnostic of product version. It makes impossible to add a new... Renato Botelho
09:25 AM Bug #10529 (Feedback): IPsec Phase 1 options Reauth and Rekey do not allow valid "0" value
Applied in changeset commit:e27e8e91e684d993fee62e2ad6cc7e4dd3d4b775. Jim Pingle
09:09 AM Bug #10529 (Resolved): IPsec Phase 1 options Reauth and Rekey do not allow valid "0" value
On vpn_ipsec_phase1.php the options for Reauth and Rekey say they should accept a value of 0, but the bootstrap input... Jim Pingle
09:00 AM Bug #10525 (Feedback): Chinese (taiwan) / HK Translation using incorrect identifier on 2.4.5
Applied in changeset commit:249a0757d5f86c7f0c4229dd45b634c83dfeccd4. Renato Botelho
08:24 AM pfSense Packages Todo #10528 (Resolved): OpenVPN client export - 2.4.9
OpenVPN client 2.4.9 was released.
It would be cool to have it updated: https://openvpn.net/community-downloads/
...
Greg M

05/04/2020

07:01 PM Revision 72aa3cf9: CDATA encode Squid LDAP options. Issue #7654
(cherry picked from commit f14c90586d33493951debc977244f83dcd095b83) Viktor Gurov
07:01 PM Revision 29f87d21: CDATA encode FreeRADIUS user names/passwords. Issue #4497
(cherry picked from commit 5ee65c008f628340fede29d9fbf42a4a68dd63e1) Jim Pingle
07:01 PM Revision 360479cf: Special characters in Schedules descr and rangedescr fields. Issue #10305
(cherry picked from commit 008c15450ec5913c671bc8545682b35f92d63da8) Viktor Gurov
06:50 PM Revision ba77c383: L2TP duplicate outbound NAT fix. Issue 10247
(cherry picked from commit 8f74c44e459e7f9c3d6559bee5d9ca1e49694852) Viktor Gurov
06:49 PM Revision f7ecea49: L2TP username containing @ (realm separator). Issue #9828
(cherry picked from commit f1efc7922e731f8f7f6c02f62fa974eeb884ea85) Viktor Gurov
06:49 PM Revision 802c938b: Allow dashed DUID to be entered in a DHCPv6 Mapping. Issue #2568
(cherry picked from commit ebccd85b82f468ea83603574c8dc9c573b27ff55) Viktor Gurov
06:48 PM Revision c096e481: Fix SMTP SSL/TLS disable validation. Issue #10317
(cherry picked from commit 93166bdcffc51c85662c83ec7789855d72aa869b) Viktor Gurov
06:47 PM Revision da7b476a: Add localhost to NTP Interfaces. Issue #10348
(cherry picked from commit 627253089841122bea33f1d0f140fc55e78f611b) Viktor Gurov
06:43 PM Revision f7e29b5b: DH group 5 warnings for IPsec Phase 1. Issue #10221
(cherry picked from commit 81a58f837a0422890a12bcdf7b3e1b60a04fcbc5) Viktor Gurov
06:40 PM Revision 18c3bb70: Update DH group warnings to say that group 5 is also weak. Issue #10221
(cherry picked from commit 4423176ef39e0461be339b5ded087678f6711c91) Sean McBride
06:40 PM Revision 64f31e89: DHCPv6 RA show default values in certain fields. Issue #10448
(cherry picked from commit 4d7bdf64eb1922136082cfff82ee626b3a8ba35d) Viktor Gurov
06:39 PM Revision d027ed2d: Remove bogus warning on limiter/shaper deletion. Issue #9334
(cherry picked from commit 86c560d985b03d421f8b572c33f8e02b2f08ea56) Viktor Gurov
06:39 PM Revision aad53bc2: Sanitize ldapbindpass and ldap_pass. Issue #10349
(cherry picked from commit 787e634e7f801c8a83e2626d50fb98de041c72ea) Viktor Gurov
06:37 PM Revision 69a614a7: Remote OpenVPN server proto definition. Issue #10368
(cherry picked from commit bd1291d0e45ee982d5a65745086864bf36918dc7) Viktor Gurov
06:37 PM Revision 3050a5d7: RED/GRED limiters do not have noecn option. Issue #10211
(cherry picked from commit 75fb1d576ab12fd399bcfeb57a02545b449a1df4) Viktor Gurov
06:36 PM Revision bcab8a67: allow to disable IPsec P1 when P2 is disabled VTI. Issue #10190
(cherry picked from commit 903826b5b231e371fe934e7ecde2d4f7b6e1be2d) Viktor Gurov
06:36 PM Revision 3cb6e79d: Exclude unsupported interfaces from DHCP Relay. Issue #10341
(cherry picked from commit 5285aa842118fa893a275e46616734b2f54c7e4f) Viktor Gurov
06:34 PM Revision e0bfe3a4: Fixed dhcpdv6 config generation for domain-list option. Fixes #10200
(cherry picked from commit afd8177f803560a1fa7040bbe2b60e68a5ec3918) Florian Apolloner
06:24 PM Revision 30783b6e: URL/URL Table alias with IDN hostnames. Issue #10321
(cherry picked from commit 48a157543b9d4f66c6f0f24316c482db82a0aa1c) Viktor Gurov
06:23 PM Revision acbeb77d: Make OpenVPN username-as-common-name options. Implements #8289
(cherry picked from commit e5c4f2a7d977fb1fd6c7b4446e187486b72285be) Jim Pingle
06:23 PM Revision 345a232f: Do not restart L2TP server after adding/modifying users. Issue #4866
(cherry picked from commit 810923482479d09c4987f7f29b12299be15ac352) Viktor Gurov
06:23 PM Revision 2816960c: Do not include disabled IPSec P2 entries to <vpn_networks>. Issue #7622
(cherry picked from commit 12f9467e207e07bee4b93673b17b836e77216f6e) Viktor Gurov
06:22 PM Revision ae0dacfc: Add ipsec_reload_package_hook() to apply function. Fixes Bug #10351
Adapted From 4aebc4ba84aefa0be7084960cb1387352e6a3792 Jim Pingle
06:20 PM Revision d16276b4: DHCP6 client discard REQUEST messages. Issue #9634
(cherry picked from commit 8788b0613a66e48ff4da45f4228bda481c37f7a9) Viktor Gurov
06:19 PM Revision 27e83e10: Compare compressed IPv6 CARP VIP. Issue #6579
(cherry picked from commit 84052eb74b7c470ebf8fd0bb1b56ce475725b1a6) Viktor Gurov
06:18 PM Revision 7f9d80e1: Firewall rule states link and Require State Filter option fix. Issue #10359
(cherry picked from commit afb4cdcd2a96138b70b888c6750f8b1140ab8c2a) Viktor Gurov
03:31 PM Bug #7725: Support for iwm
Added to 2.4.5-p1 kernel Renato Botelho
02:11 PM pfSense Packages Bug #10522: Telegraf, Netstat fails (missing lsof)
Yes, it works for me as well - after I manually install lsof. The reason I raised this is that lsof should be include... Russell Morris
01:57 PM pfSense Packages Bug #10522: Telegraf, Netstat fails (missing lsof)
can't reproduce, it work for me
[2.4.5-RELEASE][root@pfSense.trmultiservice.lab]/root: telegraf --test --input-filte...
Manuel Piovan
02:02 PM pfSense Packages Bug #7654 (Feedback): Can't use a LDAP search filter containing an accent
Jim Pingle
02:02 PM Bug #10305 (Feedback): Using special character in Schedules description
Jim Pingle
01:51 PM Bug #10247 (Feedback): Duplicate Outbound NAT entries when creating L2TP server
Original commit is commit:8f74c44e459e7f9c3d6559bee5d9ca1e49694852
Picked back in commit:ba77c38370
Jim Pingle
01:48 PM Feature #10348 (Feedback): Add localhost to NTP Interfaces
Jim Pingle
01:43 PM Feature #10221 (Feedback): Update DH group warnings to say that group 5 is also weak
Jim Pingle
01:40 PM Feature #10448 (Feedback): DHCPv6 RA - show default values in certain fields
Jim Pingle
01:39 PM Bug #9334 (Feedback): bogus dialogue on Limiter deletion
Jim Pingle
01:39 PM Todo #10349 (Feedback): status.php: Sanitize ldapbindpass and ldap_pass
Jim Pingle
01:38 PM Bug #10368 (Feedback): OpenVPN server no definition of protocol to use (udp4)
Jim Pingle
01:37 PM Bug #10211 (Feedback): Limiters ECN input validation problem
Jim Pingle
01:36 PM Feature #10341 (Feedback): Exclude unsupported interfaces from DHCP Relay
Jim Pingle
01:35 PM Bug #10200 (Feedback): DHCPv6 domain-search list not sent to clients
Jim Pingle
01:24 PM Feature #10321 (Feedback): URL/URL Table alias with IDN hostnames
Jim Pingle
01:24 PM Feature #8289 (Feedback): OpenVPN - configurable username as common name
Jim Pingle
01:23 PM Bug #4866 (Feedback): L2TP server are restarted after adding/modifying L2TP users (mpd.secret)
Jim Pingle
01:19 PM Bug #6579 (Feedback): IPv6 CARP VIPs lost upon config sync where they include non-significant zeros
Jim Pingle
01:19 PM Bug #10359 (Feedback): Require State Filter setting breaks filter rule link to associated states
Jim Pingle
09:08 AM Bug #10524: Bridge that includes a GIF interface does not come up at boot
Jim Pingle wrote:
> Did this work on a previous version?
I didn't use this combination in previous version. Howev...
Yuran Yastreb
08:02 AM Bug #10524: Bridge that includes a GIF interface does not come up at boot
Did this work on a previous version? Jim Pingle
08:59 AM pfSense Packages Bug #10526: Package pfBlockerNG Crashes on Alert view
Looks like your alert log was allowed to grow too large.
Post on https://forum.netgate.com/category/62/pfblockerng...
Jim Pingle
08:54 AM pfSense Packages Bug #10526 (New): Package pfBlockerNG Crashes on Alert view
Error Message:
Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 513799651 bytes) in ...
Larry Westfall
08:06 AM Feature #10523 (Rejected): Integrate remote backup (push) into ACB
ACB is the only method we plan on integrating for that functionality at this time. Other methods may be implemented m... Jim Pingle
07:59 AM Feature #10521: Syslog, Level Filter / Setting
Jim Pingle wrote:
> That kind of filtering should be done on a central log processing host, irrespective of the numb...
Russell Morris
07:57 AM Feature #10521 (Rejected): Syslog, Level Filter / Setting
I'm not sure this would be viable as not everything gets tagged with relevant syslog levels, especially messages from... Jim Pingle
07:49 AM Feature #10504 (Pull Request Review): Make LACP timeout PDU transmission speed configurable
Jim Pingle
02:57 AM Bug #10525 (Resolved): Chinese (taiwan) / HK Translation using incorrect identifier on 2.4.5
When I using pfsense 2.4.4 upgrade to 2.4.5 the language change Chinese(Taiwan) or HK has error.
When I want chang...
Roll Stone
01:30 AM Bug #9647: hn0: driver does not support altq
Hello.
Can someone please take a look at this one?
It seems trivial to fix or am I wrong?
Greg M
 

Also available in: Atom