Project

General

Profile

Activity

From 08/26/2020 to 09/24/2020

09/24/2020

04:32 PM Revision f81845a6: Update bootstrap to v3.4.1
Steve Beaver
02:53 PM pfSense Docs Correction #10929: Feedback on Development — Developing Packages
Great, thanks Jim. Looking to possibly make a little plugin here and have been pretty lost on where to start. alzee bum
02:48 PM pfSense Docs Correction #10929 (Resolved): Feedback on Development — Developing Packages
Thanks for catching that! I have restored the information which should be on that page, and made some additional edit... Jim Pingle
09:52 AM pfSense Docs Correction #10929 (Resolved): Feedback on Development — Developing Packages
*Page:* https://docs.netgate.com/pfsense/en/latest/development/develop-packages.html
*Feedback:* This page just li...
alzee bum
02:42 PM pfSense Docs Correction #10707 (Resolved): Feedback on Backup and Restore — Automatically Restore a pfSense Configuration During Installation
Relevant changes, and more related changes on the page, are now complete.
https://docs.netgate.com/pfsense/en/late...
Jim Pingle
01:59 PM Feature #6960: Introduce Kea DHCP as an alternative DHCP server for IPv4 and IPv6
Not enough time for this big change before 2.5.0 is out Renato Botelho
01:44 PM Bug #9058: Kernel panic during L2TP retransmit
A possible solution proposed by markj@ - https://reviews.freebsd.org/D26548
If this revision is accepted I'll impo...
Renato Botelho
10:57 AM Bug #9058: Kernel panic during L2TP retransmit
Waiting for a fix on FreeBSD side. When it happens we can target a pfSense release to add it Renato Botelho
01:18 PM Todo #9052 (In Progress): Update Font-Awesome
Jared Dillard
01:13 PM pfSense Packages Bug #10930: Wrong blocklist from dshield.org
also, https://feeds.dshield.org/top10-2.txt is mentioned in the documentation, which is not a block list. Johannes Ullrich
01:12 PM pfSense Packages Bug #10930 (Resolved): Wrong blocklist from dshield.org
The current configuration uses the wrong blocklist from dshield.org (https://isc.sans.edu/api/sources/attacks/1000/30... Johannes Ullrich
08:57 AM Feature #9527 (Pull Request Review): Add ability for LDAP extended query on groups in RFC2307 containers.
Jim Pingle
08:57 AM Feature #9527: Add ability for LDAP extended query on groups in RFC2307 containers.
Jim Pingle wrote:
> I reverted commit:e924485c9e681771806fe3ee63ed746152fcbcb9 -- Previously working LDAP servers st...
Viktor Gurov
07:30 AM Bug #10928 (Duplicate): RADIUS Authentification parameters encoding/decoding dont work for french characters like : ç, é, à
Duplicate of #10352 Jim Pingle
03:55 AM Bug #10928 (Duplicate): RADIUS Authentification parameters encoding/decoding dont work for french characters like : ç, é, à
Hello !
I tried to setup L2TP/IPSEC VPN authenticated by RADIUS with AD. (Pfsense 2.4.3)
Everything works perfe...
Oscar Mrbt
07:19 AM Bug #6891 (Duplicate): Improper shutdown causes irrecoverable filesystem corruption, unable to boot or fsck
It's probably a duplicate of #6340. Lots of improvements were made in this area on FreeBSD itself and also on pfSense. Renato Botelho
03:27 AM pfSense Packages Bug #10927 (Resolved): pfBlockerNG-devel fullfill the pfsense config history when RAM disk in use
Hi !
I set pfBlockerNG-devel to update DNSBL hourly, and it works fine.
But this hourly update use to be logged i...
Laurent BONNIN
12:27 AM pfSense Packages Bug #10922: Gmail smtp relay TLS stopped working.
Anton Palmgard wrote:
> Hi to clarify we use, smtp-relay.gmail.com as this is used by gsuite.
/usr/local/etc/stun...
Viktor Gurov

09/23/2020

06:42 PM Revision 50299413: Update URLs to docs. Fixes #10481
Jim Pingle
06:18 PM Revision 9aa882cb: Update help.php URLs. Fixes #10481
Jim Pingle
04:37 PM pfSense Packages Bug #10922: Gmail smtp relay TLS stopped working.
Hi to clarify we use, smtp-relay.gmail.com as this is used by gsuite. Anton Palmgard
03:01 AM pfSense Packages Bug #10922 (Rejected): Gmail smtp relay TLS stopped working.
no such issue on pfSense 2.4.5-p1, pfSense-pkg-stunnel-5.50_4
/usr/local/etc/stunnel/stunnel.conf:...
Viktor Gurov
04:33 PM Revision 4a5942a4: Merge pull request #4457 from vktg/bridgecpvalidation
Renato Botelho
04:26 PM Revision 3f338fde: Bridge interface Captive Portal validation. Issue #6528
Viktor Gurov
03:46 PM pfSense Docs Correction #10924: Update information on distributed vswitch behavior in VMware vSphere / ESXi
Yeah, enabling this also removes the need for the Net.ReversePathFwdCheckPromisc setting listed on that page. It basi... Nathan M
03:26 PM pfSense Docs Correction #10924: Update information on distributed vswitch behavior in VMware vSphere / ESXi
Perhaps this instead or as well: https://docs.netgate.com/pfsense/en/latest/troubleshooting/high-availability-virtual... Jim Pingle
03:19 PM pfSense Docs Correction #10582 (Closed): Feedback on Services — DNS — Blocking DNS Queries to External Resolvers
I recently rewrote this page, it should be current/accurate now. Jim Pingle
03:17 PM pfSense Docs Correction #10512 (Closed): Feedback on Routing and Multi-WAN — Using Multiple IPv4 WAN Connections
The book and wiki content has been merged, and the book content is the only copy of this present now. So based on the... Jim Pingle
03:15 PM pfSense Docs Correction #10382 (Closed): Feedback on Hardware — Tuning and Troubleshooting Network Cards
The book and wiki content has been merged, so this is addressed.
https://docs.netgate.com/pfsense/en/latest/hardwa...
Jim Pingle
03:14 PM pfSense Docs Todo #10268 (Closed): Feedback on Services
It's already under Backup and Recovery where users are most likely to look for it. Since it isn't a service running l... Jim Pingle
03:07 PM pfSense Docs Correction #10173 (Closed): Feedback on Packages — Fixing a Broken pkg Database
I don't see any references to that path, only @/usr/local/sbin/pkg-static@ which does exist.
Jim Pingle
03:06 PM pfSense Docs New Content #10009 (Closed): Feedback on System Monitoring
Seems irrelevant after the docs merge.
https://docs.netgate.com/pfsense/en/latest/monitoring/status/carp.html
Jim Pingle
03:06 PM pfSense Docs New Content #10008 (Closed): Feedback on IPsec
Advanced IPsec settings are all covered at https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/advanced.html now Jim Pingle
03:05 PM pfSense Docs New Content #10007 (Closed): Feedback on Services — Dynamic DNS
The book and former wiki content are now merged so the info is together.
https://docs.netgate.com/pfsense/en/lates...
Jim Pingle
03:04 PM pfSense Docs Correction #10006 (Closed): Feedback on Backup and Recovery — Using the AutoConfigBackup Package
Gold and ACB package refs are all gone. Jim Pingle
03:02 PM pfSense Docs Correction #9925 (Closed): Feedback on VPN — OpenVPN — Troubleshooting Windows OpenVPN Client Connectivity
This page has since been rewritten and removed the problematic references.
https://docs.netgate.com/pfsense/en/lat...
Jim Pingle
02:53 PM pfSense Docs Correction #9672 (Closed): Feedback on Backup and Recovery — Using the AutoConfigBackup Package
References to Gold and ACB as a package were all removed during the docs merge. All refs for ACB should now indicate ... Jim Pingle
02:52 PM pfSense Docs Correction #9671 (Closed): Feedback on Hardware — Hardware Selection
I fixed this at some point...
The note at the end of https://docs.netgate.com/pfsense/en/latest/hardware/selection.h...
Jim Pingle
02:48 PM pfSense Docs Correction #9670 (Closed): Feedback on Backup and Recovery
References to Gold and ACB as a package were all removed during the docs merge. All refs for ACB should now indicate ... Jim Pingle
02:45 PM pfSense Docs Correction #9494 (Resolved): Feedback on VPN — IPsec — NAT with IPsec Phase 2 Networks
This page has since been rewritten and should be clear now. Jim Pingle
02:43 PM pfSense Docs Correction #9379: Feedback on Interfaces — Using a Large Number of Interfaces
Mostly addressed in the new docs, but we can add that suggested upper number as a guide. Jim Pingle
02:40 PM pfSense Docs Correction #9373: Feedback on Services — DNS — Configuring the DNS Resolver
The main Unbound docs need updated yet but there is also this: https://docs.netgate.com/pfsense/en/latest/recipes/dns... Jim Pingle
02:36 PM Revision 93fec82f: Merge pull request #4456 from vktg/nptoverlapvalidation
Renato Botelho
02:36 PM Revision fd8b556f: Merge pull request #4455 from vktg/pppoesrvinfcheck
Renato Botelho
02:36 PM Revision 2ec97b21: Merge pull request #4454 from vktg/pppoesecondradius
Renato Botelho
02:36 PM Revision f23f5274: Merge pull request #4452 from vktg/backupdhcpleases
Renato Botelho
02:36 PM Revision 415932cf: Merge pull request #4453 from vktg/pppoenorestart
Renato Botelho
02:25 PM pfSense Docs Correction #10901 (Resolved): Feedback on Virtualization — VirtIO Driver Support
Fixed manually in the new docs repo Jim Pingle
02:24 PM pfSense Docs Correction #10877 (Feedback): Feedback on VPN — IPsec — Configuring an IPsec Remote Access Mobile VPN using IKEv2 with EAP-MSCHAPv2
Fixed in the new docs repo. Jim Pingle
10:07 AM pfSense Docs Correction #10877 (New): Feedback on VPN — IPsec — Configuring an IPsec Remote Access Mobile VPN using IKEv2 with EAP-MSCHAPv2
Jim Pingle
01:44 PM Bug #10481 (Resolved): Update doc links in WebGUI to reflect proper docs URLs
Reusing this, see #10135, same intent.
Fixed in pfsense:commit:502994130948049349e6c52b651266d8d7bf3566
Jim Pingle
01:35 PM Todo #10135 (Feedback): help.php: Update links
Latest revision is in commit:9aa882cbb18d27d0b7a2a305dfb3164080e7a4d7
All are current, no more redirects. Any othe...
Jim Pingle
01:16 PM Todo #10135: help.php: Update links
The book and former wiki content have now been merged into a single set of documentation. I'm going to reuse this iss... Jim Pingle
12:45 PM Bug #9643: Limiters do not function properly on 2.5 snapshots
Abhinav Tella wrote:
> Here are the limiters and firewall floating rule I used. When the firewall rule is enabled, n...
Jesse Beauclaire
11:33 AM Bug #6528 (Feedback): The captive portal cannot be used on interface lan since it is part of a bridge but works anyway
PR has been merged. Thanks! Renato Botelho
08:58 AM Bug #6528 (Pull Request Review): The captive portal cannot be used on interface lan since it is part of a bridge but works anyway
Jim Pingle
03:27 AM Bug #6528: The captive portal cannot be used on interface lan since it is part of a bridge but works anyway
https://github.com/pfsense/pfsense/pull/4457 Viktor Gurov
10:47 AM pfSense Docs Correction #10648 (Closed): Feedback on IPsec — Mobile IPsec — Windows IKEv2 Client Configuration
The PR was merged months ago. If more is needed, should be in a new issue/new PR. Jim Pingle
10:42 AM pfSense Docs Correction #10686 (Duplicate): Feedback on Development — Obtaining Panic Information for Developers
Duplicate of #10180 Jim Pingle
10:31 AM pfSense Packages Feature #10897 (Feedback): SNMPV3-trap/inform Add Snmpv3 trap/inform Field
PR has been merged. Thanks! Renato Botelho
10:31 AM pfSense Docs Correction #9686 (Duplicate): Feedback on Firewall — Floating Rules
Duplicate of #9685 Jim Pingle
10:30 AM pfSense Packages Feature #10913 (Feedback): Allow disabling caching in Squid completly
PR has been merged. Thanks! Renato Botelho
08:54 AM pfSense Packages Feature #10913 (Pull Request Review): Allow disabling caching in Squid completly
Jim Pingle
01:14 AM pfSense Packages Feature #10913: Allow disabling caching in Squid completly
https://github.com/pfsense/FreeBSD-ports/pull/940 Viktor Gurov
10:30 AM pfSense Packages Bug #5168 (Feedback): squid doesn't function during/after HA failover
PR has been merged. Thanks! Renato Botelho
08:59 AM pfSense Packages Bug #5168 (Pull Request Review): squid doesn't function during/after HA failover
Jim Pingle
07:07 AM pfSense Packages Bug #5168: squid doesn't function during/after HA failover
Azamat Khakimyanov wrote:
> I tested it on 2.5-DEV (built on Wed Sep 16 01:00:40 EDT 2020): With new "CARP Status VI...
Viktor Gurov
10:20 AM pfSense Docs Correction #9228: Feedback on Hardware — Hardware Sizing Guidance
We can probably take out those tables with Netgate model info and link to the comparison charts on the store which ha... Jim Pingle
09:37 AM Feature #10318 (Feedback): Do not restart PPPoE server after adding/modifying users
PR has been merged. Thanks! Renato Botelho
09:36 AM Feature #10910 (Feedback): Backup/restore DHCP v4/v6 leases
PR has been merged. Thanks! Renato Botelho
09:36 AM Bug #10926 (Feedback): Secondary RADIUS Server is never used
PR has been merged. Thanks! Renato Botelho
09:36 AM Bug #4510 (Feedback): Crash & reboot loop when configure PPPoE server on PPPoE client interface
PR has been merged. Thanks! Renato Botelho
08:55 AM Bug #4510 (Pull Request Review): Crash & reboot loop when configure PPPoE server on PPPoE client interface
Jim Pingle
01:44 AM Bug #4510: Crash & reboot loop when configure PPPoE server on PPPoE client interface
https://github.com/pfsense/pfsense/pull/4455 Viktor Gurov
09:36 AM Feature #7741 (Feedback): warn me when shooting myself in the foot with NPt
PR has been merged. Thanks! Renato Botelho
08:57 AM Feature #7741 (Pull Request Review): warn me when shooting myself in the foot with NPt
Jim Pingle
02:13 AM Feature #7741: warn me when shooting myself in the foot with NPt
https://github.com/pfsense/pfsense/pull/4456 Viktor Gurov
07:12 AM Revision 0dc5aeaa: NPT prefix overlap validation. Issue #7741
Viktor Gurov
06:41 AM Revision 4f911030: PPPoE Server interface input validation. Issue #4510
Viktor Gurov
05:13 AM Revision 80fcbd31: PPPoE Server secondary RADIUS server fixes. Issue #10926
Viktor Gurov
03:21 AM Bug #10720 (Resolved): Setup Wizard DNS Server validation JavaScript incorrectly claims IPv6 address is invalid
Danilo Zrenjanin
03:21 AM Bug #10720: Setup Wizard DNS Server validation JavaScript incorrectly claims IPv6 address is invalid
Tested on :... Danilo Zrenjanin
02:55 AM Bug #10882 (Resolved): DHCPv6 Static Mappings requires applying changes on DNS resolver setup
Added the patch on the:... Danilo Zrenjanin
02:03 AM Feature #10856 (Resolved): Backup/Restore Captive Portal usedmacs DB
Danilo Zrenjanin
02:02 AM Feature #10856: Backup/Restore Captive Portal usedmacs DB
Tested on:... Danilo Zrenjanin
01:52 AM Feature #1683: PF scrub min-ttl option
see also #10493 Viktor Gurov

09/22/2020

06:14 PM Bug #10792 (Closed): Crash when switching interface off and on again in cohesion with multicast
Awesome! Thanks for reporting Renato Botelho
06:10 PM Feature #1337: VLANs with different MAC address than parent interface
Setting the interface in promiscuous mode is not the way to go and without it FreeBSD don't offer a way to make it to... Renato Botelho
06:07 PM Bug #6167: IPsec IPComp not working
When it's fixed on FreeBSD we can import the fix and target it to a version Renato Botelho
05:10 PM Revision 7fceb8e1: Clean backup cache before reading
Steve Beaver
03:23 PM Revision 1b75667c: Backup/restore DHCP v4/v6 leases. Implements #10910
Viktor Gurov
03:06 PM Todo #9356 (Closed): Find optimal default for net.pf.request_maxcount
This has been working fine.
Note that it changed from a loader tunable to a run-time sysctl in FreeBSD stable/12 f...
Jim Pingle
03:01 PM Feature #10387 (Feedback): Reevaluate the GUI upgrade language presented to the user
Message changed to "System is going to be upgraded. Rebooting in 10 seconds"
pfSense-upgrade 0.88 on 2.5.0 and 0....
Renato Botelho
02:56 PM Revision ffe95182: Fix #10925: Check if $rtable is empty
Renato Botelho
02:53 PM Revision f5d5a463: Do not restart PPPoE server after adding/modifying users. Implements #10318
Viktor Gurov
02:53 PM Feature #10388 (Rejected): Upgrade to Python 3.8
We will keep following the default version from FreeBSD ports tree, which now is 3.7 Renato Botelho
02:51 PM pfSense Packages Bug #10646 (Duplicate): Reinstall package process stalls at pfBlockerNG when restoring a config
Duplicate of #10610 Renato Botelho
02:49 PM Bug #10518 (Rejected): Netmap appears broken in Snort and Suricata packages when Inline IPS Mode enabled
It won't affect users upgrading from 2.4 to 2.5 so there is no action to be done. Thanks Renato Botelho
01:37 PM pfSense Docs Correction #10451 (Closed): Feedback on Releases — Versions of pfSense and FreeBSD
There is a difference in "Supported" as meant on that page and versions eligible for support from Netgate TAC. Both u... Jim Pingle
01:31 PM pfSense Docs New Content #8773 (Closed): Add VPN Throughput Tuning info
Jim Pingle
01:03 PM Bug #10926 (Pull Request Review): Secondary RADIUS Server is never used
Jim Pingle
12:02 PM Bug #10926: Secondary RADIUS Server is never used
https://github.com/pfsense/pfsense/pull/4454 Viktor Gurov
09:59 AM Bug #10926 (Resolved): Secondary RADIUS Server is never used
Secondary/Backup RADIUS server is never used,
There is no $pppoecfg['radius']['server2'] in the code,
Only primary ...
Viktor Gurov
10:32 AM Bug #7096: Unbound fails to start on boot if specific network devices are configured in the "Network Interfaces"
Back when I reported the problem its was IPoE DHCP for Wan IPv4 and Track Interface for LAN IPv6.
Now it is IPv4 P...
Chris Collins
04:16 AM Bug #7096: Unbound fails to start on boot if specific network devices are configured in the "Network Interfaces"
Chris Collins wrote:
> Just to add I Dont get this issue anymore, I think the problem may have been related to unbou...
Viktor Gurov
10:05 AM Bug #10925 (Feedback): PHP: Invalid argument supplied for foreach() in /etc/inc/util.inc on line 2640
Applied in changeset commit:ffe95182999a344dd926c5079a3f74ccc62e0f46. Renato Botelho
08:57 AM Bug #10925: PHP: Invalid argument supplied for foreach() in /etc/inc/util.inc on line 2640
That's line 2640 on factory and line 2624 on CE.
The foreach() here:...
Jim Pingle
01:41 AM Bug #10925 (Resolved): PHP: Invalid argument supplied for foreach() in /etc/inc/util.inc on line 2640
Invalid argument supplied for foreach() in /etc/inc/util.inc on line 2640 error at boot.
Has started happening ab...
Craig Weber
10:01 AM Feature #10318 (Pull Request Review): Do not restart PPPoE server after adding/modifying users
Jim Pingle
09:55 AM Feature #10318: Do not restart PPPoE server after adding/modifying users
https://github.com/pfsense/pfsense/pull/4453 Viktor Gurov
09:11 AM pfSense Packages Feature #10897 (Pull Request Review): SNMPV3-trap/inform Add Snmpv3 trap/inform Field
Jim Pingle
05:29 AM pfSense Packages Feature #10897: SNMPV3-trap/inform Add Snmpv3 trap/inform Field
https://github.com/pfsense/FreeBSD-ports/pull/939 Viktor Gurov
09:09 AM Feature #10910 (Pull Request Review): Backup/restore DHCP v4/v6 leases
Jim Pingle
03:48 AM Feature #10910: Backup/restore DHCP v4/v6 leases
https://github.com/pfsense/pfsense/pull/4452 Viktor Gurov
08:44 AM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
Steve Wheeler wrote:
> After upgrading to todays snap with this change I am seeing this error:
> [...]
>
> The c...
Ben Hughes
08:20 AM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
Steve Wheeler wrote:
> The console hung at 'Writing configuration...' at boot after the update requiring me to Ctl+C...
Jim Pingle
08:19 AM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
After upgrading to todays snap with this change I am seeing this error:... Steve Wheeler
08:26 AM Bug #10155 (Resolved): sshguard is not compatible with RFC 5424 log format
This looks good now, thanks!... Jim Pingle
07:43 AM pfSense Packages Bug #10917 (Resolved): snort: invalid pidfile suffix error
Renato Botelho
01:43 AM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
I don't think NAT-T is the issue. All my firewalls have public IPs, and my tunnels don't have NAT-T (see status outpu... Brian Candler
01:17 AM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
Could another difference-maker be NAT-T? As reported above, i'm consistently seeing duplicates on a cluster i'm opera... Marc L

09/21/2020

09:13 PM pfSense Docs Correction #10924: Update information on distributed vswitch behavior in VMware vSphere / ESXi
This ticket is probably meant for this page instead - https://pfsense-docs.readthedocs.io/en/latest/highavailability/... Nathan M
08:07 PM pfSense Docs Correction #10924 (New): Update information on distributed vswitch behavior in VMware vSphere / ESXi
*Page:* https://docs.netgate.com/pfsense/en/latest/recipes/virtualize-esxi.html
*Feedback:*
Vmware has added su...
Nathan M
07:01 PM Revision c4251167: Fix ui/json replace error
Steve Beaver
06:46 PM Revision 82289330: Merge pull request #4176 from vktg/maxikev1exchanges
Renato Botelho
06:46 PM Revision 08ff1f65: Merge pull request #4436 from f-bor/ipsec_custom_port
Renato Botelho
03:26 PM Bug #10861 (Resolved): net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
I've upgraded a few systems and they all came through OK. Had the wrong value before upgrade and expected value after. Jim Pingle
03:25 PM pfSense Packages Bug #10917: snort: invalid pidfile suffix error
The pull requests against pfSense-2.4.5-RELEASE and pfSense-2.5-DEVELOPMENT have been merged. This issue can be marke... Bill Meeks
03:13 PM pfSense Packages Bug #10917 (Feedback): snort: invalid pidfile suffix error
PR has been merged. Thanks! Renato Botelho
03:11 PM pfSense Packages Bug #10917: snort: invalid pidfile suffix error
PRs:
* https://github.com/pfsense/FreeBSD-ports/pull/937
* https://github.com/pfsense/FreeBSD-ports/pull/938
Jim Pingle
03:10 PM pfSense Packages Bug #10917 (Pull Request Review): snort: invalid pidfile suffix error
Jim Pingle
03:09 PM pfSense Packages Bug #10917: snort: invalid pidfile suffix error
Two pull requests have been submitted against pfSense-2.4.5 and pfSense-2.5 to fix the issue reported in this ticket.... Bill Meeks
09:48 AM pfSense Packages Bug #10917: snort: invalid pidfile suffix error
This issue also impacts the Snort package on pfSense-2.5 under the same conditions when the physical interface name a... Bill Meeks
03:05 PM Feature #6324 (Closed): Improve IKEv2 multiple traffic selector per SA configuration GUI
There is no need for a separate option here. If you check Split Connections it does the right thing on 2.5.0.
It m...
Jim Pingle
02:30 PM Bug #10923 (Resolved): Update ixl Driver on pfSense 2.5.0 to bring back Intel X710-T2L/T4L support that was present on version 2.4.5-P1.
Intel X710 T-2L/T-4L devices were supported on pfSense 2.4.5-P1, however a regression from FreeBSD 12 onwards meant s... Abhinav Tella
02:21 PM Bug #8686: IPsec VTI: Assigned interface firewall rules are never parsed
I thought it was noted here but I don't see it. There is another FreeBSD issue at https://bugs.freebsd.org/bugzilla/s... Jim Pingle
01:58 PM Bug #9710 (Resolved): IPv6 RA: prefix option does not contain router address in spite of "R" flag being set
Jim Pingle
01:18 PM Bug #9710: IPv6 RA: prefix option does not contain router address in spite of "R" flag being set
Feedback:
Tested on:
2.5.0-DEVELOPMENT (amd64)
built on Mon Sep 21 07:00:38 EDT 2020
FreeBSD 12.2-PRERELEASE
R...
Rick Coats
01:47 PM Feature #10870 (Feedback): Allow custom IPSEC NAT-T port
PR has been merged. Thanks! Renato Botelho
01:47 PM Bug #9331 (Feedback): Parallel Rekey fails for multiple Child SAs
PR has been merged. Thanks! Renato Botelho
12:26 PM Revision 9372c82c: Adjust ETCDIR for frr7
Renato Botelho
12:16 PM Bug #10155 (Feedback): sshguard is not compatible with RFC 5424 log format
Renato Botelho
12:15 PM Bug #10155: sshguard is not compatible with RFC 5424 log format
sshguard 2.4.1 is now imported into pfSense 2.5.0 Renato Botelho
10:40 AM pfSense Packages Bug #10922 (Rejected): Gmail smtp relay TLS stopped working.
Hi, a few days ago up to a week my stunnel connection to smtp-gmail.gmail.com. stopped working with the error:
ep...
Anton Palmgard
09:54 AM Bug #7096: Unbound fails to start on boot if specific network devices are configured in the "Network Interfaces"
Just to add I Dont get this issue anymore, I think the problem may have been related to unbound starting "before" wan... Chris Collins
09:34 AM Todo #9417: Convert LDAP TLS setup from environment to LDAP_OPT_X_TLS_* set options
This is working better but today I'm seeing some inconsistencies in the behavior. I can flip back and forth between t... Jim Pingle
08:47 AM Bug #10921 (Not a Bug): Firewall rule removed and activated, but still active
https://docs.netgate.com/pfsense/en/latest/firewall/firewall-rule-troubleshooting.html#dangling-states Jim Pingle
08:31 AM Bug #10921 (Not a Bug): Firewall rule removed and activated, but still active
Hello everybody,
I'm currently testing pfsense in my laboratory. I couldn't ping the WAN interface, which is corre...
Jens Bauer
07:44 AM Bug #10560 (Duplicate): Connection fails connecting to (my) OpenVPN instance.
Jim Pingle
07:43 AM Bug #10560: Connection fails connecting to (my) OpenVPN instance.
We already have an issue for that particular problem: #4521 Jim Pingle
07:39 AM pfSense Packages Feature #10665 (Feedback): Manual OSPF neighbor definitions
I committed fixes which should fix this. Will be available shortly. Jim Pingle
07:21 AM pfSense Packages Feature #10665: Manual OSPF neighbor definitions
Looks like it's missing entries in pkg-plist and Makefile to install that file. Jim Pingle
07:00 AM pfSense Packages Feature #10665 (Assigned): Manual OSPF neighbor definitions
Tested on:
2.5.0-DEVELOPMENT (amd64)
built on Mon Sep 21 01:04:35 EDT 2020
FreeBSD 12.2-PRERELEASE
I didn't fin...
Azamat Khakimyanov
07:33 AM pfSense Packages Feature #10789 (Feedback): FRR integrated configuration and hitless reloads
PR has been merged only on 2.5.0 branch for now so we can get it properly tested Renato Botelho
06:54 AM Bug #10827 (Confirmed): Cannot add or delete separators when no rules are present
Marcos M
06:38 AM Feature #10743 (In Progress): Traffic shaper wizard: Add Google Stadia port range
Renato Botelho
06:38 AM Bug #10889: Hover text missing from Static Routes Page
Kris Phillips wrote:
> Renato Botelho wrote:
> > PR has been merged. Thanks!
>
> Hello Renato,
>
> Do you ha...
Renato Botelho
02:31 AM Bug #9024: Ping packet loss under load when using limiters
Problem also seems to be related to download limiter only, as traceroute is displayed correctly if fq-codel is applie... Thomas Pilgaard

09/20/2020

04:56 PM pfSense Docs Correction #10920 (Resolved): Feedback on Packages — Using the Package Manager
*Page:* https://docs.netgate.com/pfsense/en/latest/packages/manager.html
*Feedback:*
The information on this page...
Michael Sonstein
04:42 PM Bug #10560: Connection fails connecting to (my) OpenVPN instance.
TL;DR: It is a bug or feature of fcgicli in fact. It doesn't handle long strings being sent to the application. The "... Stefan Smietanowski
04:04 PM Bug #10892 (Resolved): Large number of VLAN/LANs make floating rules are to read
Tested in
2.5.0-DEVELOPMENT (amd64)
built on Sun Sep 20 06:59:15 EDT 2020
FreeBSD 12.2-PRERELEASE
and patch ...
Max Leighton
02:30 PM Bug #9383 (Resolved): dhcpleases kqueue error
Validated the behavior in 2.4.5_1
Tested again in
2.5.0-DEVELOPMENT (amd64)
built on Sun Sep 20 06:59:15 EDT 2...
Max Leighton
12:13 PM pfSense Packages Bug #10884 (Resolved): wrong link on haproxy-devel
Tested on
2.5.0-DEVELOPMENT (amd64)
built on Sun Sep 20 06:59:15 EDT 2020
FreeBSD 12.2-PRERELEASE
Related ...
Max Leighton
08:36 AM pfSense Packages Feature #10725 (Resolved): Squid disable multiple login sessions
Azamat Khakimyanov
08:35 AM pfSense Packages Feature #10725: Squid disable multiple login sessions
Tested on:
2.5.0-DEVELOPMENT (amd64)
built on Sun Sep 20 01:01:05 EDT 2020
FreeBSD 12.2-PRERELEASE
With default...
Azamat Khakimyanov
06:56 AM pfSense Packages Bug #8625 (Resolved): PFsense squidGuard faulty URL check
Tested on 2.4.4_p3, 2.4.4_p1 and 2.5-DEV (built on Sun Sep 20 01:01:05 EDT 2020):
- no issue if there is an url with...
Azamat Khakimyanov
05:26 AM Bug #10919 (Resolved): Improve handling of OpenVPN data cipher negotiation options
TL;DR: the cipher that is selected as --cipher in the openvpn config, should always be added to ncp-ciphers
In Ope...
Arne Schwabe
02:37 AM pfSense Packages Bug #7455: Unbound DNS Resolver failed with pfBlockerNG after reboot with /var mounted on ramfs
Similar issue over here, 2.4.5-RELEASE-p1 having LAN, VLAN and WAN1, WAN2 (LoadBalancing&Failover) and IPv4, IPv6 and... Marc Dorando
02:35 AM Bug #9567: Unbound DNS Resolver does not start up when using IPv6 DHHCPv6 WAN DHCPv6 LAN coupled with v6 Prefix Delegation
Similar issue over here, 2.4.5-RELEASE-p1 having LAN, VLAN and WAN1, WAN2 (LoadBalancing&Failover) and IPv4, IPv6 and... Marc Dorando
02:32 AM Bug #7096: Unbound fails to start on boot if specific network devices are configured in the "Network Interfaces"
Same issue over here, Unbound does not start after rebooting on 2.4.5-RELEASE-p1 having LAN, VLAN and WAN1, WAN2 (Loa... Marc Dorando
12:00 AM Feature #10918 (New): IP Aliases de-duplication
when i add an IP Aliases with duplicate or same IP-address, it will add those IPs without any warning about duplicate... Nima Mohammadi

09/19/2020

10:10 PM Feature #10743: Traffic shaper wizard: Add Google Stadia port range
Option for Stadia exists when running wizard but is not selectable on 2.5.0.a.20200919.1850 Jordan G
07:31 PM Bug #9024: Ping packet loss under load when using limiters
Well I turned off the Open VPN client and it worked. The traffic shaper is working normally. For some reason Open VPN... Joshua Babb
06:49 PM Bug #9024: Ping packet loss under load when using limiters
I as well can replicate this issue, I have outbound NAT setup and tried to setup a traffic limiter + fq_codel and see... Joshua Babb
02:04 PM Bug #10674: Port Forward Address Fields not becoming active in Safari
Unable to reproduce on Safari 13.1.2 with pfSense 2.5.0.a.20200910.1250 Michael Spears
01:41 PM pfSense Packages Bug #10602: Dashboard->Traffic Graphs bandwidth designations on hover pop-ups
Randall Barth wrote:
> The scales are reporting Mbytes/sec but the pop-up is using the Mbits/sec designation: Mb/s. ...
Kris Phillips
01:19 PM Bug #10889: Hover text missing from Static Routes Page
Renato Botelho wrote:
> PR has been merged. Thanks!
Hello Renato,
Do you have a System Patch for applying thi...
Kris Phillips
01:02 PM Bug #10827: Cannot add or delete separators when no rules are present
This item should be moved from Feedback to Confirmed, please. I also tested this and can confirm that it is present ... Kris Phillips
12:31 PM pfSense Packages Bug #10917: snort: invalid pidfile suffix error
According to the "pfsense forum":https://forum.netgate.com/topic/156861/upcoming-snort-package-updates-for-pfsense-2-... Anonymous
04:42 AM pfSense Packages Bug #10917 (Resolved): snort: invalid pidfile suffix error
After upgrading snort package from *@3.2.9.14_1@* to *@4.1.2@*, I have two interfaces where snort gives the following... Anonymous
06:52 AM Feature #9639 (Resolved): Cloudflare DDNS "API Token"
Tested on :... Danilo Zrenjanin
06:15 AM Revision 92ed9792: add custom ipsec ports
Frederic Bor

09/18/2020

07:06 PM Revision 5cbea686: Revert "Use user DN for RFC2307 membership search. Issue #9527"
This reverts commit e924485c9e681771806fe3ee63ed746152fcbcb9. Jim Pingle
06:55 PM Revision 39f48832: Use correct LDAP_OPT_X_TLS_* syntax. Fixes #9417
Also clean up the code a little, use the proper CA hash for filename. Jim Pingle
06:55 PM Revision b0c7d642: Revert "Revert LDAP_OPT_X_TLS changes since they do not work. Issue #9417"
This reverts commit 7729c5a163fb8acaca8d3f43b557176a9ed4a8db. Jim Pingle
06:32 PM Bug #10916 (Rejected): Cannot create bootle USB drive using ISO
We stopped using hybrid images on purpose. The memstick has a separate FAT partition to make it easier to load config... Jim Pingle
06:28 PM Bug #10916 (Rejected): Cannot create bootle USB drive using ISO
Using the latest daily snapshot (pfSense-CE-2.5.0-DEVELOPMENT-amd64-20200918-1020), writing the ISO to a USB drive us... Marcos M
05:42 PM Revision fd2533ab: Merge pull request #4451 from vktg/backupextradatacheckbox
Renato Botelho
05:28 PM Revision d56f80bb: Remove FRR multipath option
Jim Pingle
04:14 PM Revision 3d21e635: Merge pull request #4369 from vktg/hidemobpskfields
Renato Botelho
04:06 PM Revision 8f4b8ff2: Handle net.pf.request_maxcount via sysctl. Fixes #10861
Jim Pingle
03:15 PM Revision 35fa566c: Include extra data backup checkbox. Implements #10914
Viktor Gurov
02:59 PM Feature #7671: Gateway Monitoring Via Custom Script or Telnet.
Since the target version has been deleted, is there anyway to prove to the pfSense devs that this feature is importan... Web Dawg
02:55 PM Bug #10397 (Feedback): Changing default or static route gateway on 2.5.0 does not remove old route
It should be fixed on recent 2.5.0 snapshots Renato Botelho
02:54 PM pfSense Packages Todo #9158 (Feedback): Updates for Squid 4.x
AFAIK it's been working for some time now. Move to feedback! Renato Botelho
02:32 PM Revision ffcb0b7f: Add function to list recent backups as JSON array
Steve Beaver
02:08 PM Feature #9527 (New): Add ability for LDAP extended query on groups in RFC2307 containers.
I reverted commit:e924485c9e681771806fe3ee63ed746152fcbcb9 -- Previously working LDAP servers started to fail with no... Jim Pingle
02:05 PM Todo #9417 (Feedback): Convert LDAP TLS setup from environment to LDAP_OPT_X_TLS_* set options
Applied in changeset commit:39f48832cd45cc3a5f5f8d355bbd9253c7bcf7ae. Jim Pingle
01:55 PM Todo #9417: Convert LDAP TLS setup from environment to LDAP_OPT_X_TLS_* set options
And back on 2.5.0... Looks like there is some slightly different required syntax than I was using before. I can now u... Jim Pingle
01:43 PM Revision 40609fff: Remove commented out line
Renato Botelho
01:42 PM Revision fa343c99: Merge pull request #4400 from bonald/master
Renato Botelho
01:15 PM Bug #9643 (New): Limiters do not function properly on 2.5 snapshots
Renato Botelho
12:57 PM Bug #10861: net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
With the fix I checked in, the value is tied to the max table size, as it was before. The value is set at boot time, ... Jim Pingle
11:15 AM Bug #10861 (Feedback): net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
Applied in changeset commit:8f4b8ff22ed9cef5f1bbb8269bdc5bae8c29b959. Jim Pingle
10:48 AM Bug #10861 (In Progress): net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
Jim Pingle
12:54 PM Feature #9716 (Resolved): Italian translation
Renato Botelho
12:54 PM Bug #10438 (Resolved): Prepare pfSense-upgrade to deal with pkg 1.13.x+
Renato Botelho
12:53 PM Bug #10331 (Resolved): French language give a Warning: sprintf(): in system_advanced_admin.php
Renato Botelho
12:53 PM Feature #9544 (New): Enable ``ROUTE_MPATH`` multipath routing
This was too unstable to keep for the time being. Retargeting to Future for now. Will revisit when stability issues i... Jim Pingle
12:52 PM Feature #9545 (New): Enable Multipath Routing in the Kernel
This requires RADIX_MPATH in the kernel which proved to be too unstable, thus had to be removed. See #9544.
We wil...
Jim Pingle
12:52 PM Revision 3ef8d632: Merge pull request #4439 from vktg/cpcpdbbackup
Renato Botelho
12:52 PM Todo #10659 (Resolved): PHP: Update to 7.4.x
PHP has moved to 7.4.x. If specific bugs are found new tickets must be opened. Renato Botelho
12:51 PM Todo #10353 (Resolved): Update pkg to 1.13.x
Renato Botelho
12:46 PM Bug #9872 (Resolved): Error during build when compiling a non pfSense software
Renato Botelho
12:45 PM Todo #9360 (Resolved): Switch to Python 3.x
1 year is enough time for testing :) Renato Botelho
12:44 PM Revision 1af1e47e: Backup Captive Portal DB files. Implements #10868
Viktor Gurov
12:44 PM Feature #10914 (Feedback): Skip extra data checkbox
PR has been merged. Thanks! Renato Botelho
12:10 PM Feature #10914 (Pull Request Review): Skip extra data checkbox
Jim Pingle
10:20 AM Feature #10914: Skip extra data checkbox
https://github.com/pfsense/pfsense/pull/4451 Viktor Gurov
08:59 AM Feature #10914: Skip extra data checkbox
I was just talking with Steve B earlier this week about the way these options are worded. They shouldn't be negative ... Jim Pingle
08:28 AM Feature #10914 (Resolved): Skip extra data checkbox
Add "Skip extra data" checkbox to allow skipping backup/restore:
- Captive Portal DB (#10868), Captive Portal UsedMA...
Viktor Gurov
12:28 PM Revision 022ef976: Only set headers if called from UI
Steve Beaver
12:02 PM Bug #10544 (New): It's not possible to add a user to group operator using the gui
Renato Botelho
11:50 AM Bug #10710 (Resolved): L2TP secret uses empty value
works as expected on 2.5.0.a.20200917.1311
now it doesn't leave empty 'set l2tp secret ""'
Viktor Gurov
11:33 AM pfSense Packages Feature #10915 (Pull Request Review): security/pfSense-pkg-sudo sudo.inc enhancement for better support of NRPE
Jim Pingle
10:19 AM pfSense Packages Feature #10915: security/pfSense-pkg-sudo sudo.inc enhancement for better support of NRPE
Pull request:
https://github.com/pfsense/FreeBSD-ports/pull/936
Infra Weavers
10:06 AM pfSense Packages Feature #10915 (Resolved): security/pfSense-pkg-sudo sudo.inc enhancement for better support of NRPE
We have a requirement to permit NRPE to run custom commands as root so that we can, for instance, monitor VPN connect... Infra Weavers
11:14 AM Bug #10532 (Feedback): Mobile PSK users don't have 'mobile-userpool' section
PR has been merged. Thanks! Renato Botelho
09:03 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
do i need to open another request for the pimd part? xavier Lemaire
09:01 AM pfSense Packages Feature #10909 (Pull Request Review): #define MAXVIFS 32 to 64
Jim Pingle
12:50 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
https://github.com/pfsense/FreeBSD-src/pull/37
see also https://www.freebsd.org/cgi/man.cgi?query=multicast&apro...
Viktor Gurov
08:44 AM Bug #10838 (Feedback): mask options didn't apply to the sched limiter
PR has been merged. Thanks! Renato Botelho
08:24 AM pfSense Packages Feature #10893 (Feedback): TFTP package improvements
PR has been merged. Thanks! Renato Botelho
08:24 AM pfSense Packages Bug #10884 (Feedback): wrong link on haproxy-devel
PR has been merged. Thanks! Renato Botelho
07:54 AM Feature #10868 (Feedback): Backup Captive Portal DB
PR has been merged. Thanks! Renato Botelho
07:48 AM Bug #10844 (Resolved): DHCPv6 service Dynamic DNS revisions made to fix Bug #10346 violates RFC/is too restrictive
Danilo Zrenjanin
07:47 AM Bug #10844: DHCPv6 service Dynamic DNS revisions made to fix Bug #10346 violates RFC/is too restrictive
Tested on :... Danilo Zrenjanin
07:12 AM Bug #10846 (Resolved): Icon area within buttons are not clickable
Tested on :... Danilo Zrenjanin
07:03 AM Feature #10837 (Resolved): Update wizardapp.inc XBox and Wii ports
Tested on :... Danilo Zrenjanin
06:09 AM Revision b862ffc5: Hide IPsec Pre-Shared Keys non-psk fields. Issue #10532
Viktor Gurov
04:53 AM pfSense Packages Feature #10913 (Resolved): Allow disabling caching in Squid completly
We use Squid as a proxy to audit access to websites (or reject as needed). We disabled the disk cache and set the mem... Florian Apolloner
04:07 AM Feature #10912: DNS Domain Overrides - more than one target IP
If there are multiple authoritative DNS servers available for a domain then make a separate entry for each, using the... Viktor Gurov
02:32 AM Feature #10912 (Resolved): DNS Domain Overrides - more than one target IP
Currently when pfSense is acting as a DNS server it can configure Domain Overrides. This is possible with dnsmasq and... Pim Pish

09/17/2020

09:20 PM Revision 8774f2c7: Add red border for disabled rules
Jared Dillard
06:18 PM Revision bfdc9966: Accept backup XML data as string or file
Steve Beaver
05:30 PM Revision c19c0944: Style changes
Renato Botelho
05:28 PM Revision 45ad8273: Style changes
Renato Botelho
05:28 PM Revision 123ec43c: $a_vtimaps is always an array
Renato Botelho
05:23 PM Revision 8cfc4ab9: Style changes
Renato Botelho
05:17 PM Revision bbaedc1b: Fix indent
Renato Botelho
05:15 PM Revision 2fef80c3: Change comment to match function
Renato Botelho
05:14 PM Revision 568ec5d9: Simplify logic
Renato Botelho
05:12 PM Revision 6c08d089: Remove unused variable
Renato Botelho
05:12 PM Revision 2548a32c: Initialize config item
Renato Botelho
05:11 PM Revision d0b8c0e9: Return 1 when config section is empty
Renato Botelho
05:10 PM Revision 2420538b: Break long line
Renato Botelho
05:09 PM Revision a51fbefa: Initialize config item and remove unneded var
Renato Botelho
04:55 PM Revision f75b5662: Initialize config item and remove unneded var
Renato Botelho
04:53 PM Revision d31d3e64: Merge pull request #4190 from vktg/remove00vti
Renato Botelho
02:11 PM Revision 9c6d6a06: Merge pull request #4427 from vktg/vtinodestroy
Renato Botelho
02:00 PM Revision 4740c4b1: Don't complain about SMTP port if service is disabled
Renato Botelho
01:56 PM Revision 2c133df1: Merge pull request #4447 from overtninja/master
Renato Botelho
01:32 PM Revision dac0e1f3: Merge pull request #4448 from vktg/dhcp6dnsprefix
Renato Botelho
01:31 PM Revision 50b721ac: Merge pull request #4444 from vktg/cpmacmask
Renato Botelho
01:30 PM Revision 2440f3bd: Merge pull request #4443 from vktg/unboundmultiip
Renato Botelho
01:29 PM Revision 2ff70d34: Merge pull request #4441 from vktg/floatrulesimp
Renato Botelho
01:29 PM Revision 688b4c29: Merge pull request #4440 from vktg/rmcpfiles
Renato Botelho
01:28 PM Revision babfff05: Merge pull request #4438 from vktg/staticroutestooltip
Renato Botelho
01:27 PM Revision 59e57ed3: Merge pull request #4257 from vktg/ovpnclientpass
Renato Botelho
01:26 PM Revision be1396d0: Merge pull request #4449 from vktg/dhcpv6rmrouterip
Renato Botelho
01:25 PM Revision db7f8fef: Merge pull request #4442 from vktg/dhcp6staticdns
Renato Botelho
01:24 PM Revision 0946ad1f: Merge pull request #4315 from vktg/localradiusauth
Renato Botelho
01:22 PM Revision 48d8bd79: Merge pull request #4450 from vktg/pppalias
Renato Botelho
12:31 PM Bug #9592 (Feedback): VTI interface down because interface number created is greater than ipsec32768
PR has been merged. Thanks! Renato Botelho
12:28 PM Revision 16091d6e: Fix backup of 'all' areas01~
Steve Beaver
12:22 PM Bug #10236: Cannot add more than 2 VMXNET3 Adapters in vSphere
I believe this to be a bug in the vSphere HOST Web GUI. I have run into very similar problems with other hardware co... Patrick Sanderson
11:27 AM Bug #7379 (Resolved): Virtual IPs/Proxy ARP: Not defined pid file on starting choparp.
works as expected on 2.5.0.a.20200916.1850
choparp is restarted on vip change
Viktor Gurov
11:10 AM pfSense Packages Bug #10911 (Resolved): Bandwidthd iframe not resizing in 2.4.5/2.4.5p1
Forum thread from several posters: https://forum.netgate.com/topic/152323/bandwidthd-in-pfsense-2-4-5
Looking at 2...
Steve Y
10:29 AM Feature #10392 (Resolved): GRE: Tunnels cannot have IPv6 and IPv4 addresses at the same time
tested on two 2.5.0.a.20200916.1850
works as expected:...
Viktor Gurov
10:19 AM Feature #10910 (Resolved): Backup/restore DHCP v4/v6 leases
Backup/restore dynamic DHCP leases files /var/dhcpd/var/db/dhcpd.leases and /var/dhcpd/var/db/dhcpd6.leases
in the...
Viktor Gurov
09:38 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
Moving the feature request since it's requesting a change to the kernel. Jim Pingle
08:55 AM pfSense Packages Feature #10909 (New): #define MAXVIFS 32 to 64
as discussed in this thread https://forum.netgate.com/topic/156398/deploy-disk-images-with-inter-vlans-mulicast/7
Is...
xavier Lemaire
09:12 AM Bug #10842 (Feedback): Not destroying VTI interfaces when booting before creating a new one
PR has been merged. Thanks! Renato Botelho
08:57 AM Feature #10495 (Feedback): Add support of Pushover API for notifications
PR has been merged. Thanks! Renato Botelho
08:34 AM pfSense Packages Feature #10908 (Feedback): FreeRADIUS server certificate not using full CA chain
https://forum.netgate.com/topic/153316/freeradius-acme-built-in-cert-manager-workarounds-with-intermediate-certificat... Viktor Gurov
08:33 AM Bug #7384 (Feedback): DHCPv6 doesn't merge IPv6 prefix with the input submitted in DNS servers field when using Track Interface IPv6 configuration parameter for the LAN interface.
PR has been merged. Thanks! Renato Botelho
08:32 AM Feature #2424 (Feedback): Allow masking of pass-thru MACs
PR has been merged. Thanks! Renato Botelho
08:31 AM Feature #10896 (Feedback): Multiple IPs for one DNS entry in unbound resolver override
PR has been merged. Thanks! Renato Botelho
08:30 AM Bug #10892 (Feedback): Large number of VLAN/LANs make floating rules are to read
PR has been merged. Thanks! Renato Botelho
08:29 AM Bug #10891 (Feedback): Captive Portal related files are not deleted after deleting CP zone in WebGUI
PR has been merged. Thanks! Renato Botelho
08:28 AM Bug #10889 (Feedback): Hover text missing from Static Routes Page
PR has been merged. Thanks! Renato Botelho
08:27 AM Bug #10409 (Feedback): OpenVPN client without userpass hangs system startup
PR has been merged. Thanks! Renato Botelho
08:26 AM Bug #9710 (Feedback): IPv6 RA: prefix option does not contain router address in spite of "R" flag being set
PR has been merged. Thanks! Renato Botelho
08:25 AM Bug #10882 (Feedback): DHCPv6 Static Mappings requires applying changes on DNS resolver setup
PR has been merged. Thanks! Renato Botelho
08:24 AM Feature #10545 (Feedback): RADIUS authenticated users should be able to log in via ssh
PR has been merged. Thanks! Renato Botelho
08:23 AM Bug #7132 (Feedback): PPPoE IP Alias
PR has been merged. Thanks! Renato Botelho
07:41 AM Bug #7132 (Pull Request Review): PPPoE IP Alias
Jim Pingle
03:00 AM Bug #7132: PPPoE IP Alias
https://github.com/pfsense/pfsense/pull/4450 Viktor Gurov
12:54 AM Bug #7132: PPPoE IP Alias
It's possible to use IP Alias on PPPoE interface by setting isp gw ip
https://forum.netgate.com/topic/147135/virtual...
Viktor Gurov
08:01 AM Bug #10906 (Resolved): can't download backup Crash report begins
This is already fixed in the repo. It was broken on the latest snapshot but works after a gitsync. Jim Pingle
05:29 AM Bug #10906: can't download backup Crash report begins
same problem with backup Area : RRD Data
empty config file and crash report
all other Area work ok
Manuel Piovan
05:08 AM Bug #10906 (Resolved): can't download backup Crash report begins
latest snpshot
only if I select backup area ALL
Crash report begins. Anonymous machine information:
amd64
1...
Manuel Piovan
07:57 AM Revision ec49a8af: Allow to use IP Alias on PPP interfaces. Issue #7132
Viktor Gurov
07:40 AM Feature #10904 (Pull Request Review): Support vti interfaces in dhcrelay
Jim Pingle
12:22 AM Feature #10904: Support vti interfaces in dhcrelay
PR for the binary part: https://github.com/pfsense/FreeBSD-ports/pull/935 Frederic Bor
12:19 AM Feature #10904 (Pull Request Review): Support vti interfaces in dhcrelay
One can want to relay dhcp requests using pfSense threw IPsec vti interfaces.
It's quite easy to support them, sin...
Frederic Bor
07:14 AM Bug #10850 (Duplicate): GoDaddy (v6) returns error when creating or updating
Jim Pingle
05:25 AM Bug #10850: GoDaddy (v6) returns error when creating or updating
Ok, looks like this can be closed then, since it's a duplicate. Sorry for that, didn't realize! Anonymous
05:22 AM Bug #10850: GoDaddy (v6) returns error when creating or updating
seems the same issue as #8432
dyndns client tries to use parent interface instead of gif/lagg etc.
Viktor Gurov
05:40 AM Bug #10836 (Resolved): TSO option does not fully toggle TSO on the interface
Tested on :... Danilo Zrenjanin
05:23 AM Bug #8432: Dynamic DNS Client gives an error that it can't find IPv6 address when WAN interface is a LAGG
seems the same issue as #10850 Viktor Gurov
03:07 AM pfSense Packages Bug #10905 (Resolved): Integration between captive portal and squid. Usernames are not showing in access.log file
https://forum.netgate.com/topic/147868/integration-between-captive-portal-and-squid-usernames-are-not-showing-in-acce... Viktor Gurov

09/16/2020

08:03 PM Revision c428cdf4: Rework route functions
- Created route_table() that returns an array containing all items from
route table. It uses --libxo to get a json...
Renato Botelho
05:33 PM Revision 530e157e: Support JSON format when retrieving XML to backup
Steve Beaver
10:31 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
I believe pf is only capable of symmetric NAT. I know pfSense pf is different from FreeBSD pf but I'm curious about t... Mike Smith
07:19 AM pfSense Packages Bug #5168 (Assigned): squid doesn't function during/after HA failover
I've tested it on 2.4.4_p3 - HA cluster with simple Squid config (Transparent mode) so Squid is active on both Primar... Azamat Khakimyanov
05:35 AM pfSense Packages Feature #10689 (Resolved): Squid Reverse proxy IPv6 and HA support
tested on:
2.5.0-DEVELOPMENT (amd64)
built on Wed Sep 16 01:00:40 EDT 2020
FreeBSD 12.2-PRERELEASE
Ticket reso...
Azamat Khakimyanov
03:27 AM Revision 187da3ef: Provide option for default notification tone to play, rather than being overridden.
overtninja

09/15/2020

05:06 PM Revision 595ae1aa: Include files used to provide logic for web pages now moved to /etc/inc/web
Steve Beaver
05:04 PM Revision 35273ccf: Include files used to provide logic for web pages now moved to /etc/inc/web
Steve Beaver
03:30 PM Revision 0ff4de47: Remove diag_backup control logic to backup.inc
Steve Beaver
10:20 AM Bug #10903: Poor handling of disk full conditions
Notifications like that happen using all available channels (GUI, mail, etc). There is no need for a separate ticket ... Jim Pingle
10:08 AM Bug #10903: Poor handling of disk full conditions
Jim Pingle wrote:
> As for notifying about disk space, there are already feature requests for that (Like #10467).
...
Alan Ingram
10:02 AM Bug #10903 (Duplicate): Poor handling of disk full conditions
The DNS Resolver question is one you should ask upstream to Unbound developers -- We can't control what it decides to... Jim Pingle
09:54 AM Bug #10903 (Duplicate): Poor handling of disk full conditions
The disk on our SG-3100 recently filled up to 100%. The only symptom was that the DNS Resolver service failed, meani... Alan Ingram
07:00 AM Revision 4002dc3f: Correct use of sprintf
overtninja
04:39 AM Revision 6b18e960: Correcting style issues
overtninja

09/14/2020

10:28 PM Revision 8f07b874: Ignore the UFS journal when pfSense tries to fix a disk corruption.
Not all UFS issues are present on journal, which can make the fsck miss some
issues.
This change improves the pfSens...
Luiz Souza
10:20 PM Revision 8d90b875: Ignore the UFS journal when pfSense tries to fix a disk corruption.
Not all UFS issues are present on journal, which can make the fsck miss some
issues.
This change improves the pfSens...
Luiz Souza
01:43 PM Revision 9462cc40: DHCPv6 do not announce Router Address. Issue #9710
Viktor Gurov
01:20 PM Revision 916fa8f9: DHCPv6 Static Mapping fix. Issue #10882
Viktor Gurov
10:51 AM Bug #10781 (Resolved): Incorrect env variables if admin user logged in via ssh
When replicating the behavior in 2.4.5_1 I was also seeing this error when making changes to the DNS Resolver:
The...
Max Leighton
10:45 AM Revision 7339f154: DHCPv6 merge IPv6 prefix for DNS servers. Fixes #7384
Viktor Gurov
09:36 AM Feature #7618 (Resolved): Add support for user-supplied Host-Uniq tag and handle PADM messages in Netgraph PPPoE
Resolved in #10597 Viktor Gurov
09:11 AM Bug #10882 (Pull Request Review): DHCPv6 Static Mappings requires applying changes on DNS resolver setup
Jim Pingle
09:10 AM Bug #9710 (Pull Request Review): IPv6 RA: prefix option does not contain router address in spite of "R" flag being set
Jim Pingle
08:50 AM Bug #9710: IPv6 RA: prefix option does not contain router address in spite of "R" flag being set
Right, https://tools.ietf.org/html/rfc6275#page-65:... Viktor Gurov
07:20 AM Bug #9710 (New): IPv6 RA: prefix option does not contain router address in spite of "R" flag being set
Jim Pingle
09:04 AM Bug #10889 (Pull Request Review): Hover text missing from Static Routes Page
Jim Pingle
09:03 AM Feature #10868 (Pull Request Review): Backup Captive Portal DB
Jim Pingle
08:58 AM Bug #10891 (Pull Request Review): Captive Portal related files are not deleted after deleting CP zone in WebGUI
Jim Pingle
08:58 AM Bug #10892 (Pull Request Review): Large number of VLAN/LANs make floating rules are to read
Jim Pingle
08:49 AM Feature #10896 (Pull Request Review): Multiple IPs for one DNS entry in unbound resolver override
Jim Pingle
08:43 AM Feature #2424 (Pull Request Review): Allow masking of pass-thru MACs
Jim Pingle
08:40 AM Bug #10898 (Pull Request Review): vxlan interfaces fail the interface mismatch check at boot.
Jim Pingle
12:19 AM Bug #10898: vxlan interfaces fail the interface mismatch check at boot.
correct link: https://github.com/pfsense/pfsense/pull/4445 Viktor Gurov
12:16 AM Bug #10898: vxlan interfaces fail the interface mismatch check at boot.
https://github.com/pfsense/pfsense/pull/4446 Viktor Gurov
08:40 AM Bug #10899 (Pull Request Review): VXVLAN interfaces are not created correctly
Jim Pingle
12:19 AM Bug #10899: VXVLAN interfaces are not created correctly
https://github.com/pfsense/pfsense/pull/4445 Viktor Gurov
08:35 AM Feature #10495 (Pull Request Review): Add support of Pushover API for notifications
Jim Pingle
05:07 AM Feature #10495: Add support of Pushover API for notifications
https://github.com/pfsense/pfsense/pull/4447 Viktor Gurov
08:21 AM Bug #7384 (Pull Request Review): DHCPv6 doesn't merge IPv6 prefix with the input submitted in DNS servers field when using Track Interface IPv6 configuration parameter for the LAN interface.
Jim Pingle
05:47 AM Bug #7384: DHCPv6 doesn't merge IPv6 prefix with the input submitted in DNS servers field when using Track Interface IPv6 configuration parameter for the LAN interface.
Fix:
https://github.com/pfsense/pfsense/pull/4448
Viktor Gurov
07:58 AM pfSense Packages Feature #10893 (Pull Request Review): TFTP package improvements
Jim Pingle
07:43 AM Feature #10894 (Closed): Display warning message on dashboard if interface assignment on HA nodes is incorrect
No, that isn't viable because the interfaces themselves don't have to be the same. They could be different drivers on... Jim Pingle
07:28 AM Bug #10902: 2.5.0. Authentication logging
I used firefox and it's fine there for me. Keep the discussion on the forum. Jim Pingle
07:27 AM Bug #10902: 2.5.0. Authentication logging
Please re-open.
I know now what is the problem. If I use Chrome I get same results as you.
If I use Firefox resul...
Greg M
07:16 AM Bug #10902 (Rejected): 2.5.0. Authentication logging
I can't reproduce this. Even on a stock 2.5.0, I login, it gets logged. I logout, it gets logged. Login again, it get... Jim Pingle
06:54 AM Bug #10902 (Rejected): 2.5.0. Authentication logging
As per this post https://forum.netgate.com/topic/156762/2-5-0-logging-authentication/4
Even clean 2.5.0 does not l...
Greg M
07:20 AM Feature #10890: Allow multiple assigned interfaces to track status of a single switch port
Not really a bug, but a feature request. Jim Pingle
07:17 AM Bug #10719 (Resolved): Gateway page displays mystery icons
Jim Pingle
06:31 AM Revision 18c256c0: Pushover Notification Support. Implements #10495
overtninja
05:48 AM Feature #7467 (Feedback): Add iPhone/Android/Generic USB tethering support
Renato Botelho
02:47 AM pfSense Docs Correction #10901: Feedback on Virtualization — VirtIO Driver Support
https://github.com/pfsense/docs/pull/137 Viktor Gurov
02:32 AM pfSense Docs Correction #10901 (Resolved): Feedback on Virtualization — VirtIO Driver Support
*Page:* https://docs.netgate.com/pfsense/en/latest/virtualization/virtio-driver-support.html
*Feedback:*
> Also...
Viktor Gurov
12:49 AM pfSense Packages Bug #10900: /packages/backup/backup.php?a=download&t=backup HTTP 504, or Sends PHP Error Message as ASCII/Text file Named pfsense.bak.tgz
- directory/file to backup: /
- size (of backup file): ~800MB
- filesystem space utilization: ~19% before backup, ~...
R M
12:11 AM pfSense Packages Bug #10900: /packages/backup/backup.php?a=download&t=backup HTTP 504, or Sends PHP Error Message as ASCII/Text file Named pfsense.bak.tgz
package: Backup
Please provide more information:
- directory/file to backup
- size
- filesystem space utilization
Viktor Gurov

09/13/2020

08:18 PM Bug #10795 (Resolved): WebGUI "Dashboard -> Services Status" widget issue
I was able to reproduce using the Service Status widget rather than the OpenVPN widget. The behavior can be seen in 2... Max Leighton
04:17 PM pfSense Packages Bug #10900 (Not a Bug): /packages/backup/backup.php?a=download&t=backup HTTP 504, or Sends PHP Error Message as ASCII/Text file Named pfsense.bak.tgz
h2. ISSUE
Unable to download pfsense.bak.tgz backup file via web GUI.
h2. STEPS TO REPRODUCE
# Go to */packa...
R M
04:06 PM Bug #1478 (Resolved): some characters in FW rule descriptions do not sync properly
Tested and verified working on:
2.5.0-DEVELOPMENT (amd64)
built on Sun Sep 13 13:04:14 EDT 2020
FreeBSD 12.2-PRE...
Max Leighton
03:02 PM Bug #10899 (Resolved): VXVLAN interfaces are not created correctly
VXLAN interfaces are created with a VXLANDEV interface when operating in unicast mode resulting in:... Steve Wheeler
02:52 PM Revision 32697119: Captive Portal MAC masking. Implements #2424
Viktor Gurov
12:56 PM Bug #10883 (Resolved): Parse error: syntax error alias-utils.inc
Tested on
2.5.0-DEVELOPMENT (amd64)
built on Sun Sep 13 07:01:46 EDT 2020
FreeBSD 12.2-PRERELEASE
This is now ...
Max Leighton
12:27 PM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
Seems related to #10716 Viktor Gurov
12:09 PM Bug #10898 (Resolved): vxlan interfaces fail the interface mismatch check at boot.
vxlans are not excluded from the list of interfaces to check like other sub-interface types so it fails:... Steve Wheeler
11:03 AM Bug #10706 (New): Kernel route table entries are removed if they match disabled static route entries
If a static route is disabled at run-time it is reasonable to expect it to be removed from the system routing table. ... Steve Wheeler
09:54 AM Feature #2424: Allow masking of pass-thru MACs
https://github.com/pfsense/pfsense/pull/4444 Viktor Gurov
08:23 AM Revision 03c0fd1e: Floating rules with large number of interfaces fix. Issue #10892
Viktor Gurov
08:21 AM Bug #4298: Excessive errors from snmpd
seems to be fixed in https://reviews.freebsd.org/rS335885
needs testing
Viktor Gurov
07:31 AM Revision dfd5754a: DNS Resolver multi IP for host overrides. Implements #10896
Viktor Gurov
06:54 AM Revision 298ecdb5: OpenVPN client userpass is mandatory. Issue #10409
Viktor Gurov
04:39 AM pfSense Packages Feature #10897: SNMPV3-trap/inform Add Snmpv3 trap/inform Field
Viktor Gurov wrote:
> http://www.net-snmp.org/docs/man/snmpd.conf.html:
> [...]
I didn't understand, do u meant th...
Depressed Admin
04:23 AM pfSense Packages Feature #10897: SNMPV3-trap/inform Add Snmpv3 trap/inform Field
http://www.net-snmp.org/docs/man/snmpd.conf.html:... Viktor Gurov
03:29 AM pfSense Packages Feature #10897 (Resolved): SNMPV3-trap/inform Add Snmpv3 trap/inform Field
There is no Field for snmpv3 trap/inform host , port .there is only snmpV2c/v1 trap,inform field
Plz add
Depressed Admin
03:46 AM Feature #10896: Multiple IPs for one DNS entry in unbound resolver override
see also #4350 Viktor Gurov
02:32 AM Feature #10896: Multiple IPs for one DNS entry in unbound resolver override
https://github.com/pfsense/pfsense/pull/4443 Viktor Gurov
12:41 AM Feature #10896: Multiple IPs for one DNS entry in unbound resolver override
see also #6881 Viktor Gurov
12:39 AM Feature #10896 (Resolved): Multiple IPs for one DNS entry in unbound resolver override
https://forum.netgate.com/topic/150778/multiple-ips-for-one-dns-entry-in-unbound-resolver-override:
I would want to ...
Viktor Gurov

09/12/2020

01:27 PM pfSense Docs Correction #10895 (Resolved): Feedback on Interface Types and Configuration — GIF (Generic tunnel InterFace)
*Page:* https://docs.netgate.com/pfsense/en/latest/interfaces/gif.html
*Feedback:*
Route Caching seems to have ...
Brandon Jackson
11:19 AM pfSense Packages Feature #10893: TFTP package improvements
https://github.com/pfsense/FreeBSD-ports/pull/928 Viktor Gurov
04:59 AM pfSense Packages Feature #10893 (Resolved): TFTP package improvements
https://forum.netgate.com/topic/115198/tftp-package-only-works-through-the-gui/2:
My suggestions for improving this ...
Viktor Gurov
11:00 AM Bug #9710: IPv6 RA: prefix option does not contain router address in spite of "R" flag being set
I think this would be dependent on Feature 6827, Add Proxy Mobile IPv6 (PMIPv6)
Rick Coats
10:56 AM Bug #9710: IPv6 RA: prefix option does not contain router address in spite of "R" flag being set
Feedback: This has been implemented incorrectly.
Tested on:
2.5.0-DEVELOPMENT (amd64)
built on Thu Sep 10 13:02:...
Rick Coats
10:07 AM Bug #10882: DHCPv6 Static Mappings requires applying changes on DNS resolver setup
https://github.com/pfsense/pfsense/pull/4442 Viktor Gurov
09:41 AM Revision 3b85b43b: Remove extra 00 padding of VTI interface names. Issue #9592
Viktor Gurov
07:53 AM Revision bf810e13: Delete Captive Portal related files. Fixes #10891
Viktor Gurov
07:09 AM Bug #10892: Large number of VLAN/LANs make floating rules are to read
Fix:
https://github.com/pfsense/pfsense/pull/4441
Viktor Gurov
03:10 AM Bug #10892: Large number of VLAN/LANs make floating rules are to read
Note there is a typo in the title -- meant to write "hard to read". Joe Slent
03:04 AM Bug #10892 (New): Large number of VLAN/LANs make floating rules are to read
Since the following commit for 2.4.5, the interface column was introduced for floating rules: https://redmine.pfsense... Joe Slent
06:20 AM Feature #10894 (Closed): Display warning message on dashboard if interface assignment on HA nodes is incorrect
During XMLRPC sync it is possible to sync and compare $config['interfaces'][<interface>]['if']
and show a warning me...
Viktor Gurov
06:16 AM Revision e8c2c6f2: OpenVPN+RADIUS+Cisco-AVPair IPv6 ACL. Issue #10454
Viktor Gurov
06:09 AM Revision 4a879d79: Add option to increase parallel IKEv1 Phase 2 rekeys. Issue #9331
Viktor Gurov
05:57 AM Revision 6639718c: Static Routes Page tooltips and help text. Fixes #10889
Viktor Gurov
04:27 AM pfSense Packages Bug #10815 (Resolved): FRR with SNMP AgentX option failed to start
You need to uninstall/install (not reinstall or update!) current FRR package to get frr7 with compiled-in snmp featur... Viktor Gurov
02:56 AM Bug #10891: Captive Portal related files are not deleted after deleting CP zone in WebGUI
https://github.com/pfsense/pfsense/pull/4440 Viktor Gurov
02:46 AM Bug #10891 (Resolved): Captive Portal related files are not deleted after deleting CP zone in WebGUI
If you remove Captive Portal Zone on the services_captiveportal_zones.php page,
related files are still there:
/var...
Viktor Gurov
02:42 AM Feature #10868: Backup Captive Portal DB
https://github.com/pfsense/pfsense/pull/4439 Viktor Gurov
02:40 AM Feature #10890 (New): Allow multiple assigned interfaces to track status of a single switch port
Let's assume we use PortX on a switch to trunk VLAN_1, VLAN_2, .., VLAN_N.
On each of these interfaces, we have two ...
Joe Slent
12:59 AM Bug #10889: Hover text missing from Static Routes Page
https://github.com/pfsense/pfsense/pull/4438 Viktor Gurov

09/11/2020

04:58 PM Bug #10889 (Resolved): Hover text missing from Static Routes Page
The enabled/disabled checkmarks are missing mouse-over help text for the "Enabled/Disabled" icons on system_routes.ph... Kris Phillips
04:54 PM Bug #10719: Gateway page displays mystery icons
Steve Beaver wrote:
> Applied in changeset commit:8326101f42ec638533f6a0831a6dac4f1c5aa279.
Tested patch on 2.4.5...
Kris Phillips
03:40 PM Bug #10861: net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
Thanks Ted, I missed the part about adding it as a tunnable. Marcos M
03:31 PM pfSense Docs Correction #10877 (Feedback): Feedback on VPN — IPsec — Configuring an IPsec Remote Access Mobile VPN using IKEv2 with EAP-MSCHAPv2
Marcos M
03:30 PM pfSense Docs Correction #10877: Feedback on VPN — IPsec — Configuring an IPsec Remote Access Mobile VPN using IKEv2 with EAP-MSCHAPv2
https://github.com/pfsense/docs/pull/136 Marcos M
10:23 AM pfSense Packages Bug #9895: snort reinstallation failed
Unable to reproduce this on 2.5.0.a.20200910.1250. Michael Spears
08:53 AM Bug #10888 (Not a Bug): XG-7100 on latest 2.5.0 (September 2020) - no internet connectivity for LAN clients
I updated my XG-7100 to the latest 2.5.0 snapshot today and connected a LAN client, it pulled an IP address, could re... Jim Pingle
06:40 AM Bug #10881: Captive Portal with AD authentication can be bypassed with just a valid username, no password required
Viktor Gurov wrote:
>
> Please check the "Add option to (dis)allow unauthenticated LDAP binds" feature #9909
Th...
Aurelian Rau

09/10/2020

10:43 PM pfSense Packages Bug #10815: FRR with SNMP AgentX option failed to start
enabling agentx option made the system stuck and after 2 or 3 reboots system crashed.
agentx option enabled on Z...
Alhusein Zawi
09:25 PM Revision 174cb4df: Style: Break a couple of long lines
Renato Botelho
09:24 PM Revision 56d8a9b0: Combine nested conditionals into a single one
Renato Botelho
09:22 PM Revision 32aaba3d: Remove commented out lines
Renato Botelho
09:22 PM Revision efe0fec5: Combine nested conditionals into a single one
Renato Botelho
09:19 PM Revision ff64a57d: Style: Break a couple of long lines
Renato Botelho
09:18 PM Revision c2488bab: Same address can't be IPv4 and IPv6 at the same time
Renato Botelho
08:54 PM Revision 33f28cc5: Style: break long line
Renato Botelho
06:35 PM Bug #10888 (Not a Bug): XG-7100 on latest 2.5.0 (September 2020) - no internet connectivity for LAN clients
Original discussion - https://www.reddit.com/r/PFSENSE/comments/iqcsxw/latest_pfsense_250_breaks_internet_connectivit... Victor Hooi
03:47 PM Bug #10397: Changing default or static route gateway on 2.5.0 does not remove old route
I'll work on it
Renato Botelho
09:55 AM Bug #10397: Changing default or static route gateway on 2.5.0 does not remove old route
This is correct and working as intended.
With the multi-path routes, the gateway cannot be changed, but all other ...
Luiz Souza
01:39 PM Feature #9130: Request ID [#INC-16195]: DHCP - PXE Boot
Eric Lochtefeld wrote:
> I wanted to follow up with issue 765 (https://redmine.pfsense.org/issues/765) and see if we...
Nathan Revo
12:13 PM Bug #10694 (Resolved): Firewall Alias does not allow an ipv6 network alias in the format x:x:x:x:x:x:d.d.d.d where the 'd's are the decimal values of the four low-order 8-bit pieces of the address (standard IPv4 representation)
Jim Pingle
12:12 PM Bug #10694: Firewall Alias does not allow an ipv6 network alias in the format x:x:x:x:x:x:d.d.d.d where the 'd's are the decimal values of the four low-order 8-bit pieces of the address (standard IPv4 representation)
Feedback:
I loaded a 2.5.0-Development on a VM
2.5.0-DEVELOPMENT (amd64)
built on Wed Sep 09 19:46:45 EDT 2020
...
Rick Coats
12:11 PM Feature #10878: Allow DHCP HA "split" to be configured in the GUI
https://kb.isc.org/docs/isc-dhcp-41-manual-pages-dhcpdconf
> The split statement
>
> split bits;
>
> The spl...
Jim Pingle
12:46 AM Feature #10878: Allow DHCP HA "split" to be configured in the GUI
Jim Pingle wrote:
> The current behavior is correct and as intended, and as suggested in the ISC docs. The two will ...
Evren Yurtesen
12:08 PM pfSense Packages Feature #10816: Allow FRR BGP Neighbors to be active in both IPv4 and IPv6
This has nothing to do with networks to distribute or similar route controls. This only controls whether or not BGP w... Jim Pingle
12:06 PM Bug #10852 (Duplicate): Double Traffic Graph
Jim Pingle
11:55 AM Bug #9506: Dynamic DNS update notification sent even if IP address didn't change
I also have this same problem with 2.4.4-RELEASE-p2. I see other people have reported this issue over the years too:
...
Jeremy  99
06:29 AM pfSense Packages Bug #10770 (Resolved): arpwatch: cannot remove email once it has been entered into settings
Renato Botelho
12:00 AM pfSense Packages Bug #10770: arpwatch: cannot remove email once it has been entered into settings
I did not receive Email notifications.
email added.
there was a change in arp database
no notification.
I was...
Alhusein Zawi
04:38 AM Bug #10835 (Resolved): Verification on the interface group name length is not correct
Tested on :... Danilo Zrenjanin
04:23 AM Feature #10637 (Resolved): Turn of spell checking on package upgrade progress textarea
Tested on:
2.5.0-DEVELOPMENT (amd64)
built on Thu Sep 10 01:03:22 EDT 2020
FreeBSD 12.2-PRERELEASE
No spell che...
Azamat Khakimyanov
04:08 AM pfSense Packages Feature #9521 (Resolved): Upgrade to HAProxy 1.9
Tested on :
2.4.5-RELEASE-p1 (amd64)
built on Tue Jun 02 17:51:17 EDT 2020
FreeBSD 11.3-STABLE
and
2.5.0-DEVELOP...
Azamat Khakimyanov
03:55 AM pfSense Packages Feature #10441 (Resolved): Integration of bfd daemon
Tested on :
2.5.0-DEVELOPMENT (amd64)
built on Thu Sep 10 01:03:22 EDT 2020
FreeBSD 12.2-PRERELEASE
- integrate b...
Azamat Khakimyanov
12:33 AM Feature #10874: getting base system'
Jim Pingle wrote:
> I don't see a compelling case for adding this to the dashboard, for most it would be confusing/v...
Vinícius Zavam

09/09/2020

10:19 PM Bug #10852: Double Traffic Graph
See also #10812 → luckman212
10:19 PM pfSense Packages Feature #10816: Allow FRR BGP Neighbors to be active in both IPv4 and IPv6
it does not Redistribute connected networks(IPv6) and Kernel(IPv6) . Alhusein Zawi
10:16 PM pfSense Packages Feature #10816: Allow FRR BGP Neighbors to be active in both IPv4 and IPv6
it is working if the network(IPv6) added to "Networks to Distribute" Alhusein Zawi
10:18 PM Bug #10812: Traffic graph shows 2X the actual traffic on VLAN interfaces.
I notice #10852 also seems to be the same issue. → luckman212
09:53 PM Bug #9643: Limiters do not function properly on 2.5 snapshots
Here are the limiters and firewall floating rule I used. When the firewall rule is enabled, no traffic gets through t... Abhinav Tella
08:41 PM Bug #9643: Limiters do not function properly on 2.5 snapshots
Can you give me more details ? show me your rules and results ? Luiz Souza
05:35 PM Bug #9643: Limiters do not function properly on 2.5 snapshots
Still broken for me on the latest build, I tested just now. Abhinav Tella
03:52 PM Bug #9643 (Feedback): Limiters do not function properly on 2.5 snapshots
Can someone confirm this is still broken with a current snapshot ?
I was able to set up a floating rule and the li...
Luiz Souza
04:42 PM Bug #10703 (Resolved): OpenVPN copy doesn't save auth_pass
Tested and working in 2.5.0
built on Wed Sep 09 01:01:28 EDT 2020
Marking this ticket resolved
Max Leighton
04:25 PM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
I was observing similar behavior on an SG-3100 to XG-1537 VTI tunnel (both 2.4.5-p1 w/ patch and recommended P1 setti... Kyle Mulligan
02:02 PM Feature #10887 (Rejected): Unify DNS Host Overrides in Resolver and Forwarder
Eventually the forwarder will be removed so it doesn't make sense to expend effort here which will eventually make th... Jim Pingle
01:51 PM Feature #10887 (Rejected): Unify DNS Host Overrides in Resolver and Forwarder
There is no reason why two separate host-override systems should be used. It only serves to make managing a lot of o... Jon V
01:34 PM pfSense Packages Bug #10886 (Closed): NAT64 allows to bypass pfBlockerNG IPv4 feed list
If NAT64 is used, the firewall first checks the rules and then translates IPv6 to IPv4.
In this case, if IPv4 feeds ...
Viktor Gurov
01:05 PM Bug #10881: Captive Portal with AD authentication can be bypassed with just a valid username, no password required
Aurelian Rau wrote:
> Jim Pingle wrote:
> > If the remote access server is accepting the login, what could pfSense ...
Viktor Gurov
10:29 AM Bug #10881: Captive Portal with AD authentication can be bypassed with just a valid username, no password required
*pfSense is not allowing this behavior. AD is.* pfSense can't fix your AD security or configuration. Period.
Havin...
Jim Pingle
10:07 AM Bug #10881: Captive Portal with AD authentication can be bypassed with just a valid username, no password required
Jim Pingle wrote:
> If the remote access server is accepting the login, what could pfSense do differently? pfSense s...
Aurelian Rau
07:55 AM Bug #10881 (Not a Bug): Captive Portal with AD authentication can be bypassed with just a valid username, no password required
If the remote access server is accepting the login, what could pfSense do differently? pfSense sends the request and ... Jim Pingle
02:39 AM Bug #10881 (Not a Bug): Captive Portal with AD authentication can be bypassed with just a valid username, no password required
We have observed that we can login to the Captive Portal with a valid username and no password (we have it set up to ... Aurelian Rau
12:26 PM Feature #10635 (Resolved): status.php: Add DNS Resolver configuration
Tested and working on:
2.5.0-DEVELOPMENT (amd64)
built on Wed Sep 09 01:01:28 EDT 2020
Marking this ticket as ...
Max Leighton
09:46 AM Bug #10206: VIP alias-ip's disappear from nic (caused by running ifconfig twice.?.)
Found the regression.
For the record, this only affects the kernels built with RADIX_MPATH.
Luiz Souza
09:33 AM Revision d3b6a2f3: Merge pull request #4437 from kiokoman/patch-1
Steve Beaver
09:21 AM Revision 46cc9653: Update alias-utils.inc
Manuel Piovan
07:46 AM pfSense Packages Bug #10884 (Pull Request Review): wrong link on haproxy-devel
Jim Pingle
04:30 AM pfSense Packages Bug #10884: wrong link on haproxy-devel
PR https://github.com/pfsense/FreeBSD-ports/pull/926 Manuel Piovan
04:13 AM pfSense Packages Bug #10884 (Resolved): wrong link on haproxy-devel
haproxy-devel
if you click on
"related log entries"
https://*/status_pkglogs.php?pkg=haproxy-devel
lead to ...
Manuel Piovan
07:41 AM Bug #10883 (Feedback): Parse error: syntax error alias-utils.inc
PR has been merged Jim Pingle
04:23 AM Bug #10883: Parse error: syntax error alias-utils.inc
PR https://github.com/pfsense/pfsense/pull/4437 Manuel Piovan
04:08 AM Bug #10883 (Resolved): Parse error: syntax error alias-utils.inc
when you click on alias
PHP Parse error: syntax error, unexpected '.', expecting ';' or ',' in /etc/inc/alias-utils....
Manuel Piovan
06:36 AM Bug #7132: PPPoE IP Alias
Tested on :... Danilo Zrenjanin
06:08 AM Bug #9097 (Resolved): ECL can't locate config.xml unless device is MBR-partitioned
Danilo Zrenjanin
06:07 AM Bug #9097: ECL can't locate config.xml unless device is MBR-partitioned
Tested on :
2.5.0-DEVELOPMENT (amd64)
built on Mon Sep 07 19:04:05 EDT 2020
FreeBSD 12.2-PRERELEASE
I was able ...
Danilo Zrenjanin
05:33 AM pfSense Packages Feature #8216: Add prometheus output for telegraf
wait, its already there and works!
no need to do anything, except perhaps adding some hint to the Web UI at _Servi...
Bernd Klaus
05:20 AM pfSense Packages Feature #8216: Add prometheus output for telegraf
this would be really nice cause it obsoletes running a InfluxDB server just to get the metrics viewable in Grafana.
...
Bernd Klaus
04:19 AM pfSense Packages Bug #10885: HAProxy DNS statistics not working
package is haproxy-devel Manuel Piovan
04:18 AM pfSense Packages Bug #10885 (Resolved): HAProxy DNS statistics not working
if you click on Stat / DNS statistic
the table is not working
/haproxy/haproxy_stats.php?showstatresolvers=globalre...
Manuel Piovan
03:13 AM Bug #10882 (Resolved): DHCPv6 Static Mappings requires applying changes on DNS resolver setup
I noticed that the hostname entered into DHCPv6 Static Mappings have not been resolvable until I applied changes at t... Danilo Zrenjanin

09/08/2020

09:52 PM Revision 051a5f35: Build ipfw_nat64 kernel module in preparation for PR 4405 merge
Renato Botelho
08:59 PM Bug #10861: net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
Marcos Mendoza wrote:
> I can confirm that running the command fixes the filter reload symptom, though that fix does...
Ted Quade
03:33 PM Bug #10861: net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
I can confirm that running the command fixes the filter reload symptom, though that fix doesn't persist through reboo... Marcos M
06:52 PM Revision 238d678e: Merge pull request #4435 from vktg/pppoeacctupdatefix
Renato Botelho
06:52 PM Revision 9431c929: Merge pull request #4431 from vktg/cpusedmacsbackup
Renato Botelho
02:14 PM Bug #8156 (Resolved): Prefix not being included in DNS entry registered by DHCP6 server
Replicated on :
2.4.5-RELEASE-p1 (arm)
built on Tue Jun 02 17:45:24 EDT 2020
FreeBSD 11.3-STABLE...
Danilo Zrenjanin
02:00 PM pfSense Packages Bug #9809 (Feedback): postgresql support not compiled
PR has been merged. Thanks! Renato Botelho
08:22 AM pfSense Packages Bug #9809 (Pull Request Review): postgresql support not compiled
Jim Pingle
01:56 PM pfSense Packages Feature #10871 (Feedback): Extra time period counters for SQL backend
PR has been merged. Thanks! Renato Botelho
08:16 AM pfSense Packages Feature #10871 (Pull Request Review): Extra time period counters for SQL backend
Jim Pingle
01:53 PM Feature #10811: Randomize time of scheduled AutoConfigBackup runs
Proposing: 503 Service Unavailable with randomized retry between 5-10min or implement serverside async queueing. Vincent Jansen
01:53 PM Feature #10856 (Feedback): Backup/Restore Captive Portal usedmacs DB
PR has been merged. Thanks! Renato Botelho
01:53 PM Bug #10869 (Feedback): "Accounting updates" not working in PPPoE config page
PR has been merged. Thanks! Renato Botelho
07:56 AM Bug #10869 (Pull Request Review): "Accounting updates" not working in PPPoE config page
Jim Pingle
01:52 PM Bug #10880: AutoConfigBackup - Internal Server Error
Agree.
Proposing: 503 Service Unavailable with randomized retry between 5-10min or implement serverside async queueing.
Vincent Jansen
01:15 PM Bug #10880 (Duplicate): AutoConfigBackup - Internal Server Error
Almost certainly a duplicate of #10811 Jim Pingle
01:10 PM Bug #10880 (Duplicate): AutoConfigBackup - Internal Server Error
Error occures sometimes on scheduled backup.
No error when trigger manually.
Don't understand why it happened on th...
Vincent Jansen
01:42 PM Revision c67d5c83: Access from saveAlias()
Steve Beaver
10:46 AM Bug #10879 (Duplicate): SSH lockout table - Bogons IPv6 table to large and blocks firewall re-loading (and upon reboot) locks up all LAN traffic to internet
It is the same as the other issue. It has nothing to do with bogons or sshguard themselves, so suggestions about thos... Jim Pingle
10:18 AM Bug #10879: SSH lockout table - Bogons IPv6 table to large and blocks firewall re-loading (and upon reboot) locks up all LAN traffic to internet
Probably the same issue as https://redmine.pfsense.org/issues/10861

andreas vesalius
10:05 AM Bug #10879 (Duplicate): SSH lockout table - Bogons IPv6 table to large and blocks firewall re-loading (and upon reboot) locks up all LAN traffic to internet
The firewall rules do not load, due to some SSH 'lockout table complaining there are too many bogonsv6 from /etc/bogo... Eric Veum
09:00 AM Feature #10878 (Needs Patch): Allow DHCP HA "split" to be configured in the GUI
The current behavior is correct and as intended, and as suggested in the ISC docs. The two will work in a coordinated... Jim Pingle
08:47 AM Feature #10878 (Needs Patch): Allow DHCP HA "split" to be configured in the GUI
When a master/backup setup is made using CARP. Pfsense sets `split 128` in master's dhcpd.conf file and this causes i... Evren Yurtesen
08:15 AM Feature #10870 (Pull Request Review): Allow custom IPSEC NAT-T port
Jim Pingle
07:32 AM Bug #10876 (Duplicate): Large URL table alias expansion no longer works
Duplicate of #10861 Jim Pingle
07:31 AM Feature #10874 (Rejected): getting base system'
I don't see a compelling case for adding this to the dashboard, for most it would be confusing/visual clutter. If you... Jim Pingle
07:12 AM Bug #10873 (Rejected): Algo VPN's IPSec appears to have added name constraints on their CA cert and pfsense can't handle it
Reading over all that, I fail to see anything actionable on pfSense for it. Someone in the thread mentions trying to ... Jim Pingle
06:36 AM Feature #9639: Cloudflare DDNS "API Token"
PR: https://github.com/pfsense/pfsense/pull/4195 Renato Botelho

09/07/2020

06:00 PM pfSense Docs Correction #10877 (Resolved): Feedback on VPN — IPsec — Configuring an IPsec Remote Access Mobile VPN using IKEv2 with EAP-MSCHAPv2
*Page:* https://docs.netgate.com/pfsense/en/latest/recipes/ipsec-mobile-ikev2-eap-mschapv2.html
*Feedback:*
The...
Steve Wheeler
04:09 PM Bug #10876: Large URL table alias expansion no longer works
Error:
There were error(s) loading the rules: /tmp/rules.debug:21: cannot define table bogons6: too many elements. -...
Marcos M
03:42 PM Bug #10876 (Duplicate): Large URL table alias expansion no longer works
At some point after the nightly build of pfSense-CE-2.5.0-DEVELOPMENT-amd64-20200831-1250.iso, the URL table alias po... Marcos M
10:08 AM Bug #10797 (Resolved): status.php: Sanitize MaxMind GeoIP key
Tested in 2.5.
<pfblockerng>
<maxmind_key>xxxxx</maxmind_key>
<ntopng>
<maxmind_key>xxxxx</maxmind_key>
...
Max Leighton
08:31 AM Bug #10875 (New): PPP periodic reset does not fully restore gateway group round-robin functionality
I'm using a Multi-WAN setup with two links working in a load-balancer fashion.
I set up a periodic reset for both...
Daniel Pereira
04:43 AM Feature #10874: getting base system'
:facepalm:
how can I edit this ticket's title and information?
it was totally created by accident when I was prep...
Vinícius Zavam
04:42 AM Feature #10874 (Rejected): getting base system'
Vinícius Zavam
03:25 AM pfSense Packages Bug #9809: postgresql support not compiled
Remove feature from package:
https://github.com/pfsense/FreeBSD-ports/pull/925
Viktor Gurov
02:58 AM Bug #3487 (Closed): Punctuation removed when replicating rule descriptions from primary to secondary
fixed in #1478 Viktor Gurov
02:22 AM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
I have successfully used your patch and suggested settings on a pair of SG-3100s. There i have two tunnels to AWS tha... Marc L
12:27 AM Bug #10873 (Rejected): Algo VPN's IPSec appears to have added name constraints on their CA cert and pfsense can't handle it
This PR in algo IPS VPN configurator broke its compatibility with pfsense in its default configuration:
https://gith...
David Ross

09/06/2020

10:48 AM pfSense Packages Feature #10872 (Resolved): Add adjustable notification for Severity Alert
As of know Surricata package requires a syslog software to allow for notification of an alert. Please integrate this ... Anton Palmgard
06:13 AM Revision e181a70f: PPPoE Server Accounting Update fix. Issue #10869
Viktor Gurov
03:40 AM pfSense Packages Feature #10871: Extra time period counters for SQL backend
https://github.com/pfsense/FreeBSD-ports/pull/924 Viktor Gurov
03:32 AM pfSense Packages Feature #10871 (Feedback): Extra time period counters for SQL backend
Enable extra SQL time period counters from /usr/local/etc/raddb/mods-config/sql/counter/*sql/:
dailycounter - Max-Da...
Viktor Gurov
03:05 AM Feature #10870: Allow custom IPSEC NAT-T port
PR: https://github.com/pfsense/pfsense/pull/4436 Frederic Bor
03:00 AM Feature #10870 (Resolved): Allow custom IPSEC NAT-T port
One can need to change the default IPSEC NAT-T port on client and/or server side.
This is supported on strongSwan:...
Frederic Bor
01:17 AM Bug #10869: "Accounting updates" not working in PPPoE config page
Fix:
https://github.com/pfsense/pfsense/pull/4435
Viktor Gurov
01:01 AM Bug #10869 (Resolved): "Accounting updates" not working in PPPoE config page
https://forum.netgate.com/topic/155633/pppoe-radius-radius-accounting-update-not-working/8:
For some reason, "Accoun...
Viktor Gurov

09/05/2020

05:45 PM Bug #10861: net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
Reproduced on my firewall running latest dev snapshot. Encountered
There were error(s) loading the rules: /tmp/rule...
Michael Spears
04:40 PM Revision 23c4cd2d: Merge branch 'master' into cpusedmacsbackup
vktg
11:53 AM Bug #10610: Package upgrade or reinstall hangs indefintely on the console
Issue is also present with other packages, like squidGuard (but not squid).
Duplicate bug I opened, but am refer...
Kris Phillips
11:27 AM Feature #10868 (Resolved): Backup Captive Portal DB
Backup CaptivePortal DB files /var/db/captiveportal<zone>.db to keep connected users after restore
See also #3128 ...
Viktor Gurov
11:00 AM pfSense Packages Bug #10867 (Duplicate): squidGuard Package Hangs on Uninstall or Upgrade
Same root issue as #10610, it's a problem in pkg that Renato is already investigating. Jim Pingle
10:55 AM pfSense Packages Bug #10867 (Resolved): squidGuard Package Hangs on Uninstall or Upgrade
Tested on two different appliances (SG-1100 and XG-7100), but likely affects all appliances. If you try to upgrade s... Kris Phillips
09:46 AM pfSense Docs Todo #10866: "block bogon networks" silently blocks IPv6 client solicitations to DHCPv6 Server RA "managed" or "assisted"
Block bogon networks should never be used on internal interfaces, only WANs. That has always been true for both IPv4 ... Jim Pingle
09:37 AM pfSense Docs Todo #10866 (Resolved): "block bogon networks" silently blocks IPv6 client solicitations to DHCPv6 Server RA "managed" or "assisted"
# Problem
For interfaces configured with IPv6, if `Block bogon networks` is enabled, the associated DHCPv6 Server ...
Chase Turner
06:51 AM Revision 9185bfff: Backup/restore Captive Portal UsedMACs. Implements #10856
Viktor Gurov
01:21 AM pfSense Packages Feature #10865: squidGuard lacks options to send traffic action logs to syslog server
This is supported only by squidGuard-1.5-beta, see https://fossies.org/linux/www/squidGuard-1.5-beta.tar.gz/squidGuar... Viktor Gurov
12:18 AM pfSense Packages Feature #10858 (Resolved): OpenVPN Client silent install
1.4.23_2 - works as expected Viktor Gurov

09/04/2020

09:55 PM pfSense Packages Feature #10865 (Rejected): squidGuard lacks options to send traffic action logs to syslog server
squidGuard has options to send logs to squid's logs, but these don't seem to arrive at a syslog server and are only l... Kris Phillips
06:44 PM Revision da94bf92: Merge pull request #4434 from vktg/ddnsname
Renato Botelho
06:44 PM Revision cca03f5c: Merge pull request #4433 from vktg/cpusedmacsha
Renato Botelho
02:16 PM Revision 07588052: DHCP service DDNS key name RFC2845 compat. Fixes #10844
Viktor Gurov
01:49 PM pfSense Packages Feature #10858 (Feedback): OpenVPN Client silent install
PR has been merged. Thanks! Renato Botelho
09:38 AM pfSense Packages Feature #10858 (Pull Request Review): OpenVPN Client silent install
Jim Pingle
08:58 AM pfSense Packages Feature #10858: OpenVPN Client silent install
https://github.com/pfsense/FreeBSD-ports/pull/922 Viktor Gurov
01:44 PM Bug #10857 (Feedback): Captive Portal usedmacs DB is not copied to backup HA node
PR has been merged. Thanks! Renato Botelho
09:37 AM Bug #10857 (Pull Request Review): Captive Portal usedmacs DB is not copied to backup HA node
Jim Pingle
06:12 AM Bug #10857: Captive Portal usedmacs DB is not copied to backup HA node
https://github.com/pfsense/pfsense/pull/4433 Viktor Gurov
01:44 PM Bug #10844 (Feedback): DHCPv6 service Dynamic DNS revisions made to fix Bug #10346 violates RFC/is too restrictive
PR has been merged. Thanks! Renato Botelho
09:39 AM Bug #10844 (Pull Request Review): DHCPv6 service Dynamic DNS revisions made to fix Bug #10346 violates RFC/is too restrictive
Jim Pingle
09:19 AM Bug #10844: DHCPv6 service Dynamic DNS revisions made to fix Bug #10346 violates RFC/is too restrictive
Fix:
https://github.com/pfsense/pfsense/pull/4434
Viktor Gurov
12:56 PM Bug #10795: WebGUI "Dashboard -> Services Status" widget issue
I am not sure what versions are affected but I can define OpenVPN description using dots. e.g. <<Tunnel to office.dom... Danilo Zrenjanin
11:08 AM Revision a81a6edc: Captive Portal UsedMACs sync. Issue #10857
Viktor Gurov
09:54 AM Bug #10594: add QLogic 10 Gigabit Ethernet driver (qlxgb) to the ALTQ-capable list
Tested on:
2.5.0-DEVELOPMENT (amd64)
built on Fri Sep 04 00:59:55 EDT 2020
FreeBSD 12.2-PRERELEASE...
Danilo Zrenjanin
09:18 AM Bug #10864 (Resolved): firewall_aliases.php broken
If there was an issue here, it was probably fixed by commit:be14a3697e0f607f71b3c6ca1ea7bc01c50ff189 or commit:6bd064... Jim Pingle
02:12 AM Bug #10864: firewall_aliases.php broken
there is no /etc/inc/alias.inc on the 2.5.0.a.20200903.1850 but /etc/inc/alias-utils.inc Viktor Gurov
08:45 AM Revision be14a369: rename alias.inc in firewall_alias.php
Steve Beaver
03:21 AM Bug #10794 (Resolved): HAProxy Stats page credentials are not redacted in status.php
Tested on :
2.5.0-DEVELOPMENT (amd64)
built on Thu Sep 03 19:02:32 EDT 2020
FreeBSD 12.2-PRERELEASE
HAProxy Sta...
Danilo Zrenjanin
03:03 AM Bug #10524 (Resolved): Bridge that includes a GIF interface does not come up at boot
I was able to reproduce the bug on 2.4.5-p1
Retested on:
2.5.0-DEVELOPMENT (amd64)
built on Thu Sep 03 19:02:32 ...
Danilo Zrenjanin
12:17 AM Feature #4591: IPSec Failover Support for IP Addresses instead of Dynamic DNS / Failover Group
see also https://wiki.strongswan.org/issues/2823 Viktor Gurov

09/03/2020

08:07 PM Revision 6bd064f7: alias.inc changed to alias-utils.inc
Steve Beaver
04:41 PM Bug #10864 (Resolved): firewall_aliases.php broken
For the last several versions I've noticed this error using the web gui on an SG-5100. When trying to view Firewall A... Craig Weber
02:09 PM Revision eb34ab35: Update obsoleted files list for 2.5.0
Renato Botelho
10:55 AM Revision 18b41bd9: Remove commented out lines
Renato Botelho
10:54 AM Revision 55ac1551: Fix file name on copyright notice
Renato Botelho
08:36 AM Feature #10863 (Rejected): Add option for ARPING to occur on CARP promoted to MASTER
CARP already sends a gratuitous ARP when it assumes control. If your environment needs additional nudging, that isn't... Jim Pingle
08:00 AM Feature #10863 (Rejected): Add option for ARPING to occur on CARP promoted to MASTER
Hi all,
Coming across an issue where I have different servers on different DC's, switching provided by external co...
Ricardo Mendes

09/02/2020

01:55 PM Revision 925737f2: Fix syntax error in alias.inc
Steve Beaver
01:29 PM Bug #10773 (Resolved): if_em VLAN interfaces wont pass traffic after reboot
Luiz Souza
01:01 PM Bug #10862 (Rejected): There were error(s) loading the rules: /tmp/rules.debug:20: cannot define table bogonsv6: too many elements. -
Not enough detail here, but probably a duplicate of #10861 assuming you are running 2.5.0, if not, post on the forum ... Jim Pingle
12:52 PM Bug #10862: There were error(s) loading the rules: /tmp/rules.debug:20: cannot define table bogonsv6: too many elements. -
Hello, following the last update, no more internet, here is the error. Manuel Romero
12:50 PM Bug #10862 (Rejected): There were error(s) loading the rules: /tmp/rules.debug:20: cannot define table bogonsv6: too many elements. -
There were error(s) loading the rules: /tmp/rules.debug:20: cannot define table bogonsv6: too many elements. - The li... Manuel Romero
09:58 AM Bug #10861: net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
Most likely Jim Pingle
09:56 AM Bug #10861: net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
Does it have something to do with r364456? Steve Harrington
08:20 AM Bug #10861 (Resolved): net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
The value of @net.pf.request_maxcount@ is @65535@ at boot on the latest 2.5.0 snapshot, despite a higher value being ... Jim Pingle
08:21 AM Bug #10254: pf error "too many elements" when attempting to load large tables
This issue is quite old and resolved in a previous version. I created a new issue for the regression after confirming... Jim Pingle
02:04 AM Bug #10254: pf error "too many elements" when attempting to load large tables
Just upgraded today to 2.5.0.a.20200901.2100, hitting exact same issue. Seems like regression.
Every reboot have t...
Dmitry Fill
08:00 AM Bug #10860 (Duplicate): group names must be max 15 character
Jim Pingle
04:11 AM Bug #10860: group names must be max 15 character
i can't delete it now
sorry duplicate of #10835
Manuel Piovan
03:57 AM Bug #10860 (Duplicate): group names must be max 15 character
... Manuel Piovan
07:55 AM Bug #10765: Ampersands in ldap_extended_query are escaped twice
That is an unsupported add-on, and a rare use case. You are welcome to submit a PR with a fix, but it's not something... Jim Pingle
05:20 AM Bug #10765: Ampersands in ldap_extended_query are escaped twice
Hello, I am surprised that this issue hasn't been assigned to anybody in 2 months. Is there anything I can do to give... Louis Sautier

09/01/2020

07:32 PM Revision bff96b22: Moved controller logic out of display file and into .inc file
Steve Beaver
05:50 PM Bug #10773: if_em VLAN interfaces wont pass traffic after reboot
Thanks Luiz. Yes. The most recent snapshot fixes this issue. Steve Harrington
09:34 AM Bug #10773 (Feedback): if_em VLAN interfaces wont pass traffic after reboot
which just happened. the 2.5 sources were rebased and this fix is already applied.
Please let us know if the prob...
Luiz Souza
04:41 PM Feature #2668: Support aliases in OpenVPN local/remote/tunnel network fields
This is an incredibly important feature for anyone managing a large network. We only have 18 sites and the string for... Justin Bauer
12:20 PM pfSense Packages Feature #10859 (Resolved): Add avahi filtering feature to pfSense
Two parts to the issue;
1) Package needs to be updated from upstream to get new filtering feature added in avahi ...
Joachim Tingvold

08/31/2020

08:06 PM Revision a903e9a6: Move alias delete functionality to inc file so other processes can access it
Steve Beaver
05:44 PM Revision b53eb95a: Merge pull request #4421 from vktg/vxlangui
Renato Botelho
02:54 PM Feature #10856 (Pull Request Review): Backup/Restore Captive Portal usedmacs DB
Jim Pingle
09:31 AM Feature #10856: Backup/Restore Captive Portal usedmacs DB
https://github.com/pfsense/pfsense/pull/4431 Viktor Gurov
08:06 AM Feature #10856 (Resolved): Backup/Restore Captive Portal usedmacs DB
/var/db/captiveportal_usedmacs_<cpzone>.db files used by "Pass-through credits per MAC address" feature are not in th... Viktor Gurov
02:48 PM Revision b6ea9c61: VXLAN configuration WebGUI. Feature #6240
Viktor Gurov
12:51 PM pfSense Packages Feature #10779 (Feedback): HAProxy SSL/TLS Compatibility Mode
PR has been merged. Thanks! Renato Botelho
07:31 AM pfSense Packages Feature #10779 (Pull Request Review): HAProxy SSL/TLS Compatibility Mode
Jim Pingle
03:27 AM pfSense Packages Feature #10779: HAProxy SSL/TLS Compatibility Mode
Improvement:
https://github.com/pfsense/FreeBSD-ports/pull/921
Viktor Gurov
12:45 PM Feature #6240 (Feedback): vxlan driver
PR has been merged. Thanks! Renato Botelho
12:05 PM pfSense Packages Feature #10858 (Resolved): OpenVPN Client silent install
Allow to use openvpn client export windows installers for unattended deploy
Currently it's possible to create sile...
Viktor Gurov
08:09 AM Bug #10857 (Resolved): Captive Portal usedmacs DB is not copied to backup HA node
/var/db/captiveportal_usedmacs_<cpzone>.db files used by "Pass-through credits per MAC address" feature are not copie... Viktor Gurov
07:27 AM Bug #10855 (Rejected): Error when executing playback thu pfSsh.php (Fatal error: Cannot redeclare usage())
That isn't a supported method to run multiple playback scripts, they each expect to be run in their own environment.
...
Jim Pingle
02:00 AM Bug #10855: Error when executing playback thu pfSsh.php (Fatal error: Cannot redeclare usage())
Fix:
https://github.com/pfsense/pfsense/pull/4430
Viktor Gurov

08/30/2020

03:33 PM Bug #10840 (Resolved): status.php: Sanitize Net-SNMP community
Tested patch on 2.4.5_1. Community tag is obfuscated as expected. Resolving the ticket.
<netsnmpcommunities>
<commu...
Max Leighton
10:00 AM Bug #10855 (Rejected): Error when executing playback thu pfSsh.php (Fatal error: Cannot redeclare usage())
Input file :
[2.5.0-DEVELOPMENT][admin@example.com]/root: cat -vet ipsec.txt
playback svc stop ipse...
Marcus Oliveira

08/29/2020

09:42 AM Bug #7096: Unbound fails to start on boot if specific network devices are configured in the "Network Interfaces"
I may be experiencing the same issue. More testing is required, but at the least Unbound is not starting, and I am b... Arthur Moore

08/27/2020

03:07 PM Feature #10826 (Resolved): Support for Domeneshop DDNS
Jim Pingle
02:57 PM Feature #10826: Support for Domeneshop DDNS
confirmed to be working on latest 2.5 development snapshot Idar Lund
01:41 PM Revision c3cada8b: Merge pull request #4230 from vktg/ipsecp2shunt
Renato Botelho
01:39 PM Revision 7dcdbf6d: Merge pull request #4414 from jturnism/patch-1
Renato Botelho
01:38 PM Revision ac2e5383: Merge pull request #4429 from basicmonkey/master
Renato Botelho
01:38 PM Revision 960b4c95: Merge pull request #4428 from Marc05/master
Renato Botelho
01:38 PM Revision d45c476a: Remove deprecated hash module
Renato Botelho
12:30 PM Revision dbc1b8ee: Fix some illegal string offset errors. Issue #10659
Jim Pingle
08:41 AM Bug #10846 (Feedback): Icon area within buttons are not clickable
PR has been merged. Thanks! Renato Botelho
08:41 AM Bug #10847 (Feedback): Mobile user IPSec (PSK+Xauth) fails at user auth with PHP error
PR has been merged. Thanks! Renato Botelho
08:41 AM Feature #10837 (Feedback): Update wizardapp.inc XBox and Wii ports
PR has been merged. Thanks! Renato Botelho
08:41 AM Feature #3329 (Feedback): Allow creating "not" rules for IPsec Phase 2
PR has been merged. Thanks! Renato Botelho
08:01 AM Todo #10659 (Feedback): PHP: Update to 7.4.x
Done Renato Botelho
02:34 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
Any update on this? I experience the very same problem on version 2.4.4-RELEASE-p3 (amd64). alex alex

08/26/2020

03:52 PM Revision b2186003: Remove the /usr/libexec/telnetd from the default installation.
There is no reason to keep a telnet daemon. Luiz Souza
11:21 AM Bug #10780 (Resolved): net.inet.ip.dummynet.* values are ignored
Tested the patch on 2.4.5-p1, it works perfect. Danilo Zrenjanin
09:41 AM Bug #10854 (Not a Bug): DHCPv6 Server assigns addresses from outside of specified range (Regression from 2.4.4)
That's not a bug, it's doing exactly what you asked. IPv6 addresses are hexidecimal, not decimal. 100-150 in hex incl... Jim Pingle
09:40 AM Bug #10854: DHCPv6 Server assigns addresses from outside of specified range (Regression from 2.4.4)
NOTE: I tried editing the specified range and re-saving to restart the DHCPv6 server to see if that resolved the issu... Jason Cohen
09:38 AM Bug #10854 (Not a Bug): DHCPv6 Server assigns addresses from outside of specified range (Regression from 2.4.4)
The DHCPv6 server appears to be ignoring the specified range when assigning addresses. For example, I set one of my ... Jason Cohen
07:50 AM Feature #2358: NAT64 support
Viktor Gurov wrote:
> IPFW NAT64 kernel support:
> https://github.com/pfsense/FreeBSD-src/pull/35
As it is merge...
Jens Groh
07:45 AM pfSense Packages Bug #10824 (Resolved): BIND shutdown - dynamic zones, unclean shutdown causes startup to not load zones
Jim Pingle
02:48 AM pfSense Packages Bug #10824: BIND shutdown - dynamic zones, unclean shutdown causes startup to not load zones
Renato Botelho wrote:
> PR has been merged. Thanks!
Updated to bind 9.14_8, which includes this fix - rc.d scrip...
Dave Tickem
07:45 AM pfSense Packages Bug #10823 (Resolved): named.conf "controls" section missing IPv6 localhost on IPv6 enabled PFsense - breaking rndc
Jim Pingle
02:45 AM pfSense Packages Bug #10823: named.conf "controls" section missing IPv6 localhost on IPv6 enabled PFsense - breaking rndc
Renato Botelho wrote:
> PR has been merged. Thanks!
Updated to bind 9.14_8, which includes this fix - works as r...
Dave Tickem
07:45 AM pfSense Packages Bug #10832 (Resolved): Bind DNSSEC validation "deselected" not disabling DNSSEC validation
Jim Pingle
02:44 AM pfSense Packages Bug #10832: Bind DNSSEC validation "deselected" not disabling DNSSEC validation
Renato Botelho wrote:
> PR has been merged. Thanks!
Updated to bind 9.14_8, which includes this fix - works as r...
Dave Tickem
 

Also available in: Atom