Project

General

Profile

Activity

From 07/26/2020 to 08/24/2020

08/24/2020

01:11 PM Bug #10798 (Resolved): Unable to save CP zone named 'VIP'
Tested on:
2.5.0-DEVELOPMENT (amd64)
built on Mon Aug 24 07:02:12 EDT 2020
FreeBSD 12.1-STABLE
I was not able t...
Danilo Zrenjanin
10:16 AM pfSense Packages Bug #10845: apcupsd doesn't stop when not enabled
This is repeatable after rebooting the pfSense host. Dan Langille
10:12 AM pfSense Docs Correction #10849 (Rejected): Suggestions to improve docs related to package development
a) is correct for those who have direct commit access to that repo. Others should be cloning their own fork, not that... Jim Pingle
10:01 AM Feature #10848 (Rejected): widget "interfaces" improvement: use space for interface name, show netmask, show config type
Jim Pingle
10:01 AM Bug #10847 (Pull Request Review): Mobile user IPSec (PSK+Xauth) fails at user auth with PHP error
Jim Pingle
09:43 AM Bug #10846 (Pull Request Review): Icon area within buttons are not clickable
This issue only seems to affect the delete button on the schedules page. I can't find any other button that won't let... Jim Pingle
07:26 AM pfSense Packages Todo #10851 (Rejected): Snort PORTVERSION Changed
Thanks, but the snort package maintainer will update it as needed when it's appropriate to do so. Jim Pingle
02:18 AM pfSense Packages Todo #10851 (Rejected): Snort PORTVERSION Changed
PORTVERSION= 2.9.16 is obsolete,
Snort website port version is snort-2.9.16.1
Please check Snort Site
Sreekumar PM
07:14 AM Bug #7209: Something is seriously wrong with firewall aliases
I think I probably had this issue today on a 2.4.4-p3 firewall.
I had an alias containing one FQDN (in first row) ...
Dennis Neuhaeuser
06:16 AM Feature #8713: Allow user to disable/enable multiple firewall rules at one time
Аноним wrote:
> Currently, a user may disable or enable a firewall rule through the WebGUI by either editing the rul...
Ameelien Niko
06:15 AM Feature #2505: Toggle button to disable/enable multiple firewall rules
Matt Bochenek wrote:
> I'd like to be able to disable and enable multiple firewall rules at once. It would make it e...
Ameelien Niko

08/23/2020

10:55 AM Bug #10850 (Duplicate): GoDaddy (v6) returns error when creating or updating
When creating or updating a DDNS entry using "GoDaddy (v6)" as the service, the following entries appear in the syste... Anonymous
07:34 AM pfSense Docs Correction #10849: Suggestions to improve docs related to package development
Second line under c) "- a shell script" is a new subject "c2/d". sorry for the typo Louis B
07:30 AM pfSense Docs Correction #10849 (Rejected): Suggestions to improve docs related to package development
I have been modifying the pfSense-pkg-pimd package, in order to support the upcoming pimd-version-3 release (still in... Louis B
06:23 AM Feature #10848: widget "interfaces" improvement: use space for interface name, show netmask, show config type
sorry that was supposed to go the opnsense issues. sadly i cannot edit my report here?
the only thing that seems t...
IT IGP

08/22/2020

08:40 AM Feature #10848 (Rejected): widget "interfaces" improvement: use space for interface name, show netmask, show config type
1. even with enough space available, long interface names gets split across several lines
2. show netmask for each i...
IT IGP
08:22 AM Bug #10847 (Resolved): Mobile user IPSec (PSK+Xauth) fails at user auth with PHP error
amd64
12.1-STABLE
FreeBSD 12.1-STABLE b385628d96e(devel-12) pfSense
Crash report details:
PHP Errors:
[21-Au...
James Cooksey

08/21/2020

08:57 PM Revision ed90018e: Fix array pass by reference in ipsec.auth-user.php
Fixes error: PHP Fatal error: Uncaught Error: Cannot pass parameter 3 by reference in /etc/inc/ipsec.auth-user.php:9... James Cooksey
08:49 PM Revision 50169a70: prevent embedded button icons from interfering with click events #10846
Marc 05
08:07 PM Revision 616a1916: Added setup wizard utility file
Steve Beaver
03:32 PM Bug #10846 (Resolved): Icon area within buttons are not clickable
The embedded icon section of buttons are not clickable. See attached for reference.
This seems to only affect the ...
Marcos M
11:11 AM Bug #10827: Cannot add or delete separators when no rules are present
I was able to reproduce this, and it looks to affect both firewall_nat.php and firewall_rules.php.
Neither adding ...
Marcos M

08/20/2020

07:39 PM Revision 5130e45a: fixed xbox live stuff
removed gamesforwindowslive since it is covered by xbox live and afaik uses same servers and pretty much dead
renamed...
Joseph Turner
07:36 PM Revision 01d0443b: fixed xbox live stuff
removed gamesforwindowslive since it is covered by xbox live and afaik uses same servers and pretty much dead
renamed...
Joseph Turner
07:33 PM Revision 532be905: Merge pull request #4409 from vktg/sanitizegeoipkey
Renato Botelho
02:33 PM Bug #10797 (Feedback): status.php: Sanitize MaxMind GeoIP key
PR has been merged. Thanks! Renato Botelho
11:50 AM pfSense Packages Bug #10845: apcupsd doesn't stop when not enabled
To be clear, this is not blocking / hindering anything for me. Dan Langille
11:50 AM pfSense Packages Bug #10845: apcupsd doesn't stop when not enabled
I'm happy to try things here. Dan Langille
11:19 AM pfSense Packages Bug #10845: apcupsd doesn't stop when not enabled
I can't seem to reproduce that here on 2.4.5-p1 (arm, network UPS), 2.5.0 (amd64, network UPS), or 2.5.0 (amd64, USB ... Jim Pingle
11:07 AM pfSense Packages Bug #10845 (New): apcupsd doesn't stop when not enabled
I'm running pfSense 2.4.5-p1 and apcupsd 0.3.91_8
Attempts to stop apcupsd fail.
To reproduce:
# visit /pkg_...
Dan Langille
08:38 AM Feature #855: Ability to selectively kill states on gateway recovery
+1 I haven't really been hurt by this until recently while performing a big backup job to the cloud. Failover occurre... Raffi T
05:12 AM Bug #10844 (Resolved): DHCPv6 service Dynamic DNS revisions made to fix Bug #10346 violates RFC/is too restrictive
The GUI syntax checking changes made in the submitted revisions regarding the "DDNS Domain Key Name" is actually not ... Kewin Christensen

08/19/2020

06:17 PM Feature #7791: include /usr/bin/strings in core pfSense
Just a quick note to say thank you for adding strings - very handy, much appreciated, and keep up the good work! Royce Williams
04:41 PM Feature #10843 (New): Allow user manager settings to specify multiple authentication servers
We would really like to have redundancy with our LDAP authentication for the pfSense web interface, but this appears ... Orion Poplawski
02:14 PM Revision b55b5c18: Merge pull request #4426 from vktg/rfc2136zone
Renato Botelho
02:13 PM Revision e0d07cc4: Merge pull request #4425 from vktg/sancomminity
Renato Botelho
01:50 PM Revision 9a012045: Not destroying VTI interfaces when booting before creating a new one. Fixes #10842
Viktor Gurov
12:25 PM Bug #9643: Limiters do not function properly on 2.5 snapshots
I can also confirm it works fine on LAN, and since the setup uses NAT, it means I can use this as a workaround, I put... Chris Collins
11:27 AM Bug #9643: Limiters do not function properly on 2.5 snapshots
Hi guys, just to confirm it looks like I have the same problem.
pfSense running in a Proxmox VM, I did gui update ...
Chris Collins
09:56 AM pfSense Packages Bug #10823 (Feedback): named.conf "controls" section missing IPv6 localhost on IPv6 enabled PFsense - breaking rndc
PR has been merged. Thanks! Renato Botelho
09:56 AM pfSense Packages Bug #10824 (Feedback): BIND shutdown - dynamic zones, unclean shutdown causes startup to not load zones
PR has been merged. Thanks! Renato Botelho
09:56 AM pfSense Packages Bug #10832 (Feedback): Bind DNSSEC validation "deselected" not disabling DNSSEC validation
PR has been merged. Thanks! Renato Botelho
09:51 AM pfSense Packages Feature #10665 (Feedback): Manual OSPF neighbor definitions
PR has been merged. Thanks! Renato Botelho
09:49 AM pfSense Packages Feature #10769 (Feedback): Prevent users from creating new ACMEv1 keys
PR has been merged. Thanks! Renato Botelho
09:48 AM pfSense Packages Bug #10770 (Feedback): arpwatch: cannot remove email once it has been entered into settings
PR has been merged. Thanks! Renato Botelho
09:47 AM pfSense Packages Bug #10775 (Feedback): pfblockerNG SBL_ADs and hpHosts are not reachable anymore
PR has been merged. Thanks! Renato Botelho
09:44 AM pfSense Packages Feature #10796 (Feedback): Huawei ME909u-521 support
PR has been merged. Thanks! Renato Botelho
09:28 AM pfSense Packages Feature #10785 (Feedback): Allow Setting of ldapcachetime
PR has been merged. Thanks! Renato Botelho
09:26 AM pfSense Packages Feature #10779 (Feedback): HAProxy SSL/TLS Compatibility Mode
PR has been merged. Thanks! Renato Botelho
09:25 AM Feature #10748: Add support for limiting IPsec VPN access per user group via RADIUS
Awesome, thank you very much! Yury Zaytsev
09:23 AM Bug #10842 (Pull Request Review): Not destroying VTI interfaces when booting before creating a new one
Jim Pingle
08:54 AM Bug #10842: Not destroying VTI interfaces when booting before creating a new one
Martin VENÇON wrote:
> Are we not checking if the interface exists in the condition ? Removing the platform_booting ...
Viktor Gurov
07:44 AM Bug #10842: Not destroying VTI interfaces when booting before creating a new one
Are we not checking if the interface exists in the condition ? Removing the platform_booting part from the condition ... Martin VENÇON
07:36 AM Bug #10842: Not destroying VTI interfaces when booting before creating a new one
That code was added specifically to fix another problem that could happen when destroying an interface that doesn't e... Jim Pingle
07:04 AM Bug #10842 (Resolved): Not destroying VTI interfaces when booting before creating a new one
During the booting process, we call interface_ipsec_vti_configure() from interfaces.inc multiple times :
* From inte...
Martin VENÇON
09:14 AM Bug #10684 (Feedback): RFC 2136 incomplete options
PR has been merged. Thanks! Renato Botelho
09:06 AM Bug #10684 (Pull Request Review): RFC 2136 incomplete options
Jim Pingle
03:06 AM Bug #10684: RFC 2136 incomplete options
https://github.com/pfsense/pfsense/pull/4426 Viktor Gurov
09:14 AM Bug #10840 (Feedback): status.php: Sanitize Net-SNMP community
PR has been merged. Thanks! Renato Botelho
08:46 AM Bug #10840 (Pull Request Review): status.php: Sanitize Net-SNMP community
Jim Pingle
12:50 AM Bug #10840: status.php: Sanitize Net-SNMP community
https://github.com/pfsense/pfsense/pull/4425 Viktor Gurov
12:46 AM Bug #10840 (Resolved): status.php: Sanitize Net-SNMP community
Net-SNMP '<community>' must be sanitized:... Viktor Gurov
08:04 AM Revision 07bbe19b: RFC2136 zone option. Implements #10684
Viktor Gurov
06:01 AM pfSense Packages Feature #10841: Allow per Source/VLAN/Network individual black&whitelists
can be realized with "views": https://forum.netgate.com/topic/129365/bypassing-dnsbl-for-specific-ips Viktor Gurov
05:32 AM pfSense Packages Feature #10841 (New): Allow per Source/VLAN/Network individual black&whitelists
In corporate environments one needs to set individual black & whitelists per source (IP,network,vlan).
E.g:
Fin...
Stefan Bauer
05:58 AM Revision 50867e7d: Sanitize MaxMind GeoIP key. Implements #10797
Viktor Gurov
05:47 AM Revision 405f04f7: Sanitize Net-SNMP community. Fixes #10840
Viktor Gurov

08/18/2020

11:21 PM Revision d777d554: Merge pull request #4418 from vktg/frrsnmp245
Renato Botelho
11:19 PM Revision 9425c8b6: Merge pull request #4424 from vktg/disablevlantso
Renato Botelho
11:19 PM Revision 9798170c: Merge pull request #4423 from TheoSarrazin/master
Renato Botelho
11:18 PM Revision 05f08201: Merge pull request #4422 from rokkitlawnchair/master
Renato Botelho
11:18 PM Revision a23fce36: Merge pull request #4420 from vktg/domeneshopddns
Renato Botelho
11:16 PM Revision 19c8506c: Merge pull request #4378 from vktg/openvpncopyfix
Renato Botelho
11:15 PM Revision b21349bb: Merge pull request #4419 from vktg/vipinpvalidation
Renato Botelho
11:13 PM Revision e0c4bf66: Merge pull request #4417 from vktg/choparpkillfix
Renato Botelho
11:12 PM Revision 73ea85c6: Merge pull request #4416 from vktg/hostsfullipv6addr
Renato Botelho
11:11 PM Revision 7c21facb: Merge pull request #4415 from vktg/eclgptslice
Renato Botelho
11:10 PM Revision 2f23e737: Merge pull request #4413 from vktg/unboundstatusoutput
Renato Botelho
11:09 PM Revision 1b5f2590: Merge pull request #4411 from MariusRejdak/master
Renato Botelho
11:08 PM Revision 0adf8503: Merge pull request #4406 from somevar/master
Renato Botelho
11:07 PM Revision ed984b3a: Merge pull request #4410 from vktg/cpnamevalidation
Renato Botelho
11:05 PM Revision da1b4d6f: Merge pull request #4408 from vktg/qlaltq
Renato Botelho
11:04 PM Revision eadf7acb: Merge pull request #4407 from vktg/sanitizehaproxy
Renato Botelho
11:03 PM Revision 20c078aa: Merge pull request #4360 from vktg/gifbootbridgefix
Renato Botelho
11:02 PM Revision dc3ef005: Merge pull request #4396 from vktg/ipsecradiusgroup
Renato Botelho
10:59 PM Revision 05187d0e: Merge pull request #4403 from vktg/dummynetsysctlfix
Renato Botelho
10:57 PM Revision 2c44f228: Merge pull request #4404 from vktg/unboundrestartfix
Renato Botelho
07:26 PM Feature #10446: VIP address is not shown in firewall rules
Would be nice for controlling access to local services like HAProxy. Corey Boyle
06:21 PM pfSense Packages Bug #10815 (Feedback): FRR with SNMP AgentX option failed to start
PR has been merged. Thanks! Renato Botelho
06:20 PM Bug #10836 (Feedback): TSO option does not fully toggle TSO on the interface
PR has been merged. Thanks! Renato Botelho
06:19 PM Bug #10835 (Feedback): Verification on the interface group name length is not correct
PR has been merged. Thanks! Renato Botelho
06:18 PM Feature #10637 (Feedback): Turn of spell checking on package upgrade progress textarea
PR has been merged. Thanks! Renato Botelho
06:18 PM Feature #10826 (Feedback): Support for Domeneshop DDNS
PR has been merged. Thanks! Renato Botelho
06:16 PM Bug #10703 (Feedback): OpenVPN copy doesn't save auth_pass
PR has been merged. Thanks! Renato Botelho
06:15 PM Bug #7132 (Feedback): PPPoE IP Alias
PR has been merged. Thanks! Renato Botelho
06:14 PM Bug #7379 (Feedback): Virtual IPs/Proxy ARP: Not defined pid file on starting choparp.
PR has been merged. Thanks! Renato Botelho
06:12 PM Bug #8156 (Feedback): Prefix not being included in DNS entry registered by DHCP6 server
PR has been merged. Thanks! Renato Botelho
06:11 PM Bug #9097 (Feedback): ECL can't locate config.xml unless device is MBR-partitioned
PR has been merged. Thanks! Renato Botelho
06:10 PM Feature #10635 (Feedback): status.php: Add DNS Resolver configuration
PR has been merged. Thanks! Renato Botelho
06:09 PM Bug #10803 (Feedback): Invalid rules generated from AVPair on OpenVPN
PR has been merged. Thanks! Renato Botelho
06:08 PM Bug #10795 (Feedback): WebGUI "Dashboard -> Services Status" widget issue
PR has been merged. Thanks! Renato Botelho
06:07 PM Bug #10798 (Feedback): Unable to save CP zone named 'VIP'
PR has been merged. Thanks! Renato Botelho
06:05 PM Bug #10594 (Feedback): add QLogic 10 Gigabit Ethernet driver (qlxgb) to the ALTQ-capable list
PR has been merged. Thanks! Renato Botelho
06:04 PM Bug #10794 (Feedback): HAProxy Stats page credentials are not redacted in status.php
PR has been merged. Thanks! Renato Botelho
06:04 PM Bug #10524 (Feedback): Bridge that includes a GIF interface does not come up at boot
PR has been merged. Thanks! Renato Botelho
06:02 PM Feature #10748 (Feedback): Add support for limiting IPsec VPN access per user group via RADIUS
PR has been merged. Thanks! Renato Botelho
05:59 PM Bug #10780 (Feedback): net.inet.ip.dummynet.* values are ignored
PR has been merged. Thanks! Renato Botelho
05:57 PM Bug #10781 (Feedback): Incorrect env variables if admin user logged in via ssh
PR has been merged. Thanks! Renato Botelho
05:49 PM pfSense Docs Correction #10834 (Closed): Feedback on Virtualization — Virtualizing pfSense with VMware vSphere / ESXi
Thanks! This was fixed in https://github.com/pfsense/docs/commit/1a6b054411412f611a09d86fe29bf3d0d74545fd Jared Dillard
10:07 AM Feature #10839 (New): Add popular messengers to the Traffic Shaper Wizard
Zoom:
https://support.zoom.us/hc/en-us/articles/201362683-Network-firewall-or-proxy-server-settings-for-Zoom
QoS ma...
Viktor Gurov
07:55 AM Bug #10838 (Pull Request Review): mask options didn't apply to the sched limiter
Jim Pingle
05:13 AM Bug #10838: mask options didn't apply to the sched limiter
https://github.com/pfsense/pfsense/pull/4400 Viktor Gurov
05:13 AM Bug #10838 (Resolved): mask options didn't apply to the sched limiter
Using the GUI, the mask options didn't apply to the sched limiter.
from ipfw man:
The SCHED_MASK is used to ass...
Viktor Gurov
07:43 AM Feature #10837 (Pull Request Review): Update wizardapp.inc XBox and Wii ports
Jim Pingle
05:07 AM Feature #10837: Update wizardapp.inc XBox and Wii ports
https://github.com/pfsense/pfsense/pull/4414 Viktor Gurov
05:05 AM Feature #10837 (Resolved): Update wizardapp.inc XBox and Wii ports
These are the ports needed for any XBox live platform.
https://support.microsoft.com/en-us/help/4026770/xbox-open-th...
Viktor Gurov
06:20 AM pfSense Packages Bug #10436: softflowd no longer sends flow data after upgrade (v0.9.9_1 -> v1.0.0)
Mark Hassman wrote:
> Hi, after upgrading pfsense from v2.4.4_3 -> v2.4.5 (which included an upgrade of softflowd fr...
Chris Norris
04:16 AM Feature #10658 (Resolved): Allow to generate ECDSA certs on User Manager page
Danilo Zrenjanin
04:16 AM Feature #10658: Allow to generate ECDSA certs on User Manager page
Tested again on the:
2.5.0-DEVELOPMENT (amd64)
built on Tue Aug 18 01:03:19 EDT 2020
It looks fine.
Probab...
Danilo Zrenjanin
03:16 AM Feature #10658: Allow to generate ECDSA certs on User Manager page
There is some issue with the patch. After adding the patch I wasn't able to access to system_usermanager.php. Please ... Danilo Zrenjanin
02:54 AM Feature #10698 (Resolved): Allow to select EoIP protocol
Tested on CE 2.4.5-p1 version. After adding the patch, I was able to select IPoE under protocol drop-down menu (Firew... Danilo Zrenjanin
02:36 AM Feature #10727 (Resolved): Limiter bw type in Mbit/s
Tested the patch on CE 2.4.5-p1. After adding the patch, Mbit/s is set as a default Bw type for limiters. Danilo Zrenjanin

08/17/2020

02:23 PM Revision cd80be80: Toggle VLAN_HWTSO when TSO is toggled in the GUI. Fixes #10836
Viktor Gurov
01:06 PM Bug #10836 (Pull Request Review): TSO option does not fully toggle TSO on the interface
Jim Pingle
09:25 AM Bug #10836: TSO option does not fully toggle TSO on the interface
https://github.com/pfsense/pfsense/pull/4424 Viktor Gurov
01:06 PM pfSense Packages Bug #10832 (Pull Request Review): Bind DNSSEC validation "deselected" not disabling DNSSEC validation
Jim Pingle
09:10 AM pfSense Packages Bug #10832: Bind DNSSEC validation "deselected" not disabling DNSSEC validation
https://github.com/pfsense/FreeBSD-ports/pull/919 Viktor Gurov
11:05 AM Feature #7092: Kernel modules for alternate congestion control algorithms
there is no any '/boot/kernel/cc_*' or 'sysctl net.inet.tcp.cc.available' (except newreno) on 2.4.5-p1 and 2.5.0.a.20... Viktor Gurov
05:35 AM Bug #10827 (Feedback): Cannot add or delete separators when no rules are present
I couldn't reproduce the issue on the CE image.
Here is what I found irregular:
1)If I first create a separator ...
Danilo Zrenjanin
04:36 AM Bug #10752 (Resolved): 1:1 NAT issue if Internal IP has VIPs
Reproduced the issue. After adding the patch, filter reloaded without issues. Danilo Zrenjanin

08/15/2020

06:15 PM Bug #10836 (Resolved): TSO option does not fully toggle TSO on the interface
I am not 100% this is a bug, it may be intended behaviour. But regardless I will attach my patch.
The VLAN_HWTSO ...
Chris Collins

08/14/2020

05:07 PM Revision 2983214c: Change maxlenght of interface group name. Fixes #10835
Théo Sarrazin
12:10 PM Bug #10835 (Pull Request Review): Verification on the interface group name length is not correct
Jim Pingle
12:09 PM Bug #10835: Verification on the interface group name length is not correct
Change maxlenght of interface group name:
https://github.com/pfsense/pfsense/pull/4423
Théo Sarrazin
12:04 PM Bug #10835 (Resolved): Verification on the interface group name length is not correct
ifconfig take group name with less than 15 characters, but in the file interfaces_groups_edit.php, we can find the fo... Théo Sarrazin
05:36 AM pfSense Docs Correction #10834 (Closed): Feedback on Virtualization — Virtualizing pfSense with VMware vSphere / ESXi
*Page:* https://docs.netgate.com/pfsense/en/latest/virtualization/virtualizing-pfsense-with-vmware-vsphere-esxi.html
...
Gustav Andersson

08/13/2020

11:53 PM Bug #10833 (New): unbound exits on configuration error when link status flaps on LAN interface
I have pfSense installed at home on a small, old, core2duo-based machine. It does pretty typical home-router duty; t... John Hood
09:13 AM Bug #10830 (Not a Bug): "pkg upgrade" gives back "Shared object "libarchive.so.7" not found, required by "pkg""
You must have set your updates to come from 2.5.0 snapshots. With a mismatched version of base and pkg, use pkg-static. Jim Pingle
03:12 AM Bug #10830 (Not a Bug): "pkg upgrade" gives back "Shared object "libarchive.so.7" not found, required by "pkg""
after trying an upgrade from commandline "pkg" was upgraded from version 1.13.2 to 1.14.6. Now calling "pkg" tells me... Thomas Schweikle
09:09 AM pfSense Packages Feature #10831: Integration of nntp-proxy into pfsense
One could maybe make a case for the proxy, but just barely.
Caching is definitely not happening.
Jim Pingle
03:28 AM pfSense Packages Feature #10831 (New): Integration of nntp-proxy into pfsense
Would it be possible to integrate some nntp-proxy into pfSense? Would be nice to have it work with nntp servers this ... Thomas Schweikle
09:02 AM Bug #10829 (Duplicate): Trying to upgrade packages hangs at "Please wait while the update system initializes"
Most likely the same as #10610 (though the bug mentions FRR specifically, it affects multiple packages) Jim Pingle
03:07 AM Bug #10829 (Duplicate): Trying to upgrade packages hangs at "Please wait while the update system initializes"
From the latest stable version trying to upgrade any package leads to "Please wait while the update system initialize... Thomas Schweikle
08:58 AM Feature #10637 (Pull Request Review): Turn of spell checking on package upgrade progress textarea
Jim Pingle
06:54 AM Feature #10637: Turn of spell checking on package upgrade progress textarea
Fix: https://github.com/pfsense/pfsense/pull/4422 Heiko Mischer
04:14 AM Bug #5258 (Resolved): Using pppoe WAN with ipv6 SLAAC, reply-to rules use the wrong interface address
fixed in #9324 Viktor Gurov
03:37 AM pfSense Packages Bug #10832 (Resolved): Bind DNSSEC validation "deselected" not disabling DNSSEC validation
Bind global settings page, "Forwarder Configuration" - DNSSEC Validation setting.
Bug: The DNSSEC Validation tick-...
Dave Tickem
02:59 AM Revision 750dc0bd: Implements #10637
rokkitlawnchair

08/12/2020

07:45 PM Revision f1c8242d: Accommodate encryption_password when updating ACB config
Steve Beaver
12:03 PM Feature #9536: Support dynamic prefix in DHCPv6 Server
This seems to be at least related to issue 6626 -> https://redmine.pfsense.org/issues/6626
Heiko Mischer
12:01 PM Feature #6240: vxlan driver
WebGUI:
https://github.com/pfsense/pfsense/pull/4421
Viktor Gurov
11:45 AM Bug #10828 (Rejected): Sync of rule comments has bugs
Fixed in #1478 Viktor Gurov
11:15 AM Bug #10828 (Rejected): Sync of rule comments has bugs
A rule comment containing characters as [ / is not properly synced to standby.
If the comment on the primary is e....
Ph. T
10:12 AM pfSense Packages Bug #10824: BIND shutdown - dynamic zones, unclean shutdown causes startup to not load zones
Thanks, updated Viktor Gurov
08:58 AM pfSense Packages Bug #10824: BIND shutdown - dynamic zones, unclean shutdown causes startup to not load zones
Viktor Gurov wrote:
> Fix:
> https://github.com/pfsense/FreeBSD-ports/pull/917
Does not fix the issue - I have n...
Dave Tickem
08:35 AM pfSense Packages Bug #10823 (Pull Request Review): named.conf "controls" section missing IPv6 localhost on IPv6 enabled PFsense - breaking rndc
Jim Pingle
03:37 AM pfSense Packages Bug #10823: named.conf "controls" section missing IPv6 localhost on IPv6 enabled PFsense - breaking rndc
Viktor Gurov wrote:
> Fix:
> https://github.com/pfsense/FreeBSD-ports/pull/918
Tested, manually updating bind.in...
Dave Tickem
02:58 AM pfSense Packages Bug #10823: named.conf "controls" section missing IPv6 localhost on IPv6 enabled PFsense - breaking rndc
Fix:
https://github.com/pfsense/FreeBSD-ports/pull/918
Viktor Gurov
02:21 AM pfSense Packages Bug #10823: named.conf "controls" section missing IPv6 localhost on IPv6 enabled PFsense - breaking rndc
Sure ! "/cf/named/etc/namedb/rndc.conf" - is created:... Dave Tickem
12:30 AM pfSense Packages Bug #10823: named.conf "controls" section missing IPv6 localhost on IPv6 enabled PFsense - breaking rndc
Dave Tickem wrote:
> Agreed. Error on my part. Bug is wrong/bad/incorrect. Clean build :
>
> [...]
>
> Have be...
Viktor Gurov
05:07 AM Bug #10820: Extremely low speeds to vm's when using paravirtualized (xn*) interfaces on XenServer/XCP-ng
For future reference if someone comes across this issue, what was happening was that devices on my internal network w... Ricardo Mendes

08/11/2020

07:42 PM Revision 55cbdcb0: Improved ACB config update by requiring only a single visit to the system
Steve Beaver
05:27 PM Bug #10827 (Resolved): Cannot add or delete separators when no rules are present
If separators exist without any rules, they will reappear after being deleted and saved. The same behavior can be see... Max Leighton
04:12 PM Revision 6c85268f: Correct CRON functionality and move to pfsense-utils.inc
Steve Beaver
03:26 PM Revision e582c517: Rorganize ACB/Cron functions - phase 1
Steve Beaver
11:59 AM pfSense Packages Bug #10823: named.conf "controls" section missing IPv6 localhost on IPv6 enabled PFsense - breaking rndc
Agreed. Error on my part. Bug is wrong/bad/incorrect. Clean build :... Dave Tickem
02:31 AM pfSense Packages Bug #10823 (Feedback): named.conf "controls" section missing IPv6 localhost on IPv6 enabled PFsense - breaking rndc
unable to reproduce, it uses 127.0.0.1 for server connections by default
from https://www.freebsd.org/cgi/man.cgi?...
Viktor Gurov
09:52 AM pfSense Docs Correction #10825 (Resolved): Feedback on Introduction — Common Deployments
Merged Jim Pingle
01:28 AM pfSense Docs Correction #10825: Feedback on Introduction — Common Deployments
https://gitlab.netgate.com/docs/pfSense-book/-/merge_requests/7 Viktor Gurov
09:51 AM pfSense Packages Bug #10824 (Pull Request Review): BIND shutdown - dynamic zones, unclean shutdown causes startup to not load zones
Jim Pingle
03:52 AM pfSense Packages Bug #10824: BIND shutdown - dynamic zones, unclean shutdown causes startup to not load zones
Viktor Gurov wrote:
> Fix:
> https://github.com/pfsense/FreeBSD-ports/pull/917...
Dave Tickem
02:50 AM pfSense Packages Bug #10824: BIND shutdown - dynamic zones, unclean shutdown causes startup to not load zones
Fix:
https://github.com/pfsense/FreeBSD-ports/pull/917
Viktor Gurov
09:34 AM pfSense Packages Bug #10737 (Resolved): FRR attempts to cycle IPsec VTI interfaces even when disabled/not running
I couldn't replicate the isuse with the latest FRR 0.6.7_4 Version installed. It works as expected. Danilo Zrenjanin
09:21 AM Feature #10826 (Pull Request Review): Support for Domeneshop DDNS
Jim Pingle
04:17 AM Feature #10826: Support for Domeneshop DDNS
https://github.com/pfsense/pfsense/pull/4420 Viktor Gurov
03:24 AM Feature #10826 (Resolved): Support for Domeneshop DDNS
Domeneshop is the largest registrar for .no (Norway) domains with over 40% of all .no domains. Source (in Norwegian):... Idar Lund
09:14 AM Revision 4d6cc223: Domeneshop DynDNS support. Implements #10826
Viktor Gurov
07:25 AM Bug #9107 (Closed): New AutoConfigBackup - Cannot Access Settings When Not Connected to Internet
no such issue on 2.4.5-p1 and 2.5.0.a.20200811.0050 Viktor Gurov

08/10/2020

02:56 PM pfSense Docs Correction #10825 (Resolved): Feedback on Introduction — Common Deployments
*Page:* https://docs.netgate.com/pfsense/en/latest/book/intro/common-deployments.html#perimeter-firewall
*Feedback...
Michael Woolweaver
08:54 AM pfSense Packages Feature #10665 (Pull Request Review): Manual OSPF neighbor definitions
Jim Pingle
02:40 AM pfSense Packages Bug #10426: Filer must validate that File name is uniq
Hi, any update on the issue? DRago_Angel [InV@DER]
02:39 AM pfSense Packages Feature #10600: Add support for pfBlockerNG "Action list" feature
Hi, any update on the issue? Thanks. DRago_Angel [InV@DER]

08/09/2020

02:06 PM Feature #1205: VPN: User-based / Group-based firewall rules
see also #8836 Viktor Gurov
03:16 AM Feature #1205: VPN: User-based / Group-based firewall rules
I think it must be something like https://conexti.com.br/userauth/
I personally need such features for provide netwo...
Mikhail Makhin
11:42 AM pfSense Packages Bug #10824: BIND shutdown - dynamic zones, unclean shutdown causes startup to not load zones
Sorry, very poor bug. Affected version is PFSENSE 2.4.5p1 and BIND 9.14_7. Dave Tickem
10:54 AM pfSense Packages Bug #10824 (Resolved): BIND shutdown - dynamic zones, unclean shutdown causes startup to not load zones
Bind is killed quite TERMinally in the /usr/local/etc/rc.d/named.sh script - with a SIGTERM. This causes the server t... Dave Tickem
11:42 AM pfSense Packages Bug #10823: named.conf "controls" section missing IPv6 localhost on IPv6 enabled PFsense - breaking rndc
Sorry, very poor bug. Category is BIND. Affected version is PFSENSE 2.4.5p1 and BIND 9.14_7. Dave Tickem
10:50 AM pfSense Packages Bug #10823 (Resolved): named.conf "controls" section missing IPv6 localhost on IPv6 enabled PFsense - breaking rndc
Generator for {/cf/named}/etc/namedb/named.conf needs updating to include ::1 as well as 127.0.0.1 on PFSense instanc... Dave Tickem
09:20 AM pfSense Packages Bug #10791: Valid (vlan)interfaces do not get vif reporting "Invalid phyint address"
I am testing an early PIMD-3-beta at the moment. I do that in cooperation with the PIMD-maintainer.
Version3 does...
Louis B
08:05 AM pfSense Docs Correction #9310: Appliances with internal switch need the MAC Address section of their Getting Started guides updated
This only applies to the SG-1100 and SG-7100 since they are the only devices with a switch port as the WAN by default. Steve Wheeler

08/08/2020

10:15 AM Revision 024a5ff8: OpenVPN copy auth_pass. Fixes #10703
Viktor Gurov
10:04 AM Bug #10822 (New): Deprecated IPv6 prefix won't be announced as deprecated to clients
After a periodic reset, or unplug/plugin of the WAN connection, the old IPv6 prefix won't be announced as deprecated ... Jan Kiele
09:28 AM pfSense Packages Feature #10665: Manual OSPF neighbor definitions
https://github.com/pfsense/FreeBSD-ports/pull/916 Viktor Gurov

08/07/2020

04:18 PM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
Ticket is marked for Feedback. Feedback is being provided. Izaac Falken
10:16 AM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
If you want to discuss it, take it to the forum. As I said, there are many people using it with success. It doesn't a... Jim Pingle
10:05 AM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
Jim Pingle wrote:
> Except that it does work, and thousands of people are using is successfully
Are they? Or are th...
Izaac Falken
07:54 AM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
Except that it does work, and thousands of people are using is successfully, and pulling it would cause much more har... Jim Pingle
07:38 AM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
Did this. Within 48 hours I have six overlapping phase 2s and am in the #11000's in IPsec IDs.
I'm pretty sure it's ...
Izaac Falken
02:59 PM pfSense Docs Correction #10821 (New): Use neutral language alternatives
More info: https://www.zdnet.com/article/linux-team-approves-new-terminology-bans-terms-like-blacklist-and-slave/
...
Jared Dillard
02:04 PM Bug #10814: OpenVPN UDP multihome fails when connecting to an IP that is not logically closest.
The FreeBSD patch has been merged into head (on FreeBSD), will be MFCd soon so it's probably safe to put a 2.5.0 targ... Jim Pingle
10:02 AM Bug #7132 (Pull Request Review): PPPoE IP Alias
Jim Pingle
03:48 AM Bug #7132: PPPoE IP Alias
Extra input validation:
https://github.com/pfsense/pfsense/pull/4419
Viktor Gurov
08:37 AM Revision d96e6808: Virtual IPs interface type/mode check. Issue #7132
Viktor Gurov
05:09 AM Feature #4632: Support for Multipath TCP (MPTCP)
Telekom has started offering MTCP in Germany, and given the abysmal situation with broadband in the country we would ... Yury Zaytsev

08/06/2020

03:45 PM Bug #10820: Extremely low speeds to vm's when using paravirtualized (xn*) interfaces on XenServer/XCP-ng
Hi,
A new update. the networks were configured for vlans configured at hetzner while using hetzner vswitch.
Creat...
Ricardo Mendes
02:35 PM Bug #10820: Extremely low speeds to vm's when using paravirtualized (xn*) interfaces on XenServer/XCP-ng
Hi Jim thank you for your quick reply.
Regarding my configuration/environment, its a new setup with XCP-ng 8.1 at ...
Ricardo Mendes
01:52 PM Bug #10820 (Needs Patch): Extremely low speeds to vm's when using paravirtualized (xn*) interfaces on XenServer/XCP-ng
If the patches get accepted into FreeBSD, they will make their way into pfSense down the road. Though I find it diffi... Jim Pingle
01:35 PM Bug #10820 (Needs Patch): Extremely low speeds to vm's when using paravirtualized (xn*) interfaces on XenServer/XCP-ng
Hi,
I am experiencing an issue where I have extremely low speeds while accessing vm's behind a pfsense on a virtua...
Ricardo Mendes
02:58 PM Bug #10819: Gateway group configuration for multi-wan ignored after upgrade to 2.5.0-DEVELOPMENT image
Jim Pingle wrote:
> The bug you linked is already fixed in 2.4.5-p1 and it was unlikely to be related to anything ex...
Adrian G
10:53 AM Bug #10819 (Rejected): Gateway group configuration for multi-wan ignored after upgrade to 2.5.0-DEVELOPMENT image
The bug you linked is already fixed in 2.4.5-p1 and it was unlikely to be related to anything except accessing the GU... Jim Pingle
10:27 AM Bug #10819 (Rejected): Gateway group configuration for multi-wan ignored after upgrade to 2.5.0-DEVELOPMENT image
Hello! I recently upgraded to 2.5.0-DEV to overcome this issue: https://redmine.pfsense.org/issues/8987, which was to... Adrian G
10:13 AM pfSense Packages Feature #10818 (Resolved): UDP Broadcast Relay
Current packages like Avahi and PIMD can help users cast across VLANs, which is great for HOME/GUEST to IOT type scen... Mark Whitworth
05:45 AM Feature #6240: vxlan driver
The PR is trivial but incomplete. It just adds the kernel module.
Unless someone work on the GUI part, this featu...
Luiz Souza

08/05/2020

08:58 PM Bug #10610: Package upgrade or reinstall hangs indefintely on the console
Stefan Beckers wrote:
> Same issue here. I can reproduce this reliably (any of upgrade, reinstall or fresh install) ...
Christian Borchert
07:23 PM pfSense Packages Bug #10817 (Duplicate): FRR upgrade/install process hangs
Duplicate of #10610 Jim Pingle
06:28 PM pfSense Packages Bug #10817 (Duplicate): FRR upgrade/install process hangs
Installing or upgrading to FRR 0.6.7_4 results in a process hang, see attached photos
CLI hang is shown after the ...
Christian Borchert
02:42 PM pfSense Packages Feature #10816 (Feedback): Allow FRR BGP Neighbors to be active in both IPv4 and IPv6
Added in https://github.com/pfsense/FreeBSD-ports/commit/cae5ee237cfabc90ea5ef4dfd480acfc9055e26f Jim Pingle
02:36 PM pfSense Packages Feature #10816 (Resolved): Allow FRR BGP Neighbors to be active in both IPv4 and IPv6
BGP can carry routes for both IPv4 and IPv6 to a single neighbor of either type. Currently the code only activates th... Jim Pingle
09:09 AM Bug #7379 (Pull Request Review): Virtual IPs/Proxy ARP: Not defined pid file on starting choparp.
Jim Pingle

08/04/2020

04:07 PM Revision 18208c61: FRR SNMP module. Fixes #10815
Viktor Gurov
02:01 PM Revision e984ff68: Restart choparp on VIP change. Fixes #7379
Viktor Gurov
11:24 AM pfSense Packages Bug #10815 (Pull Request Review): FRR with SNMP AgentX option failed to start
Jim Pingle
11:21 AM pfSense Packages Bug #10815: FRR with SNMP AgentX option failed to start
FRR SNMP module for 2.4.5 branch:
https://github.com/pfsense/pfsense/pull/4418
Viktor Gurov
11:02 AM pfSense Packages Bug #10815 (Resolved): FRR with SNMP AgentX option failed to start
https://forum.netgate.com/topic/155795/frr-0-6-7_3-enable-snmp-agentx
frr for pfSense 2.4.5-p1 doesn't have snmp m...
Viktor Gurov
10:17 AM Bug #7132: PPPoE IP Alias
PPPoE requires a destination address:... Viktor Gurov
09:02 AM Bug #7379: Virtual IPs/Proxy ARP: Not defined pid file on starting choparp.
aLexander Panfilov wrote:
> New Bug after applying the patch:
> There are several PoxyARP VIPs. Open one of them to...
Viktor Gurov
08:35 AM Bug #8156 (Pull Request Review): Prefix not being included in DNS entry registered by DHCP6 server
Jim Pingle
03:36 AM Bug #8156: Prefix not being included in DNS entry registered by DHCP6 server
https://github.com/pfsense/pfsense/pull/4416 Viktor Gurov
08:33 AM Bug #9097 (Pull Request Review): ECL can't locate config.xml unless device is MBR-partitioned
Jim Pingle
02:29 AM Bug #9097: ECL can't locate config.xml unless device is MBR-partitioned
https://github.com/pfsense/pfsense/pull/4415 Viktor Gurov
08:31 AM Revision 47f05aa1: Full IPv6 host address for DHCP6 static entries. Fixes #8156
Viktor Gurov
08:21 AM Bug #10814 (Needs Patch): OpenVPN UDP multihome fails when connecting to an IP that is not logically closest.
Jim Pingle
08:16 AM Bug #10814 (Needs Patch): OpenVPN UDP multihome fails when connecting to an IP that is not logically closest.
If you connect to the external WAN IP from an OpenVPN client on an internal interface of a pfSense install running an... Steve Wheeler
07:18 AM Revision 681d099c: ECL GPT partitions support. Fixes #9097
Viktor Gurov
02:51 AM Feature #3559 (Resolved): add option for backup ddns ( dynamic dns ) in restore area
works as expected on 2.5.0.a.20200803.1850 Viktor Gurov
02:34 AM Revision 708b2b0b: Update wizardapp.inc
These are the ports needed for any xbox live platform.
https://support.microsoft.com/en-us/help/4026770/xbox-open-the...
Joseph Turner

08/03/2020

04:37 PM Revision 9edd02bb: status.php: Add DNS Resolver configuration. Implements #10635
Viktor Gurov
03:51 PM Bug #10813: Dashboard - dynamic CPU speed element disappears and reappears [cosmetic / annoying]
OK, that makes some amount of sense to me. But it still results in the text in the dashboard regularly shifting up an... Braden McGrath
03:36 PM Bug #10813 (Not a Bug): Dashboard - dynamic CPU speed element disappears and reappears [cosmetic / annoying]
It's done that way on purpose because it's redundant to show the CPU speed when it's at maximum, since the max CPU sp... Jim Pingle
03:32 PM Bug #10813 (Not a Bug): Dashboard - dynamic CPU speed element disappears and reappears [cosmetic / annoying]
I've only tested this on 2.4.5-p1 but I believe it's been around for a while. I am on amd64 arch, with an Atom C2558.... Braden McGrath
12:30 PM Feature #10807: Allow users to show advanced log filter by default in Status->System Logs->Firewall
Jim Pingle wrote:
> Already possible. System > General, check "Log Filter". Also possible in per-user settings.
S...
e 1/1
10:01 AM Feature #10807 (Rejected): Allow users to show advanced log filter by default in Status->System Logs->Firewall
Already possible. System > General, check "Log Filter". Also possible in per-user settings. Jim Pingle
12:27 PM Feature #10808: System logs->Firewall->Advanced Log Filter - more UI functionality for choosing interfaces
Jim Pingle wrote:
> Doing a drop down is not going to scale well and also prevent users from using things like regex...
e 1/1
10:11 AM Feature #10808 (Rejected): System logs->Firewall->Advanced Log Filter - more UI functionality for choosing interfaces
Doing a drop down is not going to scale well and also prevent users from using things like regex in the box to match ... Jim Pingle
11:14 AM Bug #10812 (Resolved): Traffic graph shows 2X the actual traffic on VLAN interfaces.
#3314 is back again on, as of today, latest snapshot... Nano Caiordo
10:26 AM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
Side 1: IKEv2, Rekey configured, Reauth disabled, child SA close action set to restart/reconnect
Side 2: IKEv2, Reke...
Jim Pingle
08:04 AM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
So is there a final, required set of baseline versions and recommended configuration which can do into the docs? Or ... Izaac Falken
10:22 AM Feature #10635 (Pull Request Review): status.php: Add DNS Resolver configuration
Jim Pingle
08:29 AM Feature #10811 (Closed): Randomize time of scheduled AutoConfigBackup runs
It looks like the backup server is becoming occasionally overloaded on the hour because all backups around the world ... Chris Linstruth
04:59 AM Bug #10792: Crash when switching interface off and on again in cohesion with multicast
I did retest interface stability. The situation is much better now. I can not reproduce crashes any more. Louis B
04:57 AM Feature #10747 (Resolved): Captive Portal IDN hostname support
works as expected on 2.5.0.a.20200802.1850 Viktor Gurov
01:33 AM pfSense Packages Bug #10763 (Resolved): Incorrect link to frr_bgp.xml
menu entry link is OK in the latest FRR pkg Viktor Gurov

08/02/2020

10:05 PM Bug #10810 (Rejected): LoadBalancer Virtual Servers Edit web form does not allow entry of Port Alias text
The built-in load balancer has been deprecated. It has already been removed from 2.5.0, it will not receive further d... Jim Pingle
10:01 PM Bug #10810 (Rejected): LoadBalancer Virtual Servers Edit web form does not allow entry of Port Alias text
Edit Load Balancer - Virtual Server Entry web form problem.
Trying to enter in a port alias as directed, however, on...
Patrick Best
01:19 PM Bug #10671: pfsense 2.4.5_1 does not boot on Gen2 2012R2 HyperV VM
The old kernel can be booted as Jan stated by entering
boot kernel.old
when system is stuck in bootloader.
M...
Ernesto Rey
12:30 PM Bug #10671: pfsense 2.4.5_1 does not boot on Gen2 2012R2 HyperV VM
Stumbled into the same issue. Ernesto Rey
09:40 AM Feature #10635: status.php: Add DNS Resolver configuration
https://github.com/pfsense/pfsense/pull/4413 Viktor Gurov
04:01 AM Bug #10758 (Closed): Group Authentication is never used
see fix in #10748 Viktor Gurov
02:47 AM Feature #2358: NAT64 support
IPFW NAT64 kernel support:
https://github.com/pfsense/FreeBSD-src/pull/35
Viktor Gurov
12:18 AM Bug #10803: Invalid rules generated from AVPair on OpenVPN
also fixed in #10454 Viktor Gurov

08/01/2020

06:25 AM pfSense Packages Feature #10809 (Resolved): IDS/IPS - Notifications when new rule categories are released
Please allow users to enable system notifications when new rule categories appear.
As IDS rules are not enabled as t...
e 1/1
04:40 AM Feature #10808 (Rejected): System logs->Firewall->Advanced Log Filter - more UI functionality for choosing interfaces
In Status->System Logs->Firewall->Normal View and Dynamic View please improve the "Interface" field in the Advanced L... e 1/1
04:31 AM Feature #10807 (Rejected): Allow users to show advanced log filter by default in Status->System Logs->Firewall
Please add an option for Status->System Logs->Firewall so that when one opens either "Normal View" or "Dynamic View",... e 1/1

07/31/2020

05:51 PM Bug #10806 (Resolved): armada_thermal fails during device_attach
SG-3100 is unable to read the temperature from sysctl, as the oid doesn't exist, because the driver fails to attach d... Daniel Gordon
03:13 PM Feature #10805 (New): Intel QAT (QuickAssist) encryption support for PfSense
Please consider adding Intel QAT (QuickAssist) acceleration to PfSense. Nearly all of Netgate's hardware supports it ... Adam Goldberg
01:25 PM Bug #10800: Multi WAN Load Balancing does not work on 2.5.0.a.20200729.0650
Dmitry Fill wrote:
> Version: 2.5.0.a.20200729.0650
>
> Tried to follow documentation to setup multi WAN with Lo...
Adam Goldberg
12:17 PM Feature #8786: Wireguard VPN
Take as much time as you need to get it right. I would rather have a stable, in-kernel implementation than a buggy, ... Soren Stoutner
11:57 AM Feature #8786: Wireguard VPN
There certainly is reason. We're working on the in-kernel implementation and won't be wasting our time on unstable us... Jim Pingle
11:44 AM Feature #8786: Wireguard VPN
wireguard-go exists on FreeBSD. While it may not be in-kernel, it's a userspace implementation from the same project.... Anonymous
10:29 AM Bug #10803 (Pull Request Review): Invalid rules generated from AVPair on OpenVPN
Jim Pingle
03:49 AM Bug #10803: Invalid rules generated from AVPair on OpenVPN
Pull request: https://github.com/pfsense/pfsense/pull/4411 Marius Rejdak
03:44 AM Bug #10803 (Resolved): Invalid rules generated from AVPair on OpenVPN
AVPair rule:
ip:inacl#1=permit ip 10.1.0.0 255.255.0.0 10.2.0.0 255.255.0.0 range 8000 8001
Expected rule:
pass ...
Marius Rejdak
08:56 AM pfSense Plus Feature #10804: Interface Status page information for switch uplinks may be replaced by switch port data when media state monitoring is set
Fixing the subject and adding some notes:
This happens if "Switch Port" on Interfaces > LAN (or whichever interfac...
Jim Pingle
08:49 AM pfSense Plus Feature #10804 (Resolved): Interface Status page information for switch uplinks may be replaced by switch port data when media state monitoring is set
Like in #10793#note-9 written status->interface for mvneta1 shows mixed data from mvneta1 and switch port 1.
Make ...
Grischa Zengel
08:46 AM Revision c6a9d32e: Fix OpenVPN AVPair network/netmask output. Issue #10803
Marius Rejdak
08:26 AM Bug #10793: SNMP: Netgate SG-3100 shows wrong speed
I agree, it's not a bug.
I forgot that this switch config for tracking ports exists because I only used it once at f...
Grischa Zengel
06:33 AM Bug #7020 (Feedback): <Hostname> is omitted when sending logs on syslog
An RFC 5424 option was added to 2.5.0 almost a year ago, you can test it there: #9808 Jim Pingle
02:47 AM Bug #7020: <Hostname> is omitted when sending logs on syslog
Jim Pingle wrote:
> If it's a bug, it's a bug in FreeBSD -- we use their syslogd and that's how it behaves. The defa...
Darren Spruell

07/30/2020

05:56 PM Feature #10802 (New): Seperator for DHCP Static Mapped leases
It may be nice to allow the similar separator functionality from the firewall rules page, on the status_dhcp_leases.p... Daniel Johnson
04:20 PM Bug #10800: Multi WAN Load Balancing does not work on 2.5.0.a.20200729.0650
Thank you Jim. I got redirected here after clicking link "Give Feedback" on documentation section of "Multiple WAN Co... Dmitry Fill
07:38 AM Bug #10800 (Rejected): Multi WAN Load Balancing does not work on 2.5.0.a.20200729.0650
There is not enough information here to rule out a configuration issue or a problem with your test methodology. This ... Jim Pingle
12:32 AM Bug #10800 (Rejected): Multi WAN Load Balancing does not work on 2.5.0.a.20200729.0650
Version: 2.5.0.a.20200729.0650
Tried to follow documentation to setup multi WAN with Load Balancing
1. Two WAN...
Dmitry Fill
03:57 PM Revision f2b9ea9a: Revise get_services() to include the current service state in the returned array. This saves having to get the list of services three times in order to draw the status_services web page
Steve Beaver
03:13 PM Bug #10793: SNMP: Netgate SG-3100 shows wrong speed
That doesn't happen by default. You probably selected "Port 1" as the switch port to monitor under Interfaces > LAN_1... Jim Pingle
03:06 PM Bug #10793: SNMP: Netgate SG-3100 shows wrong speed
No, no problem.
But you said mvneta1 is always at 2500MBit but pfsense shows 100MBit like picture 2020-07-30 21-24...
Grischa Zengel
02:55 PM Bug #10793: SNMP: Netgate SG-3100 shows wrong speed
"LAN Uplink" is mvneta1. The others are the individual switch ports, not mvneta* interfaces.
With the built-in bsn...
Jim Pingle
02:29 PM Bug #10793: SNMP: Netgate SG-3100 shows wrong speed
It looks like it reflects speed from 1st switch port or max link speed on switch.
!2020-07-30 21-24-58.png!
!2020...
Grischa Zengel
01:43 PM Bug #10793: SNMP: Netgate SG-3100 shows wrong speed
Grischa Zengel wrote:
> Is this relevant?
> mvneta1 supports only 2500MBit but connects with 100MBit.
I do not s...
Jim Pingle
01:39 PM Bug #10793 (Resolved): SNMP: Netgate SG-3100 shows wrong speed
Looks good now.... Jim Pingle
02:24 PM Bug #10801 (Not a Bug): Send mail on gw down
Not nearly enough information here to say it's a bug, and this site is not for support or diagnostic discussion.
F...
Jim Pingle
02:18 PM Bug #10801 (Not a Bug): Send mail on gw down
Hi.
I used to get email when gw was offline. For example pppoe dropped, gw went down and I got an email.
Now on 2...
Greg M
02:19 PM Bug #10773: if_em VLAN interfaces wont pass traffic after reboot
Looks like this fix was just MFCed to 12-stable under MFC r362063. So it should be fixed next time pfSense is rebased. Steve Harrington
11:17 AM Bug #10799: Dynamic DNS auto update
My bad. It is indeed not a bug. The dynamic DNS feature reacts to change of IP on some interface, not on the registra... Ike Doz
07:47 AM Bug #10799: Dynamic DNS auto update
Sorry about that, I posted in the forum. Ike Doz
07:37 AM Bug #10799 (Not a Bug): Dynamic DNS auto update
This site is not for support or diagnostic discussion.
For assistance in solving problems, please post on the "Net...
Jim Pingle
07:34 AM Bug #10795 (Pull Request Review): WebGUI "Dashboard -> Services Status" widget issue
Jim Pingle

07/29/2020

04:40 PM Bug #10799 (Not a Bug): Dynamic DNS auto update
I have already asked reddit.com/r/pfsense and IRC but I couldn't solve my issue so I am asking here.
I have set up...
Ike Doz
02:57 PM Revision 6947a80a: Captive Portal name validation for XML tags. Fixes #10798
Viktor Gurov
12:02 PM Bug #10793 (Feedback): SNMP: Netgate SG-3100 shows wrong speed
Fixed.
Please test with the next snapshot.
Luiz Souza
10:10 AM Bug #10798 (Pull Request Review): Unable to save CP zone named 'VIP'
Jim Pingle
09:59 AM Bug #10798: Unable to save CP zone named 'VIP'
https://github.com/pfsense/pfsense/pull/4410 Viktor Gurov
08:49 AM Bug #10798: Unable to save CP zone named 'VIP'
It's because the zone name is used as an XML tag in the config, but "vip" is a listtag, meaning it gets treated like ... Jim Pingle
08:40 AM Bug #10798: Unable to save CP zone named 'VIP'
config.xml after creating 'VIP' zone:... Viktor Gurov
07:18 AM Bug #10798 (Resolved): Unable to save CP zone named 'VIP'
https://forum.netgate.com/topic/155549/captive-portal-settings-not-saved:
I did more tests, tried to add several cap...
Viktor Gurov
08:45 AM Bug #10797 (Pull Request Review): status.php: Sanitize MaxMind GeoIP key
Jim Pingle
07:12 AM Bug #10797: status.php: Sanitize MaxMind GeoIP key
https://github.com/pfsense/pfsense/pull/4409 Viktor Gurov
05:27 AM Bug #10797 (Resolved): status.php: Sanitize MaxMind GeoIP key
maxmind_geoipdb_key - Suricata
maxmind_key - pfBlockerNG, NTOPNG
Viktor Gurov
08:42 AM Bug #10594 (Pull Request Review): add QLogic 10 Gigabit Ethernet driver (qlxgb) to the ALTQ-capable list
Jim Pingle
02:26 AM Bug #10594: add QLogic 10 Gigabit Ethernet driver (qlxgb) to the ALTQ-capable list
Correct interface name is 'qlX':
https://github.com/pfsense/pfsense/pull/4408
Viktor Gurov
08:41 AM Bug #10794 (Pull Request Review): HAProxy Stats page credentials are not redacted in status.php
Jim Pingle
02:12 AM Bug #10794: HAProxy Stats page credentials are not redacted in status.php
Sanitize stats_password:
https://github.com/pfsense/pfsense/pull/4407
Viktor Gurov
08:40 AM pfSense Packages Feature #10796 (Pull Request Review): Huawei ME909u-521 support
Jim Pingle
01:00 AM pfSense Packages Feature #10796: Huawei ME909u-521 support
https://github.com/pfsense/FreeBSD-ports/pull/898 Viktor Gurov
01:00 AM pfSense Packages Feature #10796 (Feedback): Huawei ME909u-521 support
Add Huawei ME909u-521 Viktor Gurov
08:11 AM pfSense Packages Feature #10347: Request to add pull-filter
Discussion about --route-nopull:
https://sourceforge.net/p/openvpn/mailman/openvpn-devel/thread/4B3OgL3j077iDP_MhneR...
Pippin MMD
07:24 AM Revision 4d0d242b: Correct QLogic interface name in ALTQ-capable list. Issue #10594
Viktor Gurov
07:11 AM Revision 7f11a9a0: Sanitize HAproxy stats_password. Issue #10794
Viktor Gurov
04:36 AM Bug #10784 (Feedback): HA-sync with ssh keys
Unable to reproduce it on 2.4.5-p1 and 2.5.0.a.20200728.1850 HA clusters, ~/.ssh directory owner is OK
Please give u...
Viktor Gurov
12:45 AM Bug #9796: kernel panic after removing interfaces
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=248243 Viktor Gurov

07/28/2020

05:24 PM Revision ccbb25fa: Correct description truncate in "Services Status" widget. Fixes #10795
Mikhail Burichenko
04:04 PM Bug #10793: SNMP: Netgate SG-3100 shows wrong speed
Is this relevant?
mvneta1 supports only 2500MBit but connects with 100MBit....
Grischa Zengel
10:54 AM Bug #10793: SNMP: Netgate SG-3100 shows wrong speed
I was able to reproduce this in both bsnmpd and net-snmp, looks like neither one likes the 2.5G uplink speed.
<pre...
Jim Pingle
05:55 AM Bug #10793 (Resolved): SNMP: Netgate SG-3100 shows wrong speed
I use check_nwc_health for monitoring network interfaces and it shows always over usage (>100%) on interface mvneta1.... Grischa Zengel
11:33 AM Bug #10795: WebGUI "Dashboard -> Services Status" widget issue
Jim Pingle wrote:
> Can you submit that change as a pull request on Github?
https://github.com/pfsense/pfsense/pu...
Mikhail Burichenko
10:18 AM Bug #10795: WebGUI "Dashboard -> Services Status" widget issue
Can you submit that change as a pull request on Github?
https://docs.netgate.com/pfsense/en/latest/development/sub...
Jim Pingle
09:35 AM Bug #10795 (Resolved): WebGUI "Dashboard -> Services Status" widget issue
If i use FQDN in description of openvpn service, the description line will be truncated after the first dot because:
...
Mikhail Burichenko
10:59 AM Bug #8820: System/Advanced/Misc - "Do not kill connections when schedule expires" UN-checked still leaves existing connections open.
See also: #9615 and #10790 Jim Pingle
10:59 AM Bug #9615 (Duplicate): Connections permitted by a schedule are not killed when that schedule expires.
Duplicate of #8820 Jim Pingle
10:59 AM Bug #10790 (Duplicate): States aren't killed after schedule expires
Duplicate of #8820 Jim Pingle
08:28 AM Bug #10794 (Resolved): HAProxy Stats page credentials are not redacted in status.php
The status_output file generated by status.php does not redact the HAProxy stats page login details:... Steve Wheeler
03:40 AM Bug #10792 (New): Crash when switching interface off and on again in cohesion with multicast
Hello,
There are still crashes when switching off and on (vlan)interfaces. One of those crashes seems to be trigge...
Louis B
03:27 AM pfSense Packages Bug #10791 (New): Valid (vlan)interfaces do not get vif reporting "Invalid phyint address"
Hello,
PIMD still not properly working. So I opened tow FeeBSD Bugs. This one is FreeBSD bug 248103.
Also see ht...
Louis B
03:12 AM pfSense Packages Bug #10692: PIMD starts twice at boot
Despite that this issue has state "Fixed". it is _*not fixed at all !!*_ So please "reopen" this bug! Louis B

07/27/2020

09:57 PM Bug #10790 (Duplicate): States aren't killed after schedule expires
I have several rules that allow traffic for a certain amount of time (say, 8am-10pm). That rule is immediately follow... John Pozzoli
11:53 AM pfSense Packages Feature #10789 (Feedback): FRR integrated configuration and hitless reloads
Convert FRR to use an integrated configuration file and use frr-reload where possible for hitless configuration chang... Ben Hughes
10:15 AM Bug #9796: kernel panic after removing interfaces
I do have a reproducible bug when switching interfaces off and on. I did open FreeBSD Bugzilla – Bug 248243. I did ad... Louis B
08:31 AM Feature #1337: VLANs with different MAC address than parent interface
I'm not sure that setting the interface in promiscuous mode is the right thing to do here. There will be performance... Luiz Souza
07:43 AM pfSense Packages Bug #10788 (Rejected): ntopng not displaying graphs correctly. Bottom of graphs getting cut off.
That's an issue between ntopng and your browser, not in code we have any control over. If you can still reproduce it ... Jim Pingle

07/26/2020

03:04 PM Feature #6626: Support for IPv6 firewall entries with dynamic delegated prefix and static host address
Hello,
we are also in dire need of this feature. Lack of support for dynamic prefixes makes IPv6 pretty much unusa...
Mike Murdoch
11:43 AM pfSense Packages Bug #10788 (Rejected): ntopng not displaying graphs correctly. Bottom of graphs getting cut off.
ntopng graphs are getting cut off where I can not see the time on historical graphs.
To duplicate, I go to Hosts M...
Hector Gongora
 

Also available in: Atom