Project

General

Profile

Activity

From 09/16/2020 to 10/15/2020

10/15/2020

11:38 PM Feature #7406 (Resolved): Ability to clear all dhcp leases at once
Alhusein Zawi
11:37 PM Feature #7406: Ability to clear all dhcp leases at once
Feature has been added and working.
Alhusein Zawi
08:36 PM pfSense Packages Bug #10983 (Rejected): pfBlockerNG not cleaning everything behind it
I moved from PI-Hole to pfBlockerNG for a while. I chose to move back to PI-Hole and stopped using pfBlockerNG. After... Jacques Bourdeau
07:38 PM Revision 0de6758e: Fix #9450
Change default value for clear_alarm to true so cache file is used only
once. We can't be sure the value on cache wi...
Renato Botelho
07:38 PM Revision ffedcdf4: Replace unlink() by unlink_if_exists()
Renato Botelho
06:11 PM Revision 626e247e: Merge pull request #4481 from wurzelpanzer/master
Renato Botelho
05:43 PM Revision 449fdf25: Fix #10978: Run rc.local and rc.local.running
Fix the logic used to detect if rc.local and/or rc.local.running are or
not running and execute them only when it's n...
Renato Botelho
03:09 PM Bug #10982 (Resolved): Primary/Secondary DNS Server field validation issue in Setup Wizard
When clearing out the Primary/Secondary DNS Server fields in the Setup Wizard it causes the validation to fail. An em... Jared Dillard
02:58 PM Feature #7284 (Resolved): NTPd Autoset GPS device baud rate
Anonymous
02:45 PM Bug #9450 (Feedback): Multiwan gateway group fail-over not working as expected (possible race condition)
Applied in changeset commit:0de6758e2893e4390acfa0b55e31b1dece231618. Renato Botelho
02:27 PM Bug #9450 (In Progress): Multiwan gateway group fail-over not working as expected (possible race condition)
Some problems reported at https://forum.netgate.com/topic/157633/wan-gw-monitor/2 after this was merged. I'll work o... Renato Botelho
02:27 PM Bug #10981 (Duplicate): Display of gw monitoring not working
Lets keep all information on original ticket #9450 Renato Botelho
01:56 PM Bug #10981 (Duplicate): Display of gw monitoring not working
Hi.
See post: https://forum.netgate.com/topic/157633/wan-gw-monitor/2
Something broke dpinger in last 2 days.
Greg M
01:39 PM Bug #9539 (Resolved): HA: admin user's authorized key(s) won't get synced
Tested in
2.5.0-DEVELOPMENT (amd64)
built on Thu Oct 15 07:04:11 EDT 2020
FreeBSD 12.2-STABLE
With the Synchr...
Max Leighton
01:11 PM Feature #10972 (Feedback): Add IPv6 DDNS support for easyDNS
PR has been merged. Thanks! Renato Botelho
01:06 PM Bug #10980 (Resolved): ``/etc/rc.local`` script content is executed at login instead of during boot sequence
See https://redmine.pfsense.org/issues/10978 for context.
/etc/skel/.profile is copied to .profile in all users ho...
alzee bum
01:02 PM pfSense Packages Feature #10969 (Feedback): Add Sekhan/TheGreatWall DoH feeds
PR has been merged. Thanks! Renato Botelho
01:02 PM pfSense Packages Bug #10927 (Feedback): pfBlockerNG-devel fullfill the pfsense config history when RAM disk in use
PR has been merged. Thanks! Renato Botelho
12:56 PM pfSense Packages Bug #4247 (Feedback): Changes not saved when expression list becomes empty
PR has been merged. Thanks! Renato Botelho
07:22 AM pfSense Packages Bug #4247: Changes not saved when expression list becomes empty
https://github.com/pfsense/FreeBSD-ports/pull/964 Viktor Gurov
12:56 PM Bug #10978 (Resolved): rc.initial tries to execute rc.local.running even if it doesn't exist, and even if it is already running.
alzee bum wrote:
> Renato Botelho wrote:
> > Applied in changeset commit:449fdf250171616d4865bfd5c865c64035e14496.
...
Renato Botelho
12:52 PM Bug #10978: rc.initial tries to execute rc.local.running even if it doesn't exist, and even if it is already running.
Renato Botelho wrote:
> Applied in changeset commit:449fdf250171616d4865bfd5c865c64035e14496.
Thanks Renato, that...
alzee bum
12:50 PM Bug #10978: rc.initial tries to execute rc.local.running even if it doesn't exist, and even if it is already running.
Applied in changeset commit:449fdf250171616d4865bfd5c865c64035e14496. Renato Botelho
12:44 PM Bug #10978 (Feedback): rc.initial tries to execute rc.local.running even if it doesn't exist, and even if it is already running.
Renato Botelho
12:01 PM Bug #10978 (Resolved): rc.initial tries to execute rc.local.running even if it doesn't exist, and even if it is already running.
See code here: https://github.com/pfsense/pfsense/blob/master/src/etc/rc.initial#L33
Lines 33-46 check for rc.loca...
alzee bum
12:54 PM pfSense Packages Bug #10447: Framed-IP-Address with plus sign is deprecated
PR has been merged. Thanks! Renato Botelho
12:46 PM pfSense Docs Correction #10979 (Closed): Status Light on XG-7100
The status light on the XG-7100 is currently not implemented. It should be added to the docs that this light is unus... Kris Phillips
11:02 AM Bug #10947: Virtual interface assignment can't be done in CLI interface assignment
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/14 Viktor Gurov
10:43 AM Revision 4798939d: IPsec bypass WebGUI fix. Issue #10977
Viktor Gurov
08:36 AM Revision c6d22ee1: VLAN MTU extra fix. Issue #9154
Viktor Gurov
05:44 AM Bug #10977 (Feedback): Additional IPsec bypass rules input validation
PR has been merged. Thanks! Renato Botelho
01:31 AM Bug #10977: Additional IPsec bypass rules input validation
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/12 Viktor Gurov
05:41 AM Bug #9154: Editing a VLAN parent interface causes all VLANs to be reconfigured, which can lead to problems
Viktor Gurov wrote:
> extra improvement:
> https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/13
Merged...
Renato Botelho
03:41 AM Bug #9154: Editing a VLAN parent interface causes all VLANs to be reconfigured, which can lead to problems
extra improvement:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/13
Viktor Gurov

10/14/2020

05:38 PM Bug #10977: Additional IPsec bypass rules input validation
And just seen that box needs updating but still present in:... Steve Wheeler
05:36 PM Bug #10977 (Resolved): Additional IPsec bypass rules input validation
Trying to save the save the IPSec Advanced Settings page, even without making any changes, results in an input error ... Steve Wheeler
04:04 PM Revision 2e1cfbf9: UDP/Other protocols state timeout. Implements #1635
Viktor Gurov
04:04 PM Revision c91be02b: Nested alias IDN fix. Issue #10968
Viktor Gurov
03:56 PM Revision a9fc44f0: Style fixes
Renato Botelho
03:56 PM Revision 161e60fa: Add missing parameter to get_dpinger_status() call
Renato Botelho
03:56 PM Revision 5affb137: Prevent possible race condition, fixes #9450
Instead of calling get_dpinger_status() again in the code handling dpinger
alarms, save the original alarm status in ...
Vladimir Voskoboynikov
03:56 PM Revision 094db492: Minor text fix. Issue #10546
No need to log the PID, it's added to the logs anyways. Vladimir Voskoboynikov
03:56 PM Revision 04a72a97: Add gateway substatus. Fixes #10546
Update return_gateways_status to return a substatus as well as the existing status.
status changed to be one of onli...
Vladimir Voskoboynikov
03:54 PM Revision 6fe2387c: Clean NDP table button. Implements #10975
Viktor Gurov
03:52 PM Revision 69ffb456: VLAN MTU improvements. Issue #9154
Viktor Gurov
03:48 PM Revision 7957389b: Interface assignment fix for PPP interfaces. Fixes #10240
Viktor Gurov
02:42 PM Bug #10236: Cannot add more than 2 VMXNET3 Adapters in vSphere
With some more investigation I've found the following:
*Created a new single vmxnet3 nic VM.*...
Patrick Sanderson
01:59 PM Bug #10236: Cannot add more than 2 VMXNET3 Adapters in vSphere
I've diff'd the VMX files between creating a VM with 2 nics (which works) and creating a VM with 1 NIC and attempting... Patrick Sanderson
01:48 PM Bug #10960: Bring up VXLANs correctly at boot
With that change the vxlans on WAN are created then destroyed and re-created at boot. Somehow the vxlans on WAN are b... Steve Wheeler
12:06 PM Bug #10960: Bring up VXLANs correctly at boot
first issue fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/11
Viktor Gurov
01:32 PM Bug #10902: 2.5.0. Authentication logging
Nice catch
I caught it via siem when logs got missing
Greg M
01:22 PM Bug #10902 (Confirmed): 2.5.0. Authentication logging
I have replicated this a number of times but didn't spot it until now. I only noticed it does not 'beep' when you log... Steve Wheeler
01:29 PM pfSense Packages Bug #10332 (Closed): PFBlockerNG loading GeoLite2-Country.mmdb
Indeed it does! Marcos M
11:15 AM Bug #1635: timeout setting on firewall rules does not work for UDP
Applied in changeset commit:2e1cfbf9957a559a49af37c00f07db8854950ae3. Viktor Gurov
11:06 AM Bug #1635 (Feedback): timeout setting on firewall rules does not work for UDP
PR has been merged. Thanks! Renato Botelho
11:05 AM Bug #9450: Multiwan gateway group fail-over not working as expected (possible race condition)
Applied in changeset commit:5affb137561c74bb5559f0706c86c28a85b14557. Vladimir Voskoboynikov
11:01 AM Bug #9450 (Feedback): Multiwan gateway group fail-over not working as expected (possible race condition)
PR has been merged. Thanks! Renato Botelho
11:05 AM Bug #10546: Gateways removed from routing groups based on low alert thresholds
Applied in changeset commit:04a72a975d4e59f5ad8bc9fd41df10c6a1f0ed7e. Vladimir Voskoboynikov
11:01 AM Bug #10546 (Feedback): Gateways removed from routing groups based on low alert thresholds
PR has been merged. Thanks! Renato Botelho
11:05 AM Bug #10968 (Feedback): Mixed & Upper case Alias table names broken.
PR has been merged. Thanks! Renato Botelho
11:00 AM Feature #10975: Button to clear the NDP cache
Applied in changeset commit:6fe2387c445d49ca828aa2c0ed00d9a2c842037f. Viktor Gurov
10:55 AM Feature #10975 (Feedback): Button to clear the NDP cache
PR has been merged. Thanks! Renato Botelho
03:49 AM Feature #10975: Button to clear the NDP cache
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/8 Viktor Gurov
03:31 AM Feature #10975 (Resolved): Button to clear the NDP cache
It would be nice to have a button to clear the NDP cache in "Diagnostics: NDP Table".
same as #4038
Viktor Gurov
10:54 AM Bug #9136 (Feedback): IPv6 Tracking Interfaces Lose IPv6 Address in Certain Cases
Jim, could you validate if the problem still happens after fix for #9154 was applied? Renato Botelho
10:53 AM Bug #9154 (Feedback): Editing a VLAN parent interface causes all VLANs to be reconfigured, which can lead to problems
PR has been merged. Thanks! Renato Botelho
09:33 AM Bug #9154: Editing a VLAN parent interface causes all VLANs to be reconfigured, which can lead to problems
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/6 Viktor Gurov
10:51 AM Bug #10240 (Feedback): Incorrect interface assignment after switching from PPPoE
PR has been merged. Thanks! Renato Botelho
10:20 AM pfSense Packages Bug #10976 (Rejected): Freeradius dont start with SQL configuration
no such issue on pfSense 2.5.0.a.20201013.1850 with FreeRADIUS pkg 0.15.7_18:... Viktor Gurov
07:08 AM pfSense Packages Bug #10976 (Rejected): Freeradius dont start with SQL configuration
My Pfsense is 2.5
I tried run freeradius with mysql suport but the freeradius dont start. the follow error occur:
...
Teste Teste
09:33 AM Bug #10974: pfSense showing unspecified DHCP assignment range
So I confirmed this morning it is still doling out leases in that range after I'd manually deleted them all last nigh... Mark Whitworth
04:04 AM pfSense Packages Feature #9742 (Resolved): Print Patch ID in log while patching
Tested on :... Danilo Zrenjanin
03:22 AM Bug #8131: No way to configure static ARP entries on a /31 (need a better way to configure static ARP entries)
duplicate of #2622 Viktor Gurov
03:16 AM pfSense Packages Bug #10447: Framed-IP-Address with plus sign is deprecated
Danilo Zrenjanin wrote:
> Tested on :
> [...]
>
> I still can enter 192.0.2.32+ with no complaints from pfSense....
Viktor Gurov
02:53 AM pfSense Packages Bug #10447: Framed-IP-Address with plus sign is deprecated
Tested on :... Danilo Zrenjanin
03:03 AM pfSense Packages Bug #10927: pfBlockerNG-devel fullfill the pfsense config history when RAM disk in use
Fix:
https://github.com/pfsense/FreeBSD-ports/pull/962
Viktor Gurov
01:17 AM pfSense Packages Bug #10502: LLDP spamming errors on Netgate XG-7100
Renato Botelho wrote:
> DRago_Angel [InV@DER] wrote:
> > So maybe we can track this issue https://github.com/vincen...
Viktor Gurov
01:06 AM pfSense Packages Feature #10969: Add Sekhan/TheGreatWall DoH feeds
https://github.com/pfsense/FreeBSD-ports/pull/961 Viktor Gurov

10/13/2020

11:12 PM Bug #10974 (Rejected): pfSense showing unspecified DHCP assignment range
pfSense is assigning addresses from 2 ranges in my VLAN_GUEST space. Some time ago I used that .90-.191 range, but no... Mark Whitworth
08:39 PM Revision 7d813139: Fix #10680: Rewrite cache system in interfaces.inc
Change it to not invalidate cache when not needed. Makes boot much faster
when we have many VLANs
Jonas Christoffersen
08:39 PM Revision 4320bc83: Fix #10589: Skip disabling staticarp on boot
Also implemented is a simplification of code to handle static ARP entries. Jonas Christoffersen
04:32 PM pfSense Packages Bug #10502 (In Progress): LLDP spamming errors on Netgate XG-7100
There is no PR waiting for review Renato Botelho
04:28 PM pfSense Packages Bug #10502: LLDP spamming errors on Netgate XG-7100
DRago_Angel [InV@DER] wrote:
> So maybe we can track this issue https://github.com/vincentbernat/lldpd/issues/394 an...
Renato Botelho
03:45 PM Bug #10680 (Feedback): Improve interface caching when we have many interfaces
Applied in changeset commit:7d8131393dbd7aca507cddade443af41a27fec80. Jonas Christoffersen
03:45 PM Bug #10589 (Feedback): interfaces_staticarp_configure() doesnt need to disable staticarp on boot
Applied in changeset commit:4320bc83ae45c8ebc827e3c60065578264cba532. Jonas Christoffersen
11:04 AM pfSense Packages Feature #10134 (Resolved): pfSense-pkg-softflowd: Add additional options available in softflowd-1.0.0
Tested on 2.4.5_p1 and on 2.5.0-DEVELOPMENT (built on Tue Oct 13 07:05:06 EDT 2020)
MAC Address Flow Tracking Leve...
Azamat Khakimyanov
10:55 AM pfSense Packages Feature #10893 (Resolved): TFTP package improvements
Tested on 2.4.5_p1 and on 2.5.0-DEVELOPMENT (built on Tue Oct 13 07:05:06 EDT 2020).
"Write access" and "Logging" ...
Azamat Khakimyanov
07:32 AM pfSense Packages Bug #10964 (Feedback): pfSense-pkg-frr 0.6.8_4 does not use default ospf area if one is not defined on the interface.
Renato Botelho
07:31 AM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
PR has been merged. Thanks! Renato Botelho
04:04 AM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
Chris Evans wrote:
> I'm just going in and adding/removing a fake neighbor to see if it would cause my valid BGP nei...
Ben Hughes
07:26 AM pfSense Packages Feature #10909 (Needs Patch): #define MAXVIFS 32 to 64
FreeBSD changes are merged. Waiting for pimd patch Renato Botelho
07:25 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
xavier Lemaire wrote:
> do i need to open another request for the pimd part?
Please do it
Renato Botelho

10/12/2020

10:59 PM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
Ben Hughes wrote:
> Chris Evans wrote:
> > I'm still seeing BGP neighbor resets when changes are being made, I beli...
Chris Evans
03:34 AM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
Chris Evans wrote:
> I'm still seeing BGP neighbor resets when changes are being made, I believed this effort was to...
Ben Hughes
03:32 PM Feature #10603 (Resolved): Handle -c commands with arguments in rc.initial
Anonymous
03:31 PM Bug #9058 (In Progress): Kernel panic during L2TP retransmit
Anonymous
12:12 PM Revision dccd106a: Fixed #10406 By adding "notoggleall" class to button group
Steve Beaver
12:05 PM Revision 8fa31d5e: Merge pull request #4470 from vktg/cleardhcpleases
Renato Botelho
12:04 PM Revision 085e12a1: Merge pull request #4478 from vktg/ddnsstatic
Renato Botelho
12:03 PM Revision 55aaa49d: Merge pull request #4472 from vktg/ntpauth
Renato Botelho
12:03 PM Revision 3cd0307f: Merge pull request #4480 from rdlugosz/add-helptext-for-unbound-dhcp
Renato Botelho
11:56 AM Bug #9459 (Resolved): patch pf: silence a runtime warning pfr_update_stats: assertion failed.
No response from OP. Assumed fixed Anonymous
11:55 AM Bug #9548 (Resolved): Do not use VLANMTU flag to decide if interface supports to run VLAN
No activity for ten months Anonymous
11:52 AM Bug #10776 (Closed): filterlog: Loopback source/destination sometimes reports 127.0.0.1 as 127.0.01
No response from OP in three months Anonymous
10:44 AM pfSense Packages Feature #10769 (Resolved): Prevent users from creating new ACMEv1 keys
Tested on 2.4.5_p1 and on 2.5.0-DEVELOPMENT (built on Mon Oct 12 07:05:15 EDT 2020)
There is no option to create L...
Azamat Khakimyanov
09:02 AM pfSense Docs Correction #10973 (Resolved): Feedback on Services — DHCPv6 Server
*Page:* https://docs.netgate.com/pfsense/en/latest/services/dhcp/ipv6.html
*Feedback:*
> _The Prefix Delegati...
Chris Linstruth
08:22 AM Feature #7405: Ability to add dhcp host reservations from "Diagnostics -> ARP table"
Hi,
Any chance for this to be implemented?
ml 35
07:47 AM Bug #6598 (Resolved): "PPPoE clients" placeholder in rules only includes first PPPoE server instance
Renato Botelho
07:45 AM Feature #7287 (New): NTP add support for ACTS ref clock
Renato Botelho
07:45 AM pfSense Packages Bug #7797 (Feedback): Squid Reverse Proxy alternating between destinations
PR has been merged Renato Botelho
07:44 AM pfSense Packages Bug #9211 (Feedback): GeoIP broken in pfSense-pkg-ntopng-0.8.13_3
PR has been merged Renato Botelho
07:44 AM Bug #9539 (Feedback): HA: admin user's authorized key(s) won't get synced
PR https://github.com/pfsense/pfsense/pull/4221 was merged and should fix this Renato Botelho
07:42 AM pfSense Packages Feature #9588 (Duplicate): New package: node_exporter
Duplicate of #9974 Renato Botelho
07:40 AM pfSense Packages Feature #9902 (Resolved): add sticky filter for Alert Log please
Already resolved Renato Botelho
07:39 AM Feature #9970 (New): Captive Portal and SAML2 Integration
Renato Botelho
07:39 AM pfSense Packages Bug #9981 (Resolved): Suricata "Use IP Reputation Lists on this interface." actually defaults to ON, despite incorrect comment.
Already resolved Renato Botelho
07:38 AM Bug #10161 (Resolved): Improve renaming of pfSense in non-pfSense builds.
This was resolved months ago Renato Botelho
07:38 AM Feature #10280 (New): DHCP Leases widget
Renato Botelho
07:37 AM pfSense Packages Bug #10447 (Feedback): Framed-IP-Address with plus sign is deprecated
PR was merged months ago Renato Botelho
07:29 AM pfSense Packages Feature #9721 (Feedback): add squidclient -h 127.0.0.1 mgr:info output to Diagnostics / Squid and status.php
PR has been merged. Thanks! Renato Botelho
07:26 AM pfSense Packages Feature #10950 (Feedback): Allow to select only netmap-compatible cards for inline mode
PR has been merged. Thanks! Renato Botelho
07:26 AM pfSense Packages Bug #10911 (Feedback): Bandwidthd iframe not resizing in 2.4.5/2.4.5p1
PR has been merged. Thanks! Renato Botelho
07:20 AM Bug #10406: Interfaces.php PPPoE selection display inappropriate "Toggle All" button when periodic reset set to "pre-set"
Applied in changeset commit:dccd106aa51a96b9a275858495539571f8701e6d. Anonymous
07:14 AM Bug #10406 (Feedback): Interfaces.php PPPoE selection display inappropriate "Toggle All" button when periodic reset set to "pre-set"
... Anonymous
07:12 AM Feature #1257: Handle encypted CA/Certificate private keys
Moving to Future due to lack of activity on proposed Pull Request Renato Botelho
07:11 AM Feature #2146 (Feedback): Allow concurrent logins when using vouchers
Already resolved by #9432. Leaving it in feedback for confirmation Renato Botelho
07:09 AM Bug #7778 (Feedback): DHCP relay not working correctly with bridges
PR merged months ago Renato Botelho
07:09 AM Bug #9437 (Feedback): Captive Portal Bandwidth Limiter application issue (Credentials Vs. MacAddr Validation)
PR was merged in June Renato Botelho
07:07 AM Feature #10214 (Feedback): Allow IPsec duplicate endpoints
As mentioned by Viktor on comment 6, fixed by another PR Renato Botelho
07:05 AM Feature #8794 (Feedback): NTP authentication support
PR has been merged. Thanks! Renato Botelho
07:05 AM Bug #10224 (Feedback): DHCP DDNS does not add zone entries for keys when using static host DDNS definitions
PR has been merged. Thanks! Renato Botelho
07:05 AM Feature #7406 (Feedback): Ability to clear all dhcp leases at once
PR has been merged. Thanks! Renato Botelho
06:29 AM Bug #10968: Mixed & Upper case Alias table names broken.
Viktor already have a patch to fix this one Renato Botelho
04:42 AM Feature #10322: Force ipv4/ipv6 DNS resolution for NTP servers
I'm facing the same bug. I have an IPv4-only network with IPv6 disabled in pfSense, but my DNS servers reply with bot... Monseigneur Phelypeaux

10/11/2020

10:41 PM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
I'm still seeing BGP neighbor resets when changes are being made, I believed this effort was to make it so full reloa... Chris Evans
04:56 PM Bug #10891 (Resolved): Captive Portal related files are not deleted after deleting CP zone in WebGUI
Tested in
2.5.0-DEVELOPMENT (amd64)
built on Sun Oct 11 13:01:59 EDT 2020
FreeBSD 12.2-STABLE
confirmed that ...
Max Leighton
03:25 PM Revision 00105b36: easyDNS IPv6 DynDNS support
This adds support for IPv6 records to easyDNS DynDNS.
https://redmine.pfsense.org/issues/10972
wurzelpanzer
01:39 PM Todo #10533: Change default domain for new installations from "localdomain" to "home.arpa"
There is also a Draft (2017) https://tools.ietf.org/html/draft-wkumari-dnsop-internal-00 also expired (2018) that pro... Rick Coats
01:32 PM Todo #10533: Change default domain for new installations from "localdomain" to "home.arpa"
→ luckman212 wrote:
> I'd suggest one of the following instead, since many pfSense installs are not used in home env...
Rick Coats
10:59 AM Feature #8149: NTPsec
Last commit was 6 years ago .. https://github.com/bsdphk/Ntimed
Allright, thank you for your feedback anyways!
Wilhelm Johansen
10:40 AM Bug #10960 (Confirmed): Bring up VXLANs correctly at boot
Tested:... Steve Wheeler
10:33 AM Feature #10972: Add IPv6 DDNS support for easyDNS
https://github.com/pfsense/pfsense/pull/4481 Mischa De Pol
10:13 AM Feature #10972 (Resolved): Add IPv6 DDNS support for easyDNS
Add support for easyDNS.com IPv6 dynamic DNS update.
This is based on the existing easyDNS.com IPv4 service.
ht...
Mischa De Pol
10:32 AM Bug #10899 (Resolved): VXVLAN interfaces are not created correctly
Tested:... Steve Wheeler
10:05 AM Bug #10898 (Resolved): vxlan interfaces fail the interface mismatch check at boot.
Tested in:... Steve Wheeler

10/10/2020

04:52 PM pfSense Packages Bug #10332: PFBlockerNG loading GeoLite2-Country.mmdb
It appears that this was fixed.
https://github.com/pfsense/FreeBSD-ports/commit/2eae4ebc337619fb4f6f32979968394649...
John Clark
12:36 PM pfSense Packages Bug #10332: PFBlockerNG loading GeoLite2-Country.mmdb
I could not reproduce this on pfSense 2.4.5-p1 running pfBlockerNG-devel 2.2.5_36.
Looking under /usr/local/share/...
Marcos M
04:45 PM Bug #1635: timeout setting on firewall rules does not work for UDP
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/10 Viktor Gurov
04:11 PM Feature #939 (Closed): Ability to restore specific areas of configuration backup from full config backup
already works on 2.4.4-p3 and higher Viktor Gurov
04:04 PM Todo #10464: Don't change the current update repo when new releases are available
Hello Craig,
This is not a bug report and we recommend you open a ticket with our support team.
Kris Phillips
03:54 PM pfSense Packages Bug #10886: NAT64 allows to bypass pfBlockerNG IPv4 feed list
I don't know if this is possible, but a more intuitive solution is to have a "interface" for NAT64 (non-intuitively i... Rick Coats
12:48 PM Feature #10970 (Closed): UI/GUI has an issue scrolling while drop menue is clicked/open
This is really essentially a duplicate of:
https://redmine.pfsense.org/issues/10271
Any fix that gets implemented...
Marcos M
11:53 AM Feature #10970: UI/GUI has an issue scrolling while drop menue is clicked/open
mom aiaz wrote:
> hello ,
>
> i notice that i am not able to scroll the drop-list if it taller than screen height...
Kris Phillips
05:17 AM Feature #10970 (Closed): UI/GUI has an issue scrolling while drop menue is clicked/open
hello ,
i notice that i am not able to scroll the drop-list if it taller than screen height,
to go around this i ...
mom aiaz
12:47 PM Bug #10949: PPPoE server can't be added
Tested on:... Danilo Zrenjanin
12:44 PM Bug #10532 (Resolved): Mobile PSK users don't have 'mobile-userpool' section
Tested on:... Danilo Zrenjanin
12:43 PM Bug #10971: OpenLDAP + group member attribute other than memberUid
When I change *User naming attribute* to *entryDN*, I can log in and see all groups. But it's a bit inconvenient.
...
Norbert K
12:32 PM Bug #10971 (Rejected): OpenLDAP + group member attribute other than memberUid
I am trying to connect to OpenLDAP, simple authorization works fine, I can connect as "domain user"
Then I wanted to...
Norbert K
12:36 PM Bug #7375 (Resolved): User with restricted privileges can still delete all monitoring/graphing data
Alhusein Zawi
12:34 PM Bug #7375: User with restricted privileges can still delete all monitoring/graphing data
I followed the steps
at Step 9 I received "Insufficient privileges to make the requested change (read only)." and ...
Alhusein Zawi
12:13 PM Bug #10566 (Closed): password for OpenDNS (under DynDNS) not being passed correctly
Tested this directly on the browser by using:
https://updates.opendns.com/nic/update?hostname=myhostname
I experi...
Marcos M
11:34 AM Bug #10566: password for OpenDNS (under DynDNS) not being passed correctly
I was able to reproduce this on 2.5.0.
Changing the password character from & to & when entering it in the fie...
Marcos M
11:59 AM pfSense Packages Bug #10602 (Confirmed): Dashboard->Traffic Graphs bandwidth designations on hover pop-ups
Changing status to confirmed, as this is a reproducible issue that we should patch. Kris Phillips
11:39 AM Bug #5999: IPv6 IP Alias prevents Track Interface from working with DHCPv6 and RA
> Another issue that seems to be related to this is that firewall rules using "LAN net" and similar are not obeyed if... Viktor Gurov
09:32 AM pfSense Packages Bug #10911: Bandwidthd iframe not resizing in 2.4.5/2.4.5p1
Fix:
https://github.com/pfsense/FreeBSD-ports/pull/958
Viktor Gurov
07:05 AM Bug #6598: "PPPoE clients" placeholder in rules only includes first PPPoE server instance
Tested on :... Danilo Zrenjanin
06:46 AM Bug #10675: DHCPv6 config not all directives start on a new line as expected
Tested on :... Danilo Zrenjanin
04:22 AM Bug #8390 (Feedback): Input validation does not prevent removing a gateway used by a DNS server
Ivars Strazdins wrote:
> This issue was driving me nuts!
> Thanks to your hint, I was able to find similar "ghost" ...
Viktor Gurov
03:32 AM Bug #10968: Mixed & Upper case Alias table names broken.
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/9 Viktor Gurov
03:25 AM Bug #10240 (New): Incorrect interface assignment after switching from PPPoE
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/7 Viktor Gurov
12:41 AM Bug #10955 (Resolved): XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
works fine on 2.5.0.a.20201009.1850 HA Viktor Gurov
12:16 AM pfSense Packages Feature #10969 (Resolved): Add Sekhan/TheGreatWall DoH feeds
https://github.com/Sekhan/TheGreatWall contains the DNS, IPv4 and IPv6 feeds of DoH servers:
https://raw.githubuse...
Viktor Gurov

10/09/2020

06:05 PM Revision fbb49296: Fix #9384
As mentioned by Warner Losh <imp@FreeBSD.org>, author of the change on
FreeBSD, the correct way to use quotes to para...
Renato Botelho
05:06 PM Bug #10955: XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
I started the post i put my feedback here.
built on *Fri Oct 09 14:15:42 EDT 2020* is working as expected.
Thanks
Raul Ramos
03:38 PM pfSense Docs Correction #9237 (Resolved): Remove references to pfSense Virtual VMware Appliance
@^/pfsense/en/latest/solutions/vmware@ redirect put in place here: ba0f6259351230b0a1703e16c6b6c8055ac638f2
VMWare...
Jared Dillard
01:21 PM Bug #9384 (In Progress): devd putting "$" before variable contents when using single quotes
Problem still happens Renato Botelho
01:15 PM Bug #9384 (Feedback): devd putting "$" before variable contents when using single quotes
Applied in changeset commit:fbb49296bfff21824be0f8cba94a50bcfe077416. Renato Botelho
12:59 PM Bug #9384 (In Progress): devd putting "$" before variable contents when using single quotes
I'll fix it as suggested by imp@ Renato Botelho
12:50 PM Bug #10952: Inconsistency in Subnet Defaults Between Firewall Rules and Interface Address Assignments
Important to note that if we're going to add field verification and blank fields for the subnets, we should do it for... Kris Phillips
11:41 AM Feature #10944 (Resolved): Sanitize secret2
Tested on :... Danilo Zrenjanin
10:10 AM Bug #10240 (Feedback): Incorrect interface assignment after switching from PPPoE
Applied in changeset commit:9757d69bf63931f503f4e370710a92136bc6219e. Viktor Gurov
07:29 AM Feature #8149: NTPsec
We stated in the linked Reddit thread that if we were to change, the option we would consider is ntimed, not ntpsec.
...
Jim Pingle
07:24 AM Feature #8149: NTPsec
chrony-4.0 also supports Network Time Security (NTS), as of 7 Oct 2020: https://chrony.tuxfamily.org/news.html
OPN...
Wilhelm Johansen
07:24 AM Feature #8861: Show SFP module details on ``status_interfaces.php``
Requires work in devel/php56-pfSense-module/files/pfSense.c so reassigning it Anonymous
06:56 AM Bug #8390: Input validation does not prevent removing a gateway used by a DNS server
This issue was driving me nuts!
Thanks to your hint, I was able to find similar "ghost" DNS servers in configuration...
Ivars Strazdins
12:50 AM Bug #10968: Mixed & Upper case Alias table names broken.
Fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/3
Viktor Gurov

10/08/2020

10:08 PM Bug #10943: boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
Some additional information related to VirtualBox & EFI boot problems:
I have two boxes, both built with VB 6.x & ...
Anonymous
07:10 PM Bug #10968 (Resolved): Mixed & Upper case Alias table names broken.
I have two firewalls, configured differently as core & edge, both are ver 2.5.0.a.20201006.1250 and I am still seeing... Anonymous
03:42 PM Revision 77cbaeae: Add help text to Register DHCP Leases in Resolver
This change adds a sentence to the help text for the `Register DHCP Leases in the DNS Resolver` input field.
Enablin...
Ryan Dlugosz
03:31 PM Bug #10949 (Resolved): PPPoE server can't be added
Danilo Zrenjanin wrote:
> Patch works fine.
>
> Though it is not working in the latest snapshot without the patc...
Renato Botelho
12:53 PM Bug #10949: PPPoE server can't be added
Patch works fine.
Though it is not working in the latest snapshot without the patch even though the PR has been m...
Danilo Zrenjanin
03:26 PM Feature #8149: NTPsec
Clouflare is supporting this- https://blog.cloudflare.com/secure-time/ (time.cloudflare.com:1234).
https://www.r...
Wilhelm Johansen
02:10 PM pfSense Docs Correction #9237: Remove references to pfSense Virtual VMware Appliance
I think we can remove that entire section from the product docs. The only reason it was there was to explain how to u... Jim Pingle
01:26 PM Revision 9108d083: NTP server authentication. Issue #8794
Viktor Gurov
01:26 PM pfSense Docs Correction #9697 (Resolved): Feedback on System Monitoring — Monitoring Graphs
Since the docs have been merged and the only text remaining for this is the book, this can be closed.
As mentioned...
Jim Pingle
12:36 PM pfSense Packages Todo #8332 (Resolved): pfBlockerNG doesn't include L2TP interface in outbound floating rules
Jim Pingle
12:25 PM pfSense Packages Todo #8332: pfBlockerNG doesn't include L2TP interface in outbound floating rules
Tested on :... Danilo Zrenjanin
12:36 PM pfSense Packages Feature #9721 (Pull Request Review): add squidclient -h 127.0.0.1 mgr:info output to Diagnostics / Squid and status.php
Jim Pingle
10:46 AM pfSense Packages Feature #9721: add squidclient -h 127.0.0.1 mgr:info output to Diagnostics / Squid and status.php
https://github.com/pfsense/FreeBSD-ports/pull/957 Viktor Gurov
12:18 PM Bug #10967: Kernel Memory Leak
No, it isn't a duplicate of #10624. Unbound isn't growing in this case. Patrick Linstruth
12:11 PM Bug #10967 (Rejected): Kernel Memory Leak
Probably a duplicate of #10624 but there isn't nearly enough information to go on here.
This site is not for suppo...
Jim Pingle
11:01 AM Bug #10967 (Rejected): Kernel Memory Leak
I seem to be experiencing a kernel memory leak on my Netgate APU. I think this started when I upgraded to 2.4.x. I am... Patrick Linstruth
11:55 AM Revision 5722cba4: Merge pull request #4479 from vktg/xmlrpcdhcpfix
Renato Botelho
11:55 AM Revision 4b86249d: Merge pull request #4477 from vktg/cphadel
Renato Botelho
11:54 AM Revision 4ca9f087: Merge pull request #4475 from stephenw10/master
Renato Botelho
11:54 AM Revision 94d0e37a: Merge pull request #4476 from emes/rtsold-managed-flag
Renato Botelho
11:50 AM Bug #10957: Improvement of Bogon tables handling needed
> a) to check the rule number against the max number of rules. And to stop loading if the maximum is reached (generat... Viktor Gurov
11:35 AM Revision 64431f25: route_get() improments. Fixes #10955
Viktor Gurov
11:24 AM pfSense Packages Bug #10964: pfSense-pkg-frr 0.6.8_4 does not use default ospf area if one is not defined on the interface.
I can confirm that the code change in the pull request (as of the time of this update) resolves this issue for me. S Premeau
08:07 AM pfSense Packages Bug #10964 (Pull Request Review): pfSense-pkg-frr 0.6.8_4 does not use default ospf area if one is not defined on the interface.
Jim Pingle
04:33 AM pfSense Packages Bug #10964: pfSense-pkg-frr 0.6.8_4 does not use default ospf area if one is not defined on the interface.
Fix:
https://github.com/pfsense/FreeBSD-ports/pull/956
Viktor Gurov
10:48 AM Revision 780f5eeb: Disable DOXYGEN options globally
Renato Botelho
10:47 AM Revision f0a238ea: Sort
Renato Botelho
10:41 AM Revision e5eba380: Create key and zone section for static DHCP mappings. Issue #10224
Viktor Gurov
09:46 AM Bug #10952: Inconsistency in Subnet Defaults Between Firewall Rules and Interface Address Assignments
Jim Pingle wrote:
> We've debated this in the past and always come back to leaving it as-is. We can't know what the ...
Kris Phillips
07:21 AM Bug #10397: Changing default or static route gateway on 2.5.0 does not remove old route
Wow that's a monster commit. Thank you rbgarga! → luckman212
07:13 AM Bug #10397: Changing default or static route gateway on 2.5.0 does not remove old route
→ luckman212 wrote:
> Were there any commits to pfSense to fiz this or were all the changes from upstream FreeBSD?
...
Renato Botelho
07:01 AM Bug #10397: Changing default or static route gateway on 2.5.0 does not remove old route
Were there any commits to pfSense to fiz this or were all the changes from upstream FreeBSD? → luckman212
07:08 AM Feature #10454 (Resolved): OpenVPN+RADIUS+Cisco-AVPair IPv6 ACL
works as expected on pfSense 2.5.0.a.20201006.1250
Example:
pfctl -a openvpn/ovpns1_raduser1_16748 -sr:...
Viktor Gurov
06:55 AM Bug #10965 (Feedback): rtsold not starting dhcp6c when managed bit is set
PR has been merged. Thanks! Renato Botelho
06:55 AM Bug #10963 (Feedback): Thermal Sensors widget shows invalid sensors
PR has been merged. Thanks! Renato Botelho
06:55 AM Bug #10891 (Feedback): Captive Portal related files are not deleted after deleting CP zone in WebGUI
PR has been merged. Thanks! Renato Botelho
01:40 AM Bug #10891: Captive Portal related files are not deleted after deleting CP zone in WebGUI
Max Leighton wrote:
>
> I tested in an HA pair and saw that the even though the zone gets deleted on the secondar...
Viktor Gurov
06:55 AM Bug #10955 (Feedback): XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
PR has been merged. Thanks! Renato Botelho
06:36 AM Bug #10955: XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
Fix:
https://github.com/pfsense/pfsense/pull/4479
Viktor Gurov
06:37 AM Revision c31f4e95: Delete Captive Portal related files on HA node. Fixes #10891
Viktor Gurov
05:42 AM Bug #10224: DHCP DDNS does not add zone entries for keys when using static host DDNS definitions
Updated:
https://github.com/pfsense/pfsense/pull/4478
Viktor Gurov
05:15 AM Revision 4d207e96: Ability to clear all DHCP leases at once. Implements #7406
Viktor Gurov

10/07/2020

11:29 PM Bug #10966: IPv6 - WAN does not renew address when upstream fails
Related: https://forums.whirlpool.net.au/archive/9004zpv9-6#r67799588
If i release/renew it never gets a v6 addres...
Sam McLeod
07:31 PM Bug #10966: IPv6 - WAN does not renew address when upstream fails
Might also be related to this bug that was closed as a dupe: https://redmine.pfsense.org/issues/3290 Sam McLeod
07:27 PM Bug #10966 (Resolved): IPv6 - WAN does not renew address when upstream fails
If the upstream ISP on the WAN link has an IPv6 failure / outage, PFSense does not release and renew the IPv6 lease.
...
Sam McLeod
10:28 PM Bug #10397 (Resolved): Changing default or static route gateway on 2.5.0 does not remove old route
Alhusein Zawi
10:25 PM Bug #10397: Changing default or static route gateway on 2.5.0 does not remove old route

when changing the default route , old route is removed .
[2.5.0-DEVELOPMENT][admin@pfSense.localdomain]/root: n...
Alhusein Zawi
08:16 PM Revision de8054bc: Use the full path.
Steve Wheeler
08:03 PM Revision 438253c2: Further reduce the sysctls parsed.
Remove the 'a' which does nothing when you specify OIDs. Steve Wheeler
05:42 PM Revision de7e6d42: rtsold: run script if MANAGED bit set
Michael Smith
05:20 PM Revision a7e244bb: Prevent over-matching the sysctl output
Steve Wheeler
04:44 PM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
I'm having the same issue with duplicating VTI Phase2s with tunnels to AWS.
Did anyone find settings that fixed th...
Todd Blum
03:01 PM Revision a5d53ac3: Move frr7 to net section
Renato Botelho
03:01 PM Revision 465abadd: Remove old options and fix bind to current version, 9.16
Renato Botelho
02:42 PM Bug #10383 (Resolved): Additional interfaces do not survive a reboot before the setup wizard has been run
Anonymous
02:41 PM Feature #7705 (Resolved): Support dynamic interface address for 1:1 NAT
Anonymous
02:40 PM Bug #6503 (Resolved): rrd graph for ntp monitoring does not reflect freq when neg (-) value.
Anonymous
02:39 PM Bug #7142 (Resolved): IPv6: Floating rules on 6rd enabled WAN interfaces doesn't get bound to wan_stf
Anonymous
02:39 PM Bug #7443 (Resolved): Issues Creating IPv6 Static Mappings
Anonymous
02:38 PM Bug #3924 (Resolved): Renaming limiters removes them from firewall rules
Anonymous
02:37 PM Feature #7095 (Resolved): Improve Remote Gateway field description for IPSec VPN Phase 1
Anonymous
02:37 PM Bug #10847 (Resolved): Mobile user IPSec (PSK+Xauth) fails at user auth with PHP error
Anonymous
02:15 PM Revision c82555ee: Add EXPERIMENTAL option to freeradius3 to fix PYTHON module
Renato Botelho
02:15 PM Revision a110e8d9: Remove freeradius2 options
Renato Botelho
01:13 PM Bug #10965: rtsold not starting dhcp6c when managed bit is set
PR https://github.com/pfsense/pfsense/pull/4476 Michael Smith
01:08 PM Bug #10965 (Resolved): rtsold not starting dhcp6c when managed bit is set
rtsold was recently changed to allow for a script to run when the router advertisement has the MANAGED flag set.
u...
Michael Smith
12:56 PM pfSense Packages Bug #10964: pfSense-pkg-frr 0.6.8_4 does not use default ospf area if one is not defined on the interface.
Current version with the issue:
2.5.0-DEVELOPMENT (amd64)
built on Tue Oct 06 12:54:27 EDT 2020
FreeBSD 12.2-STABLE
S Premeau
12:55 PM pfSense Packages Bug #10964 (Resolved): pfSense-pkg-frr 0.6.8_4 does not use default ospf area if one is not defined on the interface.
I am not seeing recent changes in the frr package, but this issue occurred when I updated from the 10/5 to 10/6 devel... S Premeau
12:40 PM Bug #10963 (Pull Request Review): Thermal Sensors widget shows invalid sensors
Jim Pingle
12:23 PM Bug #10963: Thermal Sensors widget shows invalid sensors
https://github.com/pfsense/pfsense/pull/4475
That looks to avoid this over-matching from over-temp warnings logged...
Steve Wheeler
12:11 PM Bug #10963 (Resolved): Thermal Sensors widget shows invalid sensors
The thermal sensors widget can show invalid sensors if it over-matches the output returned by 'sysctl aq'.
In some ...
Steve Wheeler
10:30 AM Feature #9702 (Resolved): OpenVPN "push-reset" option in Client Specific Override breaks "subnet" topology
Anonymous
10:29 AM Feature #10617 (Resolved): freeDNS Dynamic DNS API v2 Support
Anonymous
10:28 AM Bug #8807 (Resolved): HA sync : files voucher_{$cpzone}.cfg and voucher_{$cpzone}.public are not created on save in /var/save when enabling vouchers on master.
Anonymous
10:14 AM Bug #10891: Captive Portal related files are not deleted after deleting CP zone in WebGUI
Viktor, can you please check this out? Renato Botelho
10:11 AM Bug #10891 (In Progress): Captive Portal related files are not deleted after deleting CP zone in WebGUI
Anonymous
10:13 AM Bug #10869 (Resolved): "Accounting updates" not working in PPPoE config page
Anonymous
10:12 AM Todo #10676 (Resolved): JQuery 1.2 < 3.5.0 Multiple XSS From Nessus
Anonymous
10:12 AM Feature #10374 (Resolved): Add ARM32/64 network booting support to dhcpd
Anonymous
10:05 AM Bug #10327 (Resolved): Fix/Update GPS initialization commands for Garmin devices.
Anonymous
10:03 AM Bug #10709 (Resolved): services_router_advertisements.php: radvd won't start if Default valid lifetime is less than Default preferred lifetime
Anonymous
09:59 AM Feature #8645 (Resolved): Upload certificate file instead of pasting
Anonymous
09:57 AM Bug #10757 (Resolved): IPv6: NPt rules on 6rd enabled WAN interfaces don't get bound to wan_stf
Anonymous
09:50 AM Feature #9302 (Resolved): radvd always advertises DNS servers and Domain Search List regardless of M or O flag
Anonymous
08:40 AM Bug #8585 (Resolved): Logical interface MTU matches configuration of its physical port channel, not its own configuration
Anonymous

10/06/2020

06:18 PM Bug #10943: boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
i found a solution that worked for me for pfsense 2.5.0 and efi,
use SATA controller and remove the default SCSI con...
Manuel Piovan
11:19 AM Bug #10943: boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
the installation from the iso of FreeBSD-13.0-CURRENT does not even start, it stop on the boot menu with the same error Manuel Piovan
10:10 AM Bug #10943: boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
https://forums.freebsd.org/threads/cant-boot-on-uefi.68141/
following this made my system work
shell recovery fro...
Manuel Piovan
09:06 AM Bug #10943: boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
Manuel Piovan wrote:
> same problem,
> the installation complete successfully,
> also pfsense
> but when I reboo...
Renato Botelho
08:08 AM Bug #10943: boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
same problem,
the installation complete successfully,
also pfsense
but when I reboot it stop like on the screenshot
Manuel Piovan
07:02 AM Bug #10943: boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
Manuel Piovan wrote:
> pfSense-CE-2.5.0-DEVELOPMENT-amd64-latest.iso.gz 06-Oct-2020 05:13 536447915
>
...
Renato Botelho
05:10 AM Bug #10943: boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
pfSense-CE-2.5.0-DEVELOPMENT-amd64-latest.iso.gz 06-Oct-2020 05:13 536447915
still not working on my e...
Manuel Piovan
05:33 PM Feature #10962 (New): Add Cpanel support for Dynamic DNS Clients
Cpanel offers an API for updating DNS records.
Hence, Cpanel could now be added to the already extensive list of dyn...
M Jurgens
03:20 PM pfSense Packages Bug #10941 (Closed): pfBlockerNG-devel Bug in ipv6 lists when updating
Jim Pingle
02:56 PM pfSense Packages Bug #10941: pfBlockerNG-devel Bug in ipv6 lists when updating
Since it seems to be resolved, it was probably unique to my configuration, so I am amenable to closing or downgrading... Rick Coats
02:54 PM pfSense Packages Bug #10941: pfBlockerNG-devel Bug in ipv6 lists when updating
I did the upgrade from .35 to .36 today and did not get this problem this time, so it could be that it has fixed itse... Rick Coats
03:19 PM pfSense Docs Correction #10954 (Resolved): Feedback on Troubleshooting — Troubleshooting High Availability DHCP Failover
I added a more concise version of that on the page, plus on the main HA troubleshooting page and on the XML-RPC sync ... Jim Pingle
03:04 PM Bug #10961: firewall > schedules display error php
its worked Teste Teste
01:59 PM Bug #10961: firewall > schedules display error php
That whole section, or at a minimum, the empty @<schedule></schedule>@.
Post on the forum if you have more follow-...
Jim Pingle
01:59 PM Bug #10961: firewall > schedules display error php
which tags should i remove? Teste Teste
01:54 PM Bug #10961 (Closed): firewall > schedules display error php
I am unsure how your configuration ended up in that state, but you can take a backup, remove the offending tags from ... Jim Pingle
01:41 PM Bug #10961: firewall > schedules display error php
my config.xml tag schedule
<schedules>
<schedule></schedule>
</schedules>
Teste Teste
01:23 PM Bug #10961 (Feedback): firewall > schedules display error php
I checked a couple systems, one with and one without schedule entries, and neither one had an error on that page.
...
Jim Pingle
01:04 PM Bug #10961 (Closed): firewall > schedules display error php
Current Base System: 2.5.0.a.20201006.0650
On open firewall -> schedules display the follow message:
Warning: I...
Teste Teste
02:48 PM pfSense Docs Correction #9371 (Resolved): Feedback on Testing the FreeRADIUS Package
I pushed a revised copy of the page. I added info about the GUI test, and removed some other outdated info. Jim Pingle
02:01 PM pfSense Docs Correction #10417 (Closed): Feedback on Packages — Package List
I updated the package list just now and added a little more here, nothing else is needed for the list itself. Jim Pingle
01:19 PM Bug #10891: Captive Portal related files are not deleted after deleting CP zone in WebGUI
Tested in:
2.5.0-DEVELOPMENT (amd64)
built on Sun Oct 04 18:53:52 EDT 2020
FreeBSD 12.2-STABLE
The captive po...
Max Leighton
01:03 PM Bug #10714: radvd only gives out the prefix of the "first" IPv6 address of an interface
Related ? https://redmine.pfsense.org/issues/5999 Sechen Qerel
01:02 PM Bug #9384: devd putting "$" before variable contents when using single quotes
Mark told me he would take a look at upstream regression Renato Botelho
12:44 PM Feature #10934: Add ral(4) to arm64
It is in the arm64 kernel now:... Steve Wheeler
12:12 PM Feature #10934: Add ral(4) to arm64
Please confirm and set to "Resolved" if appropriate. Anonymous
12:28 PM Bug #7772 (New): Regression of Bug #906
Anonymous
12:24 PM Feature #10273 (Resolved): OpenVPN compile with --enable-async-push
Anonymous
12:23 PM Bug #10580 (Resolved): PHP error when restoring to 2.5.0
Anonymous
12:23 PM Bug #10206: VIP alias-ip's disappear from nic (caused by running ifconfig twice.?.)
Would you please confirm this fix? Anonymous
12:21 PM Feature #7741 (Resolved): warn me when shooting myself in the foot with NPt
Anonymous
12:20 PM Bug #10632 (Resolved): Incorrect swanctl.conf syntax from Child SA Close Action
Anonymous
12:19 PM Bug #9641 (Resolved): Dynamic DNS cannot update AAAA records on 6rd tunnel interfaces bound to PPPoE interfaces
Anonymous
12:16 PM Bug #10684 (Resolved): RFC 2136 incomplete options
Anonymous
12:16 PM Bug #3381 (Resolved): LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues
Anonymous
12:16 PM Feature #3329 (Resolved): Allow creating "not" rules for IPsec Phase 2
Anonymous
12:15 PM Bug #3128 (Resolved): Active voucher status not restored from backup
Anonymous
12:14 PM Feature #3031 (Resolved): Message is false after changing Hardware Checksum Offloading setting
Anonymous
12:13 PM Bug #1353 (Resolved): Number of queues possible
Anonymous
12:11 PM Feature #10914 (Resolved): Skip extra data checkbox
Anonymous
12:10 PM Feature #10910 (Resolved): Backup/restore DHCP v4/v6 leases
Anonymous
12:09 PM Bug #10803 (Resolved): Invalid rules generated from AVPair on OpenVPN
Anonymous
12:09 PM Feature #10762 (Resolved): add Broadcom NetXtreme to ALTQ-capable list
Anonymous
12:09 PM Feature #10868 (Resolved): Backup Captive Portal DB
Anonymous
12:08 PM Feature #10723 (Resolved): Disable "Hardware Checksum Offloading" if VM is detected
Anonymous
12:07 PM Feature #10454: OpenVPN+RADIUS+Cisco-AVPair IPv6 ACL
The confirm this fix and set to "Resolved" if appropriate Anonymous
12:03 PM Bug #10652 (Resolved): Duplicate upgrade_203_to_204() function in upgrade_config.inc
Anonymous
12:03 PM Bug #10623 (Resolved): Wrong Route configured for GIF interface on VLAN on LAGG
Anonymous
12:03 PM Feature #10459 (Resolved): Improved DynDNS Logging
Anonymous
12:02 PM Bug #10705 (Resolved): Difficult to see multiple selection form-control
Anonymous
12:02 PM Bug #10592 (Resolved): DigitalOcean DNS update adds new DNS record instead of update
Anonymous
12:01 PM Bug #10569 (Resolved): Sanitize ACME passwords
Anonymous
12:01 PM Bug #10529 (Resolved): IPsec Phase 1 options Reauth and Rekey do not allow valid "0" value
Anonymous
12:00 PM Feature #10495 (Resolved): Add support of Pushover API for notifications
Anonymous
12:00 PM Feature #10354 (Resolved): Telegram Notification Support
Anonymous
11:59 AM Feature #10318 (Resolved): Do not restart PPPoE server after adding/modifying users
Anonymous
11:59 AM Feature #10256 (Resolved): Add support for IPv6 to No-IP Dynamic DNS
Anonymous
11:56 AM Bug #10241 (Resolved): Updating Dynamic DNS provider Hover is not working
Anonymous
11:47 AM Revision 29b42d65: Merge pull request #4474 from stephenw10/master
Renato Botelho
11:03 AM Bug #9413 (Resolved): VLAN driver missing ALTQ support
ALTQ rules loaded without error on the latest 2.5.0 snapshot. Jim Pingle
10:43 AM Bug #9413: VLAN driver missing ALTQ support
Please test/close Anonymous
11:01 AM Todo #10135 (Resolved): help.php: Update links
Anonymous
10:45 AM Bug #9646 (Resolved): OpenSSL 1.1.1 does not list engines for AES-NI or BSD crypto
Anonymous
10:43 AM Feature #9432 (Resolved): Block additional Captive Portal Logins
Anonymous
10:42 AM Bug #9255 (Resolved): Potential performance issue when using multiple authentication servers in a zone
Anonymous
10:42 AM Bug #9385: OpenVPN logs a "Device busy" error when opening tap interfaces, but continues to function
This is still happening for every OpenVPN instance (clients or servers, tap or tun) but does not appear to be harmful... Jim Pingle
10:42 AM Bug #9208 (Resolved): The wrong session timeout value can be used for some captive portal users
Anonymous
10:42 AM pfSense Packages Todo #9158 (Resolved): Updates for Squid 4.x
Anonymous
10:41 AM Bug #8809 (Resolved): HA sync : changing a voucher roll on master does not reset active tickets on slave.
Anonymous
10:40 AM Feature #7304 (Resolved): DHCP: Enable OMAPI Config
Anonymous
10:40 AM Bug #8472 (Resolved): IPsec with "Split connections" enabled (multiple P2's) - new added P2's are not coming up (between two pfsense's 2.4.3)
I recently tested this when checking on #6324 and it works fine on 2.5.0. Jim Pingle
10:24 AM Bug #8472: IPsec with "Split connections" enabled (multiple P2's) - new added P2's are not coming up (between two pfsense's 2.4.3)
Please test & confirm Anonymous
10:37 AM Bug #6598 (In Progress): "PPPoE clients" placeholder in rules only includes first PPPoE server instance
Anonymous
10:31 AM Feature #6240 (Resolved): vxlan driver
Anonymous
10:30 AM Feature #9152 (Duplicate): Sort diag_states_summary.php by states
Appears to be a duplicate of #9718 Jim Pingle
10:30 AM Bug #6030: Duplicated tracker IDs on block private networks rules
Please confirm fix Anonymous
10:28 AM Feature #4038 (Resolved): Button to clear the arp cache
Anonymous
10:28 AM Bug #3039 (Resolved): New vouchers doesn't sync with CARP slave
Anonymous
10:27 AM Feature #885 (Resolved): Show gateway/group IPs on mouseover
Anonymous
10:26 AM Feature #97 (Resolved): Captive Portal should sync its database to other members of clusters
Anonymous
10:26 AM Feature #8160 (Resolved): Accomodate both RADIUS and pool IP addresses in IPsec
Anonymous
10:24 AM Feature #7467 (Resolved): Add iPhone/Android/Generic USB tethering support
Anonymous
10:21 AM Feature #7767 (Resolved): OCSP support for OpenVPN server
Anonymous
10:21 AM Bug #7384 (Resolved): DHCPv6 doesn't merge IPv6 prefix with the input submitted in DNS servers field when using Track Interface IPv6 configuration parameter for the LAN interface.
Anonymous
10:17 AM Bug #7742 (Resolved): 1:1 NAT for IPv6 applies wrong subnet mask to "Single Host"
Anonymous
10:10 AM pfSense Packages Bug #7267 (New): Status Traffic Totals - Stacked Bar - Scale not high enough
Anonymous
09:56 AM Feature #9297: Graph for hardware temperature readings
Out of scope for 2.5.0 Anonymous
09:52 AM Feature #7016: system_information_widget.php - Indicate adaptive state timeout status when active
Suggest move this to factory Anonymous
09:42 AM Bug #10899 (Feedback): VXVLAN interfaces are not created correctly
This has been merged as part of https://redmine.pfsense.org/issues/10898 Steve Wheeler
09:38 AM Bug #10812: Traffic graph shows 2X the actual traffic on VLAN interfaces.
Last time this came up it was due to VLAN traffic counting twice on the parent. In https://redmine.pfsense.org/issues... Jim Pingle
09:36 AM Bug #9344: OpenVPN click NCP Algorithms will always go to DH Parameters website(in Chinese-Taiwan)
Setting to "Future". Requires translation assistance on https://zanata.netgate.com which has not been forthcoming. Anonymous
09:28 AM Bug #10236: Cannot add more than 2 VMXNET3 Adapters in vSphere
Would you please verify of close? Anonymous
09:19 AM pfSense Packages Bug #10791: Valid (vlan)interfaces do not get vif reporting "Invalid phyint address"
PIMD-3 is not yet available for testing/development. Pushing this to "Future"
https://github.com/troglobit/pimd/bl...
Anonymous
09:12 AM Feature #9718: Make diag_states_summary table sortable
Redesigning the page to accommodate sorting is out of scope for 3.5.0 - Resetting target to "Future" Anonymous
08:59 AM Bug #10948 (Resolved): Gateway group popover not populated on firewall_rules.php
Anonymous
07:59 AM Bug #7375 (Feedback): User with restricted privileges can still delete all monitoring/graphing data
PR has been merged. Thanks! Renato Botelho
07:59 AM pfSense Packages Todo #8332 (Feedback): pfBlockerNG doesn't include L2TP interface in outbound floating rules
PR has been merged. Thanks! Renato Botelho
07:10 AM pfSense Packages Feature #10789 (Feedback): FRR integrated configuration and hitless reloads
PRs #950 and #955 are now merged. Thanks! Renato Botelho
06:58 AM Bug #10960 (Feedback): Bring up VXLANs correctly at boot
PR has been merged. Thanks! Renato Botelho

10/05/2020

11:56 PM Revision d9f267f2: Delay configuring vxlans at boot
Configure VXLAN interfaces after the parent interfaces are configured. Add them to the delayed list with GRE and GIF. Steve Wheeler
10:37 PM Revision 52ec3b56: Merge pull request #4471 from vktg/pppoeaddfix
Renato Botelho
10:37 PM Revision 8fd813e8: Merge pull request #4301 from vktg/arpclearbtn
Renato Botelho
10:36 PM Revision c198f41f: Merge pull request #4469 from vktg/gwgrpopupfix
Renato Botelho
10:36 PM Revision 342bbc96: Merge pull request #4468 from vktg/syslogdintcheck
Renato Botelho
10:35 PM Revision b6d7ccd6: Merge pull request #4467 from vktg/gwlbfix
Renato Botelho
10:35 PM Revision 55cf9910: Remove space from EOL
Renato Botelho
10:34 PM Revision b41c0fd5: Merge pull request #4466 from vktg/sanitizewifiradius
Renato Botelho
10:33 PM Revision c5495c59: Merge pull request #4464 from vktg/ovpnipsecsameradiusparser
Renato Botelho
10:31 PM Revision 281c0412: Merge pull request #4465 from vktg/sanitizesecret2
Renato Botelho
10:27 PM Revision 3b222257: Style fixes
Renato Botelho
10:23 PM Revision 8dc360ea: Fix #10898
Fix vxlan interfaces configuration at boot Steve Wheeler
07:08 PM Bug #10960: Bring up VXLANs correctly at boot
This addresses the 2nd issue here:
https://github.com/pfsense/pfsense/pull/4474
Steve Wheeler
07:04 PM Bug #10960 (Resolved): Bring up VXLANs correctly at boot
With the patches from 10898 and 10899 VXLAN interfaces can be added and are created at boot. VXLANs on WAN are config... Steve Wheeler
05:37 PM Feature #10944 (Feedback): Sanitize secret2
PR has been merged. Thanks! Renato Botelho
05:37 PM Feature #10469 (Feedback): Same RADIUS Cisco-AVPair parser code for both OpenVPN/IPsec
PR has been merged. Thanks! Renato Botelho
05:37 PM Feature #10946 (Feedback): Sanitize WiFi 802.1x RADIUS shared secret
PR has been merged. Thanks! Renato Botelho
05:37 PM Bug #6025 (Feedback): Load balancing fails when one gateway has a weight of 1 and another gateway has a weight >1
PR has been merged. Thanks! Renato Botelho
05:37 PM Bug #9660 (Feedback): Syslogd keeps using old IP address after interface IP address change
PR has been merged. Thanks! Renato Botelho
05:37 PM Bug #10948 (Feedback): Gateway group popover not populated on firewall_rules.php
PR has been merged. Thanks! Renato Botelho
07:23 AM Bug #10948 (Pull Request Review): Gateway group popover not populated on firewall_rules.php
Jim Pingle
05:37 PM Feature #4038 (Feedback): Button to clear the arp cache
PR has been merged. Thanks! Renato Botelho
05:37 PM Bug #10949 (Feedback): PPPoE server can't be added
PR has been merged. Thanks! Renato Botelho
07:59 AM Bug #10949 (Pull Request Review): PPPoE server can't be added
Jim Pingle
05:27 PM Bug #10898 (Feedback): vxlan interfaces fail the interface mismatch check at boot.
PR has been merged. Thanks! Renato Botelho
04:38 PM Bug #10959: Traffic graph stopped on interface used via netmap
Edivan Carneiro de castro wrote:
> I've been using pfsense 2.5 for a month now, worked normally. only after 2020-10-...
Bill Meeks
12:09 PM Bug #10959: Traffic graph stopped on interface used via netmap
I've been using pfsense 2.5 for a month now, worked normally. only after 2020-10-02 updates the traffic graphic stopped Teste Teste
12:05 PM Bug #10959: Traffic graph stopped on interface used via netmap
I use Vmware as network interface Teste Teste
12:03 PM Bug #10959: Traffic graph stopped on interface used via netmap
In the dashboard and Status > Traffic Graph Teste Teste
12:01 PM Bug #10959 (Feedback): Traffic graph stopped on interface used via netmap
Which traffic graphs specifically?
The ones on the dashboard?
The one on Status > Traffic Graph?
The ones un...
Jim Pingle
11:53 AM Bug #10959: Traffic graph stopped on interface used via netmap

Current Base System: 2.5.0.a.20201005.1047
Problem: After update, the traffic graphic stopped on interface wit...
Teste Teste
11:41 AM Bug #10959 (Feedback): Traffic graph stopped on interface used via netmap
Current Base System: 2.5.0.a.20201005.1047
Problem: After update, the traffic grafic stoped on interface with snor...
Teste Teste
03:36 PM Bug #8465: Lost default gateway after recover from failover with CARP VIP and HA
well we solved the problem by this way , first create a script to check if the default route is still exists or no th... Milad Soltanian
03:31 PM pfSense Docs Correction #9375 (Resolved): Feedback on ACME - no info on how to use cron
This is now covered in the newly rewritten ACME docs. Jim Pingle
02:52 PM Bug #10857 (Resolved): Captive Portal usedmacs DB is not copied to backup HA node
Tested in
2.5.0-DEVELOPMENT (amd64)
built on Sun Oct 04 18:53:52 EDT 2020
FreeBSD 12.2-STABLE
/var/db/captive...
Max Leighton
01:46 PM Bug #10956 (Resolved): Panic configuring LAGG+VLAN interfaces when using a kernel with ``INVARIANTS``.
Jim Pingle
01:41 PM Bug #10956: Panic configuring LAGG+VLAN interfaces when using a kernel with ``INVARIANTS``.
A few minutes ago I updated my system via the GUI to today 1250. The router did restart properly! and seems to work n... Louis B
09:58 AM Bug #10956 (Feedback): Panic configuring LAGG+VLAN interfaces when using a kernel with ``INVARIANTS``.
INVARIANTS has been removed from the kernel, try the next new snapshot. Jim Pingle
09:15 AM Bug #10956: Panic configuring LAGG+VLAN interfaces when using a kernel with ``INVARIANTS``.
That's due to INVARIANTS in the kernel which is only a temporary measure to gather information while other issues are... Jim Pingle
01:00 AM Bug #10956 (Closed): Panic configuring LAGG+VLAN interfaces when using a kernel with ``INVARIANTS``.
In very recent snapshots I have big problems which seems lagg related. May be related to freebsd issue https://bugs.f... Louis B
09:59 AM Bug #10943 (Feedback): boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
This is possibly related to INVARIANTS being added to the kernel which increased its size.
INVARIANTS has now been...
Jim Pingle
08:49 AM Bug #10943: boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
Any lagg issue is unrelated to this. This is failing to boot at all only on EFI installs.
Any posts in that thread...
Jim Pingle
09:18 AM Bug #10958 (Not a Bug): randomly blocking network access from one lan to an other, reboot helps
This site is not for support or diagnostic discussion.
For assistance in solving problems, please post on the "Net...
Jim Pingle
05:01 AM Bug #10958 (Not a Bug): randomly blocking network access from one lan to an other, reboot helps
My Setup is as follows:
LAN_1: Network Devices like Laptop, Smartphone etc
LAN_3: LAN Services like Sambashare etc
...
raf thebee
09:18 AM Bug #10957 (Needs Patch): Improvement of Bogon tables handling needed
Feel free to submit a PR which implements a proposed change.
Jim Pingle
01:16 AM Bug #10957 (Needs Patch): Improvement of Bogon tables handling needed
As intro. A firewall should not pass traffic before all basic things like firewall-rules, routing tables, security v... Louis B
09:08 AM Bug #10955 (Confirmed): XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
I'm seeing this as well Jim Pingle
09:07 AM Feature #10387 (Resolved): Reevaluate the GUI upgrade language presented to the user
Jim Pingle
08:47 AM Bug #10952: Inconsistency in Subnet Defaults Between Firewall Rules and Interface Address Assignments
We've debated this in the past and always come back to leaving it as-is. We can't know what the user needs to put the... Jim Pingle
08:41 AM pfSense Packages Feature #10953 (Rejected): IPSec Profile Wizard Unavailable in Community Edition Repos
That's intentional for the time being. Jim Pingle
08:40 AM Bug #10951 (Rejected): Firewall Rule Defaults Should be Any Instead of TCP
We've debated this before and the current default is acceptable. You'd be trading one set of support questions for an... Jim Pingle
08:39 AM Bug #10923 (Resolved): Update ixl Driver on pfSense 2.5.0 to bring back Intel X710-T2L/T4L support that was present on version 2.4.5-P1.
Jim Pingle
08:39 AM pfSense Packages Todo #8332 (Pull Request Review): pfBlockerNG doesn't include L2TP interface in outbound floating rules
Jim Pingle
08:38 AM Feature #7406 (Pull Request Review): Ability to clear all dhcp leases at once
Jim Pingle
08:27 AM pfSense Packages Feature #10950 (Pull Request Review): Allow to select only netmap-compatible cards for inline mode
Jim Pingle
08:10 AM Feature #8794 (Pull Request Review): NTP authentication support
Jim Pingle
07:33 AM pfSense Packages Feature #6176: Privilege for OpenVPN Client Export
Adding a per-user privilege so uses can download their own clients is not going to happen (see comments on the PR). T... Jim Pingle
06:34 AM pfSense Packages Feature #10415 (Resolved): FreeRADIUS Package: Add option to enter NT or MD5 prehashed passwords in configuration
Tested on:
2.4.5_p1 and
2.5.0-DEVELOPMENT (amd64)
built on Mon Oct 05 00:53:54 EDT 2020
FreeBSD 12.2-STABLE
NT...
Azamat Khakimyanov
01:59 AM pfSense Packages Feature #9974 (Resolved): Add pfSense package for sysutils/node_exporter
Tested on:
2.5.0-DEVELOPMENT (amd64)
built on Mon Oct 05 00:53:54 EDT 2020
FreeBSD 12.2-STABLE
I was able succe...
Azamat Khakimyanov

10/04/2020

10:18 PM Bug #10955 (Resolved): XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
Forum post: https://forum.netgate.com/topic/156974/xmlrpc-sync-error-built-on-sun-sep-20-01-01-05-edt-2020
I'm see...
Max Leighton
07:29 PM Feature #10387: Reevaluate the GUI upgrade language presented to the user
The message "System is going to be upgraded. Rebooting in 10 seconds" appears in the verbose console output portion o... Jordan G
05:43 PM Bug #10943: boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
As per the linked Netgate forum thread, is this only affecting those with vlans on laggs?
https://bugs.freebsd.org...
andreas vesalius
03:29 PM pfSense Docs Correction #10954: Feedback on Troubleshooting — Troubleshooting High Availability DHCP Failover
(sorry, ignore the accidental copy & paste second paragraph) - can't edit. Bill McGonigle
03:28 PM pfSense Docs Correction #10954 (Resolved): Feedback on Troubleshooting — Troubleshooting High Availability DHCP Failover
*Page:* https://docs.netgate.com/pfsense/en/latest/troubleshooting/ha-dhcp-failover.html
*Feedback:*
Could use ...
Bill McGonigle
10:20 AM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
PR: https://github.com/pfsense/FreeBSD-ports/pull/955 Ben Hughes
07:50 AM pfSense Packages Bug #5168 (Resolved): squid doesn't function during/after HA failover
Tested on:
2.5.0-DEVELOPMENT (amd64)
built on Sun Oct 04 00:53:54 EDT 2020
FreeBSD 12.2-STABLE
I created HA cl...
Azamat Khakimyanov

10/03/2020

08:59 PM pfSense Packages Feature #10953 (Rejected): IPSec Profile Wizard Unavailable in Community Edition Repos
The IPSec Profile Wizard is not available in pfSense Community Edition, which would be helpful for customers and help... Kris Phillips
06:04 PM Bug #9058: Kernel panic during L2TP retransmit
And I hit it again with 2.5.0.a.20201003.0050 Bianco Veigel
05:22 PM pfSense Packages Bug #10815: FRR with SNMP AgentX option failed to start
uninstall/install FRR made agentx option working . ( No Crash)
agentx option enabled on Zebra Global Settings .
...
Alhusein Zawi
12:58 PM pfSense Packages Feature #9913 (Resolved): Adding note Squid Traffic Managment Settings about feature limit
Tested on :... Danilo Zrenjanin
12:50 PM Bug #10952 (New): Inconsistency in Subnet Defaults Between Firewall Rules and Interface Address Assignments
When creating a new firewall rule, after selecting "Network" under the source or destination fields, the field defaul... Kris Phillips
12:31 PM Bug #10951 (Rejected): Firewall Rule Defaults Should be Any Instead of TCP
In any new firewall rule creation, the protocol defaults to TCP rather than "Any" (or at the very least TCP/UDP). Al... Kris Phillips
12:10 PM Bug #10923: Update ixl Driver on pfSense 2.5.0 to bring back Intel X710-T2L/T4L support that was present on version 2.4.5-P1.
I did a fresh install with the latest build (Oct 3) and the X710-T2L is detected and the 2.5 Gbps and 5 Gbps Eth mode... Abhinav Tella
12:05 PM Revision 1d1b49cd: PPPoE server add fix. Fixes #10949
Viktor Gurov
10:36 AM pfSense Packages Todo #8332: pfBlockerNG doesn't include L2TP interface in outbound floating rules
https://github.com/pfsense/FreeBSD-ports/pull/954 Viktor Gurov
09:50 AM Revision 6f3f9671: Button to clear the ARP cache. Issue #4038
Viktor Gurov
09:31 AM pfSense Packages Feature #10950: Allow to select only netmap-compatible cards for inline mode
https://github.com/pfsense/FreeBSD-ports/pull/953 Viktor Gurov
08:58 AM pfSense Packages Feature #10950 (Resolved): Allow to select only netmap-compatible cards for inline mode
https://www.freebsd.org/cgi/man.cgi?query=netmap&sektion=4:... Viktor Gurov
09:29 AM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
Looking into firewalling between two VRFs I've discovered that FRR, contrary to the documentation (http://docs.frrout... Ben Hughes
08:51 AM pfSense Packages Bug #10771 (Feedback): arpwatch: option to not send hourly email notification on cron run
already merged Viktor Gurov
08:23 AM Feature #8794: NTP authentication support
Server side authentication support:
https://github.com/pfsense/pfsense/pull/4472
Viktor Gurov
07:06 AM Bug #10949: PPPoE server can't be added
Fix:
https://github.com/pfsense/pfsense/pull/4471
Viktor Gurov
06:46 AM Bug #10949 (Resolved): PPPoE server can't be added
I tested adding a PPPoE server on the latest snapshot. ... Danilo Zrenjanin
07:02 AM Bug #6598: "PPPoE clients" placeholder in rules only includes first PPPoE server instance
I couldn't add PPPoE server on the latest snapshot.... Danilo Zrenjanin
06:28 AM Revision 96e6e165: Gateway group popover fix. Issue #10948
Viktor Gurov
06:12 AM Feature #10912 (Resolved): DNS Domain Overrides - more than one target IP
Tested on :... Danilo Zrenjanin
04:48 AM Feature #7406: Ability to clear all dhcp leases at once
https://github.com/pfsense/pfsense/pull/4470 Viktor Gurov
03:11 AM pfSense Packages Feature #6176: Privilege for OpenVPN Client Export
> bearsh bearsh wrote:
> > it would be very cool to be able to limit access for users to their own client configs. u...
Viktor Gurov
01:29 AM Bug #10948: Gateway group popover not populated on firewall_rules.php
https://github.com/pfsense/pfsense/pull/4469 Viktor Gurov
12:05 AM Bug #9636: uninstall packages
Unable to reproduce on latest 2.5 nightly builds Michael Spears

10/02/2020

04:15 PM Revision 4e9467ae: Revised fix 10945 to include gateway popup
Steve Beaver
04:10 PM Bug #10708: ZFS bootpool boot symlink issue
I had another issue with bootpool getting out of sync on an upgrade and so I decided to try every partition scheme ot... Paul Magid
03:39 PM pfSense Packages Bug #10941: pfBlockerNG-devel Bug in ipv6 lists when updating
I could not reproduce this using settings/rules as close as possible. Marcos M
02:05 PM pfSense Docs Correction #10559 (Resolved): Feedback on User Management — Granting Users Access to SSH
I revised the recipe and updated this (and other) references to match the GUI on 2.5.0. Jim Pingle
02:00 PM Revision 35339786: Fixed #9855
by preventing form submission on second and subsequent clicks Steve Beaver
01:18 PM Revision 11a71857: Popover sanitizer stuff is more logically provided in pfSense.js where other popover controls live
Steve Beaver
12:57 PM Revision 72f4fb2c: Fixed #10945
By adding the HTML elements used in pfSense popovers to the default sanitizer whitelist Steve Beaver
12:40 PM Bug #10945 (Resolved): Alias popup not displaying contents
Anonymous
12:37 PM Bug #10945: Alias popup not displaying contents
The gateway popup issue is not related to this one. See https://redmine.pfsense.org/issues/10948 Anonymous
10:23 AM Bug #10945 (In Progress): Alias popup not displaying contents
Aliases are working OK for me but Gateway popovers are empty still. Jim Pingle
09:05 AM Bug #10945 (Resolved): Alias popup not displaying contents
Tested the patch on the:... Danilo Zrenjanin
08:05 AM Bug #10945: Alias popup not displaying contents
Applied in changeset commit:72f4fb2c0bad87e04ce4a442724c1753bbfb1678. Anonymous
08:01 AM Bug #10945 (Feedback): Alias popup not displaying contents
Anonymous
07:54 AM Bug #10945: Alias popup not displaying contents
Specifically adding table elements to the sanitizer's list of allowed content is effective:... Anonymous
07:22 AM Bug #10945: Alias popup not displaying contents
The issue is caused by changes in Bootstrap 3.4.1 which disable HTML in popovers. In theory, this should turn off the... Anonymous
12:45 AM Bug #10945: Alias popup not displaying contents
same issue with gateway_info_popup()
and on Firewall NAT pages too
Viktor Gurov
12:30 PM Bug #10948 (Resolved): Gateway group popover not populated on firewall_rules.php
This bug does not appear to be related to the similar alias popover issue.
If the user hovers over a gateway group...
Anonymous
11:51 AM Bug #7375 (Pull Request Review): User with restricted privileges can still delete all monitoring/graphing data
Jim Pingle
11:47 AM Bug #7375: User with restricted privileges can still delete all monitoring/graphing data
https://github.com/pfsense/FreeBSD-ports/pull/951 Viktor Gurov
11:28 AM Revision fd3af9eb: Rebind syslogd on interface change. Issue #9660
Viktor Gurov
10:54 AM Bug #9058: Kernel panic during L2TP retransmit
Bianco Veigel wrote:
> it crashed again with 2.5.0.a.20200930.0050
Thanks for your patience so far, it's very app...
Mark Johnston
03:59 AM Bug #9058: Kernel panic during L2TP retransmit
it crashed again with 2.5.0.a.20200930.0050 Bianco Veigel
10:15 AM Bug #9855 (Resolved): CSRF error at login when clicking the 'sign in' button multiple times
After a gitsync I can't induce a CSRF error at login in either Chrome or Firefox. Jim Pingle
09:10 AM Bug #9855: CSRF error at login when clicking the 'sign in' button multiple times
Applied in changeset commit:353397867b30842f643a40ffd2eb6986bed5b32a. Anonymous
09:01 AM Bug #9855 (Feedback): CSRF error at login when clicking the 'sign in' button multiple times
Anonymous
09:10 AM Bug #10947: Virtual interface assignment can't be done in CLI interface assignment
The same is likely true of many virtual interface types (GIF, GRE, etc) and the solution is likely the same for all o... Jim Pingle
08:13 AM Bug #10947 (Resolved): Virtual interface assignment can't be done in CLI interface assignment
Hi,
I have added new VMXNET3 interfaces to the pfSense VM and migrated the working E1000 Interfaces to the new VM...
Hamid Hashemi
07:45 AM Bug #9660 (Pull Request Review): Syslogd keeps using old IP address after interface IP address change
Jim Pingle
06:31 AM Bug #9660: Syslogd keeps using old IP address after interface IP address change
https://github.com/pfsense/pfsense/pull/4468 Viktor Gurov
07:42 AM Feature #4776: Add 802.1x dynamic vlan support
I don't think it's something we want to pile onto 2.5.0 right now. We're starting to lock down what will be added at ... Jim Pingle
04:21 AM Feature #4776: Add 802.1x dynamic vlan support
Dynamic VLAN support is not compiled:... Viktor Gurov
07:33 AM Bug #6025 (Pull Request Review): Load balancing fails when one gateway has a weight of 1 and another gateway has a weight >1
Jim Pingle
02:26 AM Bug #6025: Load balancing fails when one gateway has a weight of 1 and another gateway has a weight >1
https://github.com/pfsense/pfsense/pull/4467 Viktor Gurov
07:31 AM Feature #10946 (Pull Request Review): Sanitize WiFi 802.1x RADIUS shared secret
Jim Pingle
12:23 AM Feature #10946: Sanitize WiFi 802.1x RADIUS shared secret
https://github.com/pfsense/pfsense/pull/4466 Viktor Gurov
12:19 AM Feature #10946 (Resolved): Sanitize WiFi 802.1x RADIUS shared secret
"auth_server_shared_secret" and "auth_server_shared_secret2" from wireless interfaces configuration 802.1x RADIUS Opt... Viktor Gurov
07:24 AM Revision 821be56a: Load balancing when one gateway has a weight of 1 and another gateway has a weight >1. Fixes #6025
Viktor Gurov
05:22 AM Revision fd33f774: Sanitize WiFi 802.1x RADIUS shared secrets. Implements #10946
Viktor Gurov
12:07 AM Bug #10677 (Resolved): pfSense 2.5 incorrect rtwn(4) wireless regexp
2.5.0.a.20201001.0050 can find rtwn(4) correctly Viktor Gurov

10/01/2020

09:21 PM pfSense Packages Bug #10429: Status Traffic Total broken 2.4.5
Manuel Piovan wrote:
> https://forum.netgate.com/topic/151914/traffic-totals-hourly-report-problem/
pfSense versi...
Vinoth Kumar R
03:36 PM pfSense Packages Feature #10789 (Pull Request Review): FRR integrated configuration and hitless reloads
Jim Pingle
02:44 PM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
Fixed case of the fat fingers in frr_bgp.xml: https://github.com/pfsense/FreeBSD-ports/pull/950 Ben Hughes
03:32 PM pfSense Docs Correction #9372 (Resolved): Feedback on User Management — Configuring User Authentication Servers
I just pushed changes which cover this and more. Jim Pingle
02:13 PM Revision 1f7f2b6b: Sanitize secret2. Implements #10944
Viktor Gurov
02:05 PM Revision 72a9d589: Remove unnecessary parameter from filter_rule_tracker()
Renato Botelho
01:51 PM Revision 1574802c: Fix #6030
Use a range of tracker ids for anti-lockout, bogons and rfc1918 rules so
any rule has a unique identifier
Renato Botelho
01:43 PM pfSense Docs Correction #10877 (Resolved): Feedback on VPN — IPsec — Configuring an IPsec Remote Access Mobile VPN using IKEv2 with EAP-MSCHAPv2
Jim Pingle
01:42 PM pfSense Docs Correction #8862 (Resolved): [feedback form] Include configuration examples for IPv6 WANs
I added a warning to the page informing users that only the ISP can tell them what their settings should be for IPv6,... Jim Pingle
01:19 PM Bug #10668 (Resolved): curl -T "{file1,file2}" loops forever eating up the RAM
Renato Botelho
01:10 PM Bug #10668: curl -T "{file1,file2}" loops forever eating up the RAM
After updating ACME package to the latest version, the system was updated with curl 7.68.0 (amd64-portbld-freebsd11.3... robi robi
12:34 PM Bug #10668 (Feedback): curl -T "{file1,file2}" loops forever eating up the RAM
I've imported curl 7.68.0, which fixes this issue. Also bumped revision of ACME port to 0.68_3 and added a explicit ... Renato Botelho
12:49 PM Revision 4537e922: Same RADIUS ACL parser for IPsec/OpenVPN. Implements #10469
Viktor Gurov
12:43 PM Bug #10943: boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
Appears to be limited to EFI and also affects upgrades, not just new installs:
https://forum.netgate.com/topic/157...
Jim Pingle
07:38 AM Bug #10943: boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
i tested also the new build, 20201001.0650
after the reboot done by the upgrade process you don't lose access to th...
Manuel Piovan
07:09 AM Bug #10943 (Resolved): boot fail after upgrade to the latest snapshot 20201001.0050. if bios is set to efi
how to reproduce:
created a new virtual machine under esxi with bios set to efi
install a previous snapshot, everyt...
Manuel Piovan
12:42 PM Feature #10469 (Pull Request Review): Same RADIUS Cisco-AVPair parser code for both OpenVPN/IPsec
Jim Pingle
07:55 AM Feature #10469: Same RADIUS Cisco-AVPair parser code for both OpenVPN/IPsec
https://github.com/pfsense/pfsense/pull/4464 Viktor Gurov
12:41 PM Feature #10944 (Pull Request Review): Sanitize secret2
Jim Pingle
09:14 AM Feature #10944: Sanitize secret2
https://github.com/pfsense/pfsense/pull/4465 Viktor Gurov
09:13 AM Feature #10944 (Resolved): Sanitize secret2
Sanitize 'secret2' - PPPoE Secondary RADIUS Server shared secret Viktor Gurov
12:15 PM Revision d1c961ff: Merge pull request #4463 from vktg/ldapauth2307fix
Renato Botelho
11:28 AM Revision 0db1cc68: Fix #10743: Enable/Disable GoogleStadia checkbox
Renato Botelho
11:23 AM Bug #10671: pfsense 2.4.5_1 does not boot on Gen2 2012R2 HyperV VM
I have the same issue with Hyper-V under Windows Server 2019. I had to roll back to 2.4.4 (that was the latest .iso I... Jeff Munk
10:35 AM Bug #10945 (Resolved): Alias popup not displaying contents
On firewall rules when hovering over an alias, the info popup only displays the header "Alias details" and no content... Jim Pingle
09:50 AM Bug #3334 (Resolved): Status/Traffic Graph isn't IPv6 ready
I'd say it's working well enough for now. I tried it on a few more systems and it's OK, even on arm. Jim Pingle
05:55 AM Bug #3334 (Feedback): Status/Traffic Graph isn't IPv6 ready
Jim Pingle wrote:
> Also it looks like there is an odd condition where the first time you switch to iftop, it doesn'...
Renato Botelho
05:54 AM Bug #3334: Status/Traffic Graph isn't IPv6 ready
Jim Pingle wrote:
> There is still a problem or two here.
>
> The iftop binary is not present unless you manually...
Renato Botelho
09:00 AM Bug #6030 (Feedback): Duplicated tracker IDs on block private networks rules
Applied in changeset commit:1574802cdd0aa00e93377d326d907f8c0217b8ea. Renato Botelho
08:27 AM Bug #6030: Duplicated tracker IDs on block private networks rules
I'm working on a fix Renato Botelho
07:25 AM Feature #10934 (Feedback): Add ral(4) to arm64
PR has been merged. Thanks! Renato Botelho
07:16 AM Bug #10942 (Feedback): LDAP Auth error after update 2.5.0.a.20200930.1303
PR has been merged. Thanks! Renato Botelho
07:06 AM Bug #10942: LDAP Auth error after update 2.5.0.a.20200930.1303
Edivan Carneiro de castro wrote:
> Viktor Gurov wrote:
> > fix:
> > https://github.com/pfsense/pfsense/pull/4463
...
Viktor Gurov
06:49 AM Bug #10942: LDAP Auth error after update 2.5.0.a.20200930.1303
Viktor Gurov wrote:
> fix:
> https://github.com/pfsense/pfsense/pull/4463
I dont understand how to apply this fix
Teste Teste
05:42 AM Bug #10942 (Pull Request Review): LDAP Auth error after update 2.5.0.a.20200930.1303
Renato Botelho
12:49 AM Bug #10942: LDAP Auth error after update 2.5.0.a.20200930.1303
fix:
https://github.com/pfsense/pfsense/pull/4463
Viktor Gurov
07:01 AM pfSense Packages Bug #10937: HAProxy frontend and backend entry limit
I looked for existing CVE's around increasing the limit, but did not find any issues with it. I would agree however t... Marcos M
06:35 AM Feature #10743 (Feedback): Traffic shaper wizard: Add Google Stadia port range
Applied in changeset commit:0db1cc68a452bc8fddb3cea9ad2997c0bb49d0ec. Renato Botelho
06:31 AM Bug #9646 (Feedback): OpenSSL 1.1.1 does not list engines for AES-NI or BSD crypto
It's working as expected on recent snapshots Renato Botelho
05:58 AM Bug #9058 (Feedback): Kernel panic during L2TP retransmit
Renato Botelho
05:48 AM Revision ac4a56f1: LDAP group search fix. Issue #10942
Viktor Gurov
03:41 AM Feature #10896 (Resolved): Multiple IPs for one DNS entry in unbound resolver override
Tested on :... Danilo Zrenjanin
03:21 AM Feature #10711 (Resolved): Allow to use OpenVPN TAP interfaces in DHCP Relay
Tested on :... Danilo Zrenjanin
03:05 AM pfSense Packages Bug #10939 (Resolved): default port is not fixed on 2.4.5
Tested on :... Danilo Zrenjanin

09/30/2020

11:25 PM pfSense Packages Bug #10930 (Resolved): Wrong blocklist from dshield.org
test on new pfblockerng-devel pkg install on 2.4.5p1 and 2.5.0-DEVELOPMENT (arm)built on Wed Sep 30 18:54:01 EDT 2020... Jordan G
12:34 PM pfSense Packages Bug #10930 (Feedback): Wrong blocklist from dshield.org
PR has been merged. Thanks! Renato Botelho
08:40 AM pfSense Packages Bug #10930 (Pull Request Review): Wrong blocklist from dshield.org
Jim Pingle
03:30 AM pfSense Packages Bug #10930: Wrong blocklist from dshield.org
Fix:
https://github.com/pfsense/FreeBSD-ports/pull/946
Viktor Gurov
07:17 PM Bug #10942 (Resolved): LDAP Auth error after update 2.5.0.a.20200930.1303
pfsense given the follow error auth LDAP after update
Crash report details:
PHP Errors:
[30-Sep-2020 18:10:54 ...
Teste Teste
05:27 PM Bug #10610: Package upgrade or reinstall hangs indefintely on the console
pkg-1.5.16 is the fixed version on 2.4.5 Renato Botelho
02:34 PM Bug #10610: Package upgrade or reinstall hangs indefintely on the console
Renato Botelho wrote:
> pkg 1.15.6 should fix this problem. If it passes all tests we can apply it to 2.4.5 as well...
Renato Botelho
05:07 PM Revision 6f766384: Merge pull request #4273 from vktg/ovpn6avpair
Renato Botelho
05:07 PM Revision f18c95b9: Merge pull request #4462 from vktg/dnsdomaintip
Renato Botelho
05:07 PM Revision 8f3c14b1: Merge pull request #4461 from vktg/enanochecksum
Renato Botelho
05:07 PM Revision 1eea4340: Merge pull request #4460 from vktg/pppoerulesfix
Renato Botelho
02:19 PM pfSense Packages Bug #10941 (Closed): pfBlockerNG-devel Bug in ipv6 lists when updating

I posted initially in the forum with screenshots in case it is something I am doing but during update the pfblock...
Rick Coats
02:07 PM Revision a220a22a: Fix encoding and validation on load_balancer_monitor*. Fixes #10940
Jim Pingle
12:38 PM pfSense Packages Feature #10915 (Feedback): security/pfSense-pkg-sudo sudo.inc enhancement for better support of NRPE
PR has been merged. Thanks! Renato Botelho
05:11 AM pfSense Packages Feature #10915: security/pfSense-pkg-sudo sudo.inc enhancement for better support of NRPE
Previous PR superseded by https://github.com/pfsense/FreeBSD-ports/pull/947 Infra Weavers
12:32 PM pfSense Packages Bug #10939 (Feedback): default port is not fixed on 2.4.5
PR has been merged. Thanks! Renato Botelho
08:38 AM pfSense Packages Bug #10939 (Pull Request Review): default port is not fixed on 2.4.5
Jim Pingle
02:07 AM pfSense Packages Bug #10939: default port is not fixed on 2.4.5
Fix:
https://github.com/pfsense/FreeBSD-ports/pull/945
Viktor Gurov
02:01 AM pfSense Packages Bug #10939 (Resolved): default port is not fixed on 2.4.5
it seems https://github.com/pfsense/FreeBSD-ports/commit/8e931a80646180ac8e15b97876140fa0c3e22eca#diff-1eba1393d5e47b... Viktor Gurov
12:31 PM pfSense Packages Feature #10908 (Feedback): FreeRADIUS server certificate not using full CA chain
PR has been merged. Thanks! Renato Botelho
08:35 AM pfSense Packages Feature #10908 (Pull Request Review): FreeRADIUS server certificate not using full CA chain
Jim Pingle
01:24 AM pfSense Packages Feature #10908: FreeRADIUS server certificate not using full CA chain
https://github.com/pfsense/FreeBSD-ports/pull/944 Viktor Gurov
12:08 PM Bug #6598 (Feedback): "PPPoE clients" placeholder in rules only includes first PPPoE server instance
PR has been merged. Thanks! Renato Botelho
08:33 AM Bug #6598 (Pull Request Review): "PPPoE clients" placeholder in rules only includes first PPPoE server instance
Jim Pingle
12:27 AM Bug #6598: "PPPoE clients" placeholder in rules only includes first PPPoE server instance
https://github.com/pfsense/pfsense/pull/4460 Viktor Gurov
12:08 PM Feature #10723 (Feedback): Disable "Hardware Checksum Offloading" if VM is detected
PR has been merged. Thanks! Renato Botelho
08:38 AM Feature #10723 (Pull Request Review): Disable "Hardware Checksum Offloading" if VM is detected
Jim Pingle
01:38 AM Feature #10723: Disable "Hardware Checksum Offloading" if VM is detected
ena(4) fix:
https://github.com/pfsense/pfsense/pull/4461
Viktor Gurov
12:08 PM Feature #10912 (Feedback): DNS Domain Overrides - more than one target IP
PR has been merged. Thanks! Renato Botelho
08:48 AM Feature #10912 (Pull Request Review): DNS Domain Overrides - more than one target IP
Jim Pingle
05:24 AM Feature #10912: DNS Domain Overrides - more than one target IP
https://github.com/pfsense/pfsense/pull/4462 Viktor Gurov
12:07 PM Feature #10454 (Feedback): OpenVPN+RADIUS+Cisco-AVPair IPv6 ACL
PR has been merged. Thanks! Renato Botelho
10:22 AM Revision 5fc9aa09: DNS Domain Overrides help tip. Issue #10912
Viktor Gurov
09:36 AM Bug #9349 (Feedback): IPSec service start/stop/restart fails after settings change
Anonymous
09:18 AM Feature #4763 (Resolved): Restore from backup that contains only area Traffic Shaper doesn't restore Limiters
Anonymous
06:48 AM pfSense Packages Bug #9980 (Closed): Fresh install of Suricata 4.1.5 package warns about CVE-2015-3152; need newer MySQL
no such message on pfSense 2.4.5-p1/2.5 with suricata-5.0.3/suricata-4.1.8 Viktor Gurov
06:37 AM Revision d81121e1: Disable "Hardware Checksum Offloading" if ena(4) is detected. Implements #10723
Viktor Gurov
05:25 AM Revision c227689b: PPPoE clients rules fix. Issue #6598
Viktor Gurov
04:39 AM Feature #9768 (Closed): IPsec for site-to-site scenario where one side has dynamic ip
Implemented in #7095 and #10214 Viktor Gurov
04:36 AM Feature #7410 (Closed): IPSEC multiple dynamic IP remote clients
Implemented in #7095 and #10214 Viktor Gurov

09/29/2020

10:22 PM Revision 82b8ad2b: Merge pull request #4458 from vktg/rfc2307userdnupdate
Renato Botelho
10:22 PM Revision e97eeb7d: Merge pull request #4385 from vktg/nohwchksumvm
Renato Botelho
10:21 PM Revision 9ae8cf51: Merge pull request #4459 from vktg/ipsecmultiph1
Renato Botelho
10:21 PM Revision f76cec6d: Remove old comment
Renato Botelho
10:21 PM Revision 1b4cb00f: IPsec PH1 creation fix. Issue #9592
Viktor Gurov
10:21 PM Revision 80f1c44b: Use init_config_arr() to initialize config items
Renato Botelho
10:21 PM Revision 6279f1b8: Style fixes
Renato Botelho
10:21 PM Revision 71e7de02: Simplify logic
Renato Botelho
10:21 PM Revision 2b6de647: Create a pointer to reduce really long lines
Renato Botelho
10:21 PM Revision 413e939f: Combine 2 similar tests to simplify logic
Renato Botelho
10:21 PM Revision 58e0bfbc: Combine 2 similar tests to simplify logic
Renato Botelho
10:21 PM Revision b2a98518: Remove unnecessary variable
Renato Botelho
10:21 PM Revision dfc51883: Move 'unable to find config' condition early and reduce indentation
Renato Botelho
10:21 PM Revision 7489746e: Leave function when debug file could not be opened
Renato Botelho
10:21 PM Revision 0c9d489e: Style fixes
Renato Botelho
06:49 PM Todo #9052 (Resolved): Update Font-Awesome
Thanks for catching that Bill! I had originally looked that part over. I agree it will be challenging (I had original... Jared Dillard
05:37 PM Todo #9052: Update Font-Awesome
Jared Dillard wrote:
> With the current shim in place we don't have to tackle the renaming of classes just yet, in f...
Bill Meeks
03:10 PM Todo #9052: Update Font-Awesome
With the current shim in place we don't have to tackle the renaming of classes just yet, in fact it maybe be better t... Jared Dillard
06:27 PM Bug #9058: Kernel panic during L2TP retransmit
Bianco Veigel wrote:
> I'd like to test the new version, but there is still no 20200929-1250.
A new snapshot is a...
Renato Botelho
05:11 PM Bug #9058: Kernel panic during L2TP retransmit
Bianco Veigel wrote:
> I'd like to test the new version, but there is still no 20200929-1250.
That build failed. ...
Renato Botelho
04:05 PM Bug #9058: Kernel panic during L2TP retransmit
I'd like to test the new version, but there is still no 20200929-1250. Bianco Veigel
09:28 AM Bug #9058: Kernel panic during L2TP retransmit
https://reviews.freebsd.org/D26586 was also imported to devel-12 branch. Next round of snapshots (1250) will have th... Renato Botelho
07:26 AM Bug #9058: Kernel panic during L2TP retransmit
Bianco Veigel wrote:
> I've updated to 2.5.0.a.20200928.1250 and got the same crash as before. I've attached the cra...
Renato Botelho
06:25 AM Bug #9058 (In Progress): Kernel panic during L2TP retransmit
Renato Botelho
05:24 AM Bug #9058: Kernel panic during L2TP retransmit
I've updated to 2.5.0.a.20200928.1250 and got the same crash as before. I've attached the crashdump.
Is there anyt...
Bianco Veigel
05:31 PM pfSense Packages Feature #10789 (Feedback): FRR integrated configuration and hitless reloads
PR has been merged. Thanks! Renato Botelho
05:30 PM Feature #10723 (Feedback): Disable "Hardware Checksum Offloading" if VM is detected
Applied in changeset commit:12a0edbb3f6fe89c9c0905f5ea9095b71ac892a7. Viktor Gurov
05:22 PM Feature #10723 (In Progress): Disable "Hardware Checksum Offloading" if VM is detected
PR has been merged. Thanks!
Keep ticket as In Progress since we need the same for ena interfaces
Renato Botelho
05:25 PM pfSense Packages Bug #10932: wrong link on haproxy
PR has been merged. Thanks! Renato Botelho
05:22 PM Bug #9592 (Feedback): VTI interface down because interface number created is greater than ipsec32768
PR has been merged. Thanks! Renato Botelho
05:22 PM Feature #9527 (Feedback): Add ability for LDAP extended query on groups in RFC2307 containers.
PR has been merged. Thanks! Renato Botelho
03:16 PM pfSense Docs Correction #10920 (Resolved): Feedback on Packages — Using the Package Manager
I updated the general package info on https://docs.netgate.com/pfsense/en/latest/packages/index.html and https://docs... Jim Pingle
03:00 PM pfSense Docs Correction #10895 (Resolved): Feedback on Interface Types and Configuration — GIF (Generic tunnel InterFace)
Updated GIF at https://docs.netgate.com/pfsense/en/latest/interfaces/gif.html
Updated GRE at https://docs.netgate.co...
Jim Pingle
01:45 PM Bug #10610 (Feedback): Package upgrade or reinstall hangs indefintely on the console
pkg 1.15.6 should fix this problem. If it passes all tests we can apply it to 2.4.5 as well Renato Botelho
01:24 PM Bug #10610: Package upgrade or reinstall hangs indefintely on the console
It's a bug on pkg. I'm working on a fix Renato Botelho
12:39 PM Bug #10938 (Not a Bug): "librrd.so.8" not found with 2.4.5
It's not a general bug but something amiss with your installation. That file should come from the rrdtool FreeBSD pkg... Jim Pingle
11:45 AM Bug #10938 (Not a Bug): "librrd.so.8" not found with 2.4.5
After upgrading to the latest 2.4.5-RELEASE-p1 (arm64) running on Netgate SG-1100
I get this one "librrd.so.8" not f...
George K
12:28 PM Bug #10352: RADIUS authentication fails with MSCHAPv1 or MSCHAPv2 when passwords contain international characters
Use the current release 2.4.5-p1 or a development snapshot (2.5.0). Testing with older/unsupported versions is irrele... Jim Pingle
11:30 AM Bug #10352: RADIUS authentication fails with MSCHAPv1 or MSCHAPv2 when passwords contain international characters
I tried with PAP and MD5-CHAP on
2.4.3-RELEASE (amd64) memstick serial and
FreeBSD 11.1-RELEASE-p7
but the resu...
Oscar Mrbt
12:13 PM Bug #9636: uninstall packages
I am able to reproduce this using the nightly image from Sept 14th, as well as the latest image from Sept 29th.
# ...
Marcos M
11:53 AM pfSense Packages Bug #10937: HAProxy frontend and backend entry limit
The input variable change is an OK workaround (I'm not sure why it's at 5000) but also the form code should probably ... Jim Pingle
11:35 AM pfSense Packages Bug #10937: HAProxy frontend and backend entry limit
Making the following change then restarting php-fpm and webConfigurator (option 16 & 11 in console) resolved the issu... Marcos M
11:04 AM pfSense Packages Bug #10937: HAProxy frontend and backend entry limit
Some additional files from testing. Marcos M
10:42 AM pfSense Packages Bug #10937 (Resolved): HAProxy frontend and backend entry limit
There seems to be some sort of limit in the number of entries/rows you can have in a single haproxy frontend or backe... Marcos M
09:57 AM pfSense Packages Bug #10936 (Resolved): both haproxy/haproxy-devel non-existent option lb-agent-chk
both 2.4.5-p1 and 2.5.0
setting Health check method to Agent...
Manuel Piovan
07:54 AM pfSense Packages Feature #10665 (Assigned): Manual OSPF neighbor definitions
Azamat Khakimyanov
07:53 AM pfSense Packages Feature #10665: Manual OSPF neighbor definitions
Tested on:
2.5.0-DEVELOPMENT (amd64)
built on Tue Sep 29 01:01:39 EDT 2020
FreeBSD 12.2-PRERELEASE
Issue with a...
Azamat Khakimyanov
05:49 AM pfSense Packages Feature #10479 (Resolved): Keep settings after deinstall option
Tested on 2.4.5_p1 and on 2.5.0-DEVELOPMENT (built on Tue Sep 29 01:00:34 EDT 2020)
There is an option "Save setting...
Azamat Khakimyanov
03:57 AM pfSense Packages Bug #10552 (Resolved): Typo in OpenBGPD's settings page
tested on 2.4.5_p1 and on 2.5.0-DEVELOPMENT (built on Tue Sep 29 01:00:34 EDT 2020)
It's Router-ID now.
This bug ...
Azamat Khakimyanov

09/28/2020

08:24 PM Bug #10409 (Resolved): OpenVPN client without userpass hangs system startup
Tested in
2.5.0-DEVELOPMENT (amd64)
built on Sun Sep 20 06:59:15 EDT 2020
FreeBSD 12.2-PRERELEASE
As expected,...
Max Leighton
03:42 PM pfSense Docs Correction #9618 (Resolved): Feedback on System Monitoring — Firewall Logs
Relevant parts should be covered by the latest round of doc updates. Jim Pingle
12:40 PM pfSense Docs Correction #9376 (Resolved): Feedback on System Monitoring — Filter Log Format for pfSense 2.2
Added it to the action line as well as reason and direction, since all of them could have that value (per filterlog.c) Jim Pingle
12:36 PM pfSense Docs Correction #9377 (Rejected): log file format : missing igmp. <protocol-specific-data> ::= <tcp-data> | <udp-data> | <icmp-data> | <carp-data>
I don't see anything in filterlog which would handle igmp data in that field as stated. The person reporting this mig... Jim Pingle
12:31 PM pfSense Docs Correction #9379 (Resolved): Feedback on Interfaces — Using a Large Number of Interfaces
Updated doc with the advice above. Jim Pingle
11:16 AM pfSense Docs New Content #10774 (Resolved): Feedback on Installing and Upgrading — Upgrade Troubleshooting
Tip added: https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide-update.html#upgrading-using-the-console Jim Pingle
08:13 AM pfSense Packages Bug #10935 (New): FRR 0.6.7-6 - BGPD service recycled IPv6 without Route Map
https://forum.netgate.com/topic/157120/frr-0-6-7_6-bgp-won-t-start-without-route-map-ipv6-unicast?_=1601149473142
...
Jeremy Peterson
06:08 AM Bug #9058 (Feedback): Kernel panic during L2TP retransmit
I've imported the fix to pfSense. Next round of snapshots with timestamp bigger than 20200928.0650 will contain the ... Renato Botelho
02:00 AM Bug #9450: Multiwan gateway group fail-over not working as expected (possible race condition)
Dear gents
is the behavior I describe
https://forum.netgate.com/topic/156890/dpinger-broken-or-dashboard-broken...
Jörn Greszki
01:56 AM Bug #10546: Gateways removed from routing groups based on low alert thresholds
Dear gents
is the behavior I describe
https://forum.netgate.com/topic/156890/dpinger-broken-or-dashboard-broken...
Jörn Greszki

09/27/2020

06:20 PM Feature #10934: Add ral(4) to arm64
Opened a PR: https://github.com/pfsense/FreeBSD-src/pull/38 Steve Wheeler
06:05 AM Feature #10934 (Resolved): Add ral(4) to arm64
As the title the ral(4) driver is not included in arm64 images.
The RT3090 device that requires it is one of the f...
Steve Wheeler
06:14 PM Bug #10889 (Resolved): Hover text missing from Static Routes Page
Tested in
2.5.0-DEVELOPMENT (amd64)
built on Sun Sep 27 13:02:36 EDT 2020
FreeBSD 12.2-PRERELEASE
Mouseover t...
Max Leighton
05:38 PM Bug #9303 (Resolved): HA sync : disabling captive portal HA sync does remove all zones on slave
Tested in
2.5.0-DEVELOPMENT (amd64)
built on Sun Sep 27 13:02:36 EDT 2020
FreeBSD 12.2-PRERELEASE
The zones ...
Max Leighton
11:22 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
I am not sure if my issue:
https://forum.netgate.com/topic/156890/dpinger-broken-or-dashboard-broken-or-my-brain-i...
Jörn Greszki

09/26/2020

02:01 PM Todo #9052: Update Font-Awesome
Thanks Jared. Just to make sure I'm clear, this FontAwsome update is currently limited to just pfSense-2.5, or do you... Bill Meeks
10:15 AM pfSense Packages Bug #10933: Retired / Invalid IPv4 lists in pfBlockerNG
The user email and password need to be included in the link as follows for the BB_C2 feed to work, with %40 replacing... Abhinav Tella
09:36 AM pfSense Packages Bug #10933 (Resolved): Retired / Invalid IPv4 lists in pfBlockerNG
I went through the currently available IPv4 lists in pfBlockerNG-devel and noted the ones that are no longer maintain... Marcos M

09/25/2020

11:39 PM Revision fb435045: Update Font Awesome to v5 using shim
Jared Dillard
06:44 PM Todo #9052: Update Font-Awesome
Thanks Bill! I was going to post an update when it said someone else had commented.
The icons will need to updated...
Jared Dillard
06:20 PM Todo #9052: Update Font-Awesome
I will add that the Snort and Suricata GUI packages both use FontAwesome icons in many places, and a cursory review o... Bill Meeks
06:09 PM Todo #9052: Update Font-Awesome
Still working on this, but as an update:
Going from v4 to v5 is a breaking change (as expected) and a number of ic...
Jared Dillard
06:30 PM Revision 561cc3e5: diag_dns.php: Fix button icon to match text for alias actions.
Jim Pingle
05:17 PM pfSense Packages Bug #10932: wrong link on haproxy
PR https://github.com/pfsense/FreeBSD-ports/pull/943 Manuel Piovan
04:00 PM pfSense Packages Bug #10932 (Resolved): wrong link on haproxy
package haproxy
if you click on
"related log entries"
https://*/status_pkglogs.php?pkg=haproxy
lead to 404 ...
Manuel Piovan
04:56 PM Bug #9058: Kernel panic during L2TP retransmit
A fix was pushed on FreeBSD. I'm going to import it to pfSense Renato Botelho
02:28 PM Bug #9058: Kernel panic during L2TP retransmit
As far as I can tell this has been accepted upstream (https://svnweb.freebsd.org/changeset/base/366167). Can someone ... Bianco Veigel
04:11 PM Revision f0c51530: System DNS Server changes. Implements #10931
There are significant changes here, but ultimately should be a smooth
transition. See https://redmine.pfsense.org/iss...
Jim Pingle
03:23 PM pfSense Docs Correction #10787: Feedback on Services — DNS — Performing a DNS Lookup
Also noteworthy that I fixed the icon for the button in the "Update Alias" case.
See pfsense:commit:561cc3e529bcd5...
Jim Pingle
02:16 PM pfSense Docs Correction #10787 (Resolved): Feedback on Services — DNS — Performing a DNS Lookup
I updated the page with better info, should all be covered now. Jim Pingle
02:35 PM pfSense Docs New Content #10489 (Resolved): Feedback on System Monitoring — Remote Logging with Syslog
I fixed up the log settings page(s), removed redundant info, added new stuff for 2.5, and added notes about using sys... Jim Pingle
01:14 PM pfSense Docs Correction #10180 (Resolved): Feedback on Development — Obtaining Panic Information for Developers
Rewrote the page to remove the outdated info, and added some more missing info. Jim Pingle
12:00 PM pfSense Packages Feature #10789 (Pull Request Review): FRR integrated configuration and hitless reloads
Jim Pingle
11:35 AM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
Fixup PR: https://github.com/pfsense/FreeBSD-ports/pull/942 Ben Hughes
11:20 AM Feature #10931 (Feedback): system.php: Add option to omit DNS Servers from resolv.conf
Applied in changeset commit:f0c51530cd31a5003d5a18cfa32575d0a9ff2f5f. Jim Pingle
11:10 AM Feature #10931: system.php: Add option to omit DNS Servers from resolv.conf
Tugged on a dangling thread of this sweater and unraveled quite a lot.
There were three functions with confusing n...
Jim Pingle
07:37 AM Feature #10931 (In Progress): system.php: Add option to omit DNS Servers from resolv.conf
Jim Pingle
07:36 AM Feature #10931 (Resolved): system.php: Add option to omit DNS Servers from resolv.conf
Some users prefer that the system _only_ use the DNS Resolver/Forwarder for DNS resolution, rather than the entries i... Jim Pingle
11:16 AM Bug #9592 (Pull Request Review): VTI interface down because interface number created is greater than ipsec32768
Jim Pingle
09:44 AM Bug #9592: VTI interface down because interface number created is greater than ipsec32768
Regression fix:
https://github.com/pfsense/pfsense/pull/4459
Viktor Gurov
09:45 AM Feature #10214: Allow IPsec duplicate endpoints
Fixed in https://redmine.pfsense.org/issues/9592#note-5 Viktor Gurov
08:50 AM Feature #10214 (Pull Request Review): Allow IPsec duplicate endpoints
Jim Pingle
08:42 AM Feature #10214: Allow IPsec duplicate endpoints
see also #9768 and #7410 Viktor Gurov
08:41 AM Feature #10214: Allow IPsec duplicate endpoints
"Gateway duplicates" checkbox allows to create duplicate PH1 entries in WebGUI,
but /var/etc/ipsec/swanctl.conf only...
Viktor Gurov
07:11 AM Bug #10925 (Resolved): PHP: Invalid argument supplied for foreach() in /etc/inc/util.inc on line 2640
Craig Weber wrote:
> Renato Botelho wrote:
> > Applied in changeset commit:ffe95182999a344dd926c5079a3f74ccc62e0f46...
Renato Botelho
06:11 AM Bug #10925: PHP: Invalid argument supplied for foreach() in /etc/inc/util.inc on line 2640
Renato Botelho wrote:
> Applied in changeset commit:ffe95182999a344dd926c5079a3f74ccc62e0f46.
Great, thank you! I...
Craig Weber
07:09 AM Feature #790 (New): Advanced options for dnsclient (resolv.conf)
Removing target, PR was closed (no activity for ~1yr after changes were requested) Jim Pingle
05:53 AM Revision 12a0edbb: Disable "Hardware Checksum Offloading" if VTNET is detected. Implements #10723
Viktor Gurov
05:38 AM Revision 3f6151d7: Use user DN for RFC2307 membership search (updated). Issue #9527
Viktor Gurov

09/24/2020

04:32 PM Revision f81845a6: Update bootstrap to v3.4.1
Steve Beaver
02:53 PM pfSense Docs Correction #10929: Feedback on Development — Developing Packages
Great, thanks Jim. Looking to possibly make a little plugin here and have been pretty lost on where to start. alzee bum
02:48 PM pfSense Docs Correction #10929 (Resolved): Feedback on Development — Developing Packages
Thanks for catching that! I have restored the information which should be on that page, and made some additional edit... Jim Pingle
09:52 AM pfSense Docs Correction #10929 (Resolved): Feedback on Development — Developing Packages
*Page:* https://docs.netgate.com/pfsense/en/latest/development/develop-packages.html
*Feedback:* This page just li...
alzee bum
02:42 PM pfSense Docs Correction #10707 (Resolved): Feedback on Backup and Restore — Automatically Restore a pfSense Configuration During Installation
Relevant changes, and more related changes on the page, are now complete.
https://docs.netgate.com/pfsense/en/late...
Jim Pingle
01:59 PM Feature #6960: Introduce Kea DHCP as an alternative DHCP server for IPv4 and IPv6
Not enough time for this big change before 2.5.0 is out Renato Botelho
01:44 PM Bug #9058: Kernel panic during L2TP retransmit
A possible solution proposed by markj@ - https://reviews.freebsd.org/D26548
If this revision is accepted I'll impo...
Renato Botelho
10:57 AM Bug #9058: Kernel panic during L2TP retransmit
Waiting for a fix on FreeBSD side. When it happens we can target a pfSense release to add it Renato Botelho
01:18 PM Todo #9052 (In Progress): Update Font-Awesome
Jared Dillard
01:13 PM pfSense Packages Bug #10930: Wrong blocklist from dshield.org
also, https://feeds.dshield.org/top10-2.txt is mentioned in the documentation, which is not a block list. Johannes Ullrich
01:12 PM pfSense Packages Bug #10930 (Resolved): Wrong blocklist from dshield.org
The current configuration uses the wrong blocklist from dshield.org (https://isc.sans.edu/api/sources/attacks/1000/30... Johannes Ullrich
08:57 AM Feature #9527 (Pull Request Review): Add ability for LDAP extended query on groups in RFC2307 containers.
Jim Pingle
08:57 AM Feature #9527: Add ability for LDAP extended query on groups in RFC2307 containers.
Jim Pingle wrote:
> I reverted commit:e924485c9e681771806fe3ee63ed746152fcbcb9 -- Previously working LDAP servers st...
Viktor Gurov
07:30 AM Bug #10928 (Duplicate): RADIUS Authentification parameters encoding/decoding dont work for french characters like : ç, é, à
Duplicate of #10352 Jim Pingle
03:55 AM Bug #10928 (Duplicate): RADIUS Authentification parameters encoding/decoding dont work for french characters like : ç, é, à
Hello !
I tried to setup L2TP/IPSEC VPN authenticated by RADIUS with AD. (Pfsense 2.4.3)
Everything works perfe...
Oscar Mrbt
07:19 AM Bug #6891 (Duplicate): Improper shutdown causes irrecoverable filesystem corruption, unable to boot or fsck
It's probably a duplicate of #6340. Lots of improvements were made in this area on FreeBSD itself and also on pfSense. Renato Botelho
03:27 AM pfSense Packages Bug #10927 (Resolved): pfBlockerNG-devel fullfill the pfsense config history when RAM disk in use
Hi !
I set pfBlockerNG-devel to update DNSBL hourly, and it works fine.
But this hourly update use to be logged i...
Laurent BONNIN
12:27 AM pfSense Packages Bug #10922: Gmail smtp relay TLS stopped working.
Anton Palmgard wrote:
> Hi to clarify we use, smtp-relay.gmail.com as this is used by gsuite.
/usr/local/etc/stun...
Viktor Gurov

09/23/2020

06:42 PM Revision 50299413: Update URLs to docs. Fixes #10481
Jim Pingle
06:18 PM Revision 9aa882cb: Update help.php URLs. Fixes #10481
Jim Pingle
04:37 PM pfSense Packages Bug #10922: Gmail smtp relay TLS stopped working.
Hi to clarify we use, smtp-relay.gmail.com as this is used by gsuite. Anton Palmgard
03:01 AM pfSense Packages Bug #10922 (Rejected): Gmail smtp relay TLS stopped working.
no such issue on pfSense 2.4.5-p1, pfSense-pkg-stunnel-5.50_4
/usr/local/etc/stunnel/stunnel.conf:...
Viktor Gurov
04:33 PM Revision 4a5942a4: Merge pull request #4457 from vktg/bridgecpvalidation
Renato Botelho
04:26 PM Revision 3f338fde: Bridge interface Captive Portal validation. Issue #6528
Viktor Gurov
03:46 PM pfSense Docs Correction #10924: Update information on distributed vswitch behavior in VMware vSphere / ESXi
Yeah, enabling this also removes the need for the Net.ReversePathFwdCheckPromisc setting listed on that page. It basi... Nathan M
03:26 PM pfSense Docs Correction #10924: Update information on distributed vswitch behavior in VMware vSphere / ESXi
Perhaps this instead or as well: https://docs.netgate.com/pfsense/en/latest/troubleshooting/high-availability-virtual... Jim Pingle
03:19 PM pfSense Docs Correction #10582 (Closed): Feedback on Services — DNS — Blocking DNS Queries to External Resolvers
I recently rewrote this page, it should be current/accurate now. Jim Pingle
03:17 PM pfSense Docs Correction #10512 (Closed): Feedback on Routing and Multi-WAN — Using Multiple IPv4 WAN Connections
The book and wiki content has been merged, and the book content is the only copy of this present now. So based on the... Jim Pingle
03:15 PM pfSense Docs Correction #10382 (Closed): Feedback on Hardware — Tuning and Troubleshooting Network Cards
The book and wiki content has been merged, so this is addressed.
https://docs.netgate.com/pfsense/en/latest/hardwa...
Jim Pingle
03:14 PM pfSense Docs Todo #10268 (Closed): Feedback on Services
It's already under Backup and Recovery where users are most likely to look for it. Since it isn't a service running l... Jim Pingle
03:07 PM pfSense Docs Correction #10173 (Closed): Feedback on Packages — Fixing a Broken pkg Database
I don't see any references to that path, only @/usr/local/sbin/pkg-static@ which does exist.
Jim Pingle
03:06 PM pfSense Docs New Content #10009 (Closed): Feedback on System Monitoring
Seems irrelevant after the docs merge.
https://docs.netgate.com/pfsense/en/latest/monitoring/status/carp.html
Jim Pingle
03:06 PM pfSense Docs New Content #10008 (Closed): Feedback on IPsec
Advanced IPsec settings are all covered at https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/advanced.html now Jim Pingle
03:05 PM pfSense Docs New Content #10007 (Closed): Feedback on Services — Dynamic DNS
The book and former wiki content are now merged so the info is together.
https://docs.netgate.com/pfsense/en/lates...
Jim Pingle
03:04 PM pfSense Docs Correction #10006 (Closed): Feedback on Backup and Recovery — Using the AutoConfigBackup Package
Gold and ACB package refs are all gone. Jim Pingle
03:02 PM pfSense Docs Correction #9925 (Closed): Feedback on VPN — OpenVPN — Troubleshooting Windows OpenVPN Client Connectivity
This page has since been rewritten and removed the problematic references.
https://docs.netgate.com/pfsense/en/lat...
Jim Pingle
02:53 PM pfSense Docs Correction #9672 (Closed): Feedback on Backup and Recovery — Using the AutoConfigBackup Package
References to Gold and ACB as a package were all removed during the docs merge. All refs for ACB should now indicate ... Jim Pingle
02:52 PM pfSense Docs Correction #9671 (Closed): Feedback on Hardware — Hardware Selection
I fixed this at some point...
The note at the end of https://docs.netgate.com/pfsense/en/latest/hardware/selection.h...
Jim Pingle
02:48 PM pfSense Docs Correction #9670 (Closed): Feedback on Backup and Recovery
References to Gold and ACB as a package were all removed during the docs merge. All refs for ACB should now indicate ... Jim Pingle
02:45 PM pfSense Docs Correction #9494 (Resolved): Feedback on VPN — IPsec — NAT with IPsec Phase 2 Networks
This page has since been rewritten and should be clear now. Jim Pingle
02:43 PM pfSense Docs Correction #9379: Feedback on Interfaces — Using a Large Number of Interfaces
Mostly addressed in the new docs, but we can add that suggested upper number as a guide. Jim Pingle
02:40 PM pfSense Docs Correction #9373: Feedback on Services — DNS — Configuring the DNS Resolver
The main Unbound docs need updated yet but there is also this: https://docs.netgate.com/pfsense/en/latest/recipes/dns... Jim Pingle
02:36 PM Revision 93fec82f: Merge pull request #4456 from vktg/nptoverlapvalidation
Renato Botelho
02:36 PM Revision fd8b556f: Merge pull request #4455 from vktg/pppoesrvinfcheck
Renato Botelho
02:36 PM Revision 2ec97b21: Merge pull request #4454 from vktg/pppoesecondradius
Renato Botelho
02:36 PM Revision f23f5274: Merge pull request #4452 from vktg/backupdhcpleases
Renato Botelho
02:36 PM Revision 415932cf: Merge pull request #4453 from vktg/pppoenorestart
Renato Botelho
02:25 PM pfSense Docs Correction #10901 (Resolved): Feedback on Virtualization — VirtIO Driver Support
Fixed manually in the new docs repo Jim Pingle
02:24 PM pfSense Docs Correction #10877 (Feedback): Feedback on VPN — IPsec — Configuring an IPsec Remote Access Mobile VPN using IKEv2 with EAP-MSCHAPv2
Fixed in the new docs repo. Jim Pingle
10:07 AM pfSense Docs Correction #10877 (New): Feedback on VPN — IPsec — Configuring an IPsec Remote Access Mobile VPN using IKEv2 with EAP-MSCHAPv2
Jim Pingle
01:44 PM Bug #10481 (Resolved): Update doc links in WebGUI to reflect proper docs URLs
Reusing this, see #10135, same intent.
Fixed in pfsense:commit:502994130948049349e6c52b651266d8d7bf3566
Jim Pingle
01:35 PM Todo #10135 (Feedback): help.php: Update links
Latest revision is in commit:9aa882cbb18d27d0b7a2a305dfb3164080e7a4d7
All are current, no more redirects. Any othe...
Jim Pingle
01:16 PM Todo #10135: help.php: Update links
The book and former wiki content have now been merged into a single set of documentation. I'm going to reuse this iss... Jim Pingle
12:45 PM Bug #9643: Limiters do not function properly on 2.5 snapshots
Abhinav Tella wrote:
> Here are the limiters and firewall floating rule I used. When the firewall rule is enabled, n...
Jesse Beauclaire
11:33 AM Bug #6528 (Feedback): The captive portal cannot be used on interface lan since it is part of a bridge but works anyway
PR has been merged. Thanks! Renato Botelho
08:58 AM Bug #6528 (Pull Request Review): The captive portal cannot be used on interface lan since it is part of a bridge but works anyway
Jim Pingle
03:27 AM Bug #6528: The captive portal cannot be used on interface lan since it is part of a bridge but works anyway
https://github.com/pfsense/pfsense/pull/4457 Viktor Gurov
10:47 AM pfSense Docs Correction #10648 (Closed): Feedback on IPsec — Mobile IPsec — Windows IKEv2 Client Configuration
The PR was merged months ago. If more is needed, should be in a new issue/new PR. Jim Pingle
10:42 AM pfSense Docs Correction #10686 (Duplicate): Feedback on Development — Obtaining Panic Information for Developers
Duplicate of #10180 Jim Pingle
10:31 AM pfSense Packages Feature #10897 (Feedback): SNMPV3-trap/inform Add Snmpv3 trap/inform Field
PR has been merged. Thanks! Renato Botelho
10:31 AM pfSense Docs Correction #9686 (Duplicate): Feedback on Firewall — Floating Rules
Duplicate of #9685 Jim Pingle
10:30 AM pfSense Packages Feature #10913 (Feedback): Allow disabling caching in Squid completly
PR has been merged. Thanks! Renato Botelho
08:54 AM pfSense Packages Feature #10913 (Pull Request Review): Allow disabling caching in Squid completly
Jim Pingle
01:14 AM pfSense Packages Feature #10913: Allow disabling caching in Squid completly
https://github.com/pfsense/FreeBSD-ports/pull/940 Viktor Gurov
10:30 AM pfSense Packages Bug #5168 (Feedback): squid doesn't function during/after HA failover
PR has been merged. Thanks! Renato Botelho
08:59 AM pfSense Packages Bug #5168 (Pull Request Review): squid doesn't function during/after HA failover
Jim Pingle
07:07 AM pfSense Packages Bug #5168: squid doesn't function during/after HA failover
Azamat Khakimyanov wrote:
> I tested it on 2.5-DEV (built on Wed Sep 16 01:00:40 EDT 2020): With new "CARP Status VI...
Viktor Gurov
10:20 AM pfSense Docs Correction #9228: Feedback on Hardware — Hardware Sizing Guidance
We can probably take out those tables with Netgate model info and link to the comparison charts on the store which ha... Jim Pingle
09:37 AM Feature #10318 (Feedback): Do not restart PPPoE server after adding/modifying users
PR has been merged. Thanks! Renato Botelho
09:36 AM Feature #10910 (Feedback): Backup/restore DHCP v4/v6 leases
PR has been merged. Thanks! Renato Botelho
09:36 AM Bug #10926 (Feedback): Secondary RADIUS Server is never used
PR has been merged. Thanks! Renato Botelho
09:36 AM Bug #4510 (Feedback): Crash & reboot loop when configure PPPoE server on PPPoE client interface
PR has been merged. Thanks! Renato Botelho
08:55 AM Bug #4510 (Pull Request Review): Crash & reboot loop when configure PPPoE server on PPPoE client interface
Jim Pingle
01:44 AM Bug #4510: Crash & reboot loop when configure PPPoE server on PPPoE client interface
https://github.com/pfsense/pfsense/pull/4455 Viktor Gurov
09:36 AM Feature #7741 (Feedback): warn me when shooting myself in the foot with NPt
PR has been merged. Thanks! Renato Botelho
08:57 AM Feature #7741 (Pull Request Review): warn me when shooting myself in the foot with NPt
Jim Pingle
02:13 AM Feature #7741: warn me when shooting myself in the foot with NPt
https://github.com/pfsense/pfsense/pull/4456 Viktor Gurov
07:12 AM Revision 0dc5aeaa: NPT prefix overlap validation. Issue #7741
Viktor Gurov
06:41 AM Revision 4f911030: PPPoE Server interface input validation. Issue #4510
Viktor Gurov
05:13 AM Revision 80fcbd31: PPPoE Server secondary RADIUS server fixes. Issue #10926
Viktor Gurov
03:21 AM Bug #10720 (Resolved): Setup Wizard DNS Server validation JavaScript incorrectly claims IPv6 address is invalid
Danilo Zrenjanin
03:21 AM Bug #10720: Setup Wizard DNS Server validation JavaScript incorrectly claims IPv6 address is invalid
Tested on :... Danilo Zrenjanin
02:55 AM Bug #10882 (Resolved): DHCPv6 Static Mappings requires applying changes on DNS resolver setup
Added the patch on the:... Danilo Zrenjanin
02:03 AM Feature #10856 (Resolved): Backup/Restore Captive Portal usedmacs DB
Danilo Zrenjanin
02:02 AM Feature #10856: Backup/Restore Captive Portal usedmacs DB
Tested on:... Danilo Zrenjanin
01:52 AM Feature #1683: PF scrub min-ttl option
see also #10493 Viktor Gurov

09/22/2020

06:14 PM Bug #10792 (Closed): Crash when switching interface off and on again in cohesion with multicast
Awesome! Thanks for reporting Renato Botelho
06:10 PM Feature #1337: VLANs with different MAC address than parent interface
Setting the interface in promiscuous mode is not the way to go and without it FreeBSD don't offer a way to make it to... Renato Botelho
06:07 PM Bug #6167: IPsec IPComp not working
When it's fixed on FreeBSD we can import the fix and target it to a version Renato Botelho
05:10 PM Revision 7fceb8e1: Clean backup cache before reading
Steve Beaver
03:23 PM Revision 1b75667c: Backup/restore DHCP v4/v6 leases. Implements #10910
Viktor Gurov
03:06 PM Todo #9356 (Closed): Find optimal default for net.pf.request_maxcount
This has been working fine.
Note that it changed from a loader tunable to a run-time sysctl in FreeBSD stable/12 f...
Jim Pingle
03:01 PM Feature #10387 (Feedback): Reevaluate the GUI upgrade language presented to the user
Message changed to "System is going to be upgraded. Rebooting in 10 seconds"
pfSense-upgrade 0.88 on 2.5.0 and 0....
Renato Botelho
02:56 PM Revision ffe95182: Fix #10925: Check if $rtable is empty
Renato Botelho
02:53 PM Revision f5d5a463: Do not restart PPPoE server after adding/modifying users. Implements #10318
Viktor Gurov
02:53 PM Feature #10388 (Rejected): Upgrade to Python 3.8
We will keep following the default version from FreeBSD ports tree, which now is 3.7 Renato Botelho
02:51 PM pfSense Packages Bug #10646 (Duplicate): Reinstall package process stalls at pfBlockerNG when restoring a config
Duplicate of #10610 Renato Botelho
02:49 PM Bug #10518 (Rejected): Netmap appears broken in Snort and Suricata packages when Inline IPS Mode enabled
It won't affect users upgrading from 2.4 to 2.5 so there is no action to be done. Thanks Renato Botelho
01:37 PM pfSense Docs Correction #10451 (Closed): Feedback on Releases — Versions of pfSense and FreeBSD
There is a difference in "Supported" as meant on that page and versions eligible for support from Netgate TAC. Both u... Jim Pingle
01:31 PM pfSense Docs New Content #8773 (Closed): Add VPN Throughput Tuning info
Jim Pingle
01:03 PM Bug #10926 (Pull Request Review): Secondary RADIUS Server is never used
Jim Pingle
12:02 PM Bug #10926: Secondary RADIUS Server is never used
https://github.com/pfsense/pfsense/pull/4454 Viktor Gurov
09:59 AM Bug #10926 (Resolved): Secondary RADIUS Server is never used
Secondary/Backup RADIUS server is never used,
There is no $pppoecfg['radius']['server2'] in the code,
Only primary ...
Viktor Gurov
10:32 AM Bug #7096: Unbound fails to start on boot if specific network devices are configured in the "Network Interfaces"
Back when I reported the problem its was IPoE DHCP for Wan IPv4 and Track Interface for LAN IPv6.
Now it is IPv4 P...
Chris Collins
04:16 AM Bug #7096: Unbound fails to start on boot if specific network devices are configured in the "Network Interfaces"
Chris Collins wrote:
> Just to add I Dont get this issue anymore, I think the problem may have been related to unbou...
Viktor Gurov
10:05 AM Bug #10925 (Feedback): PHP: Invalid argument supplied for foreach() in /etc/inc/util.inc on line 2640
Applied in changeset commit:ffe95182999a344dd926c5079a3f74ccc62e0f46. Renato Botelho
08:57 AM Bug #10925: PHP: Invalid argument supplied for foreach() in /etc/inc/util.inc on line 2640
That's line 2640 on factory and line 2624 on CE.
The foreach() here:...
Jim Pingle
01:41 AM Bug #10925 (Resolved): PHP: Invalid argument supplied for foreach() in /etc/inc/util.inc on line 2640
Invalid argument supplied for foreach() in /etc/inc/util.inc on line 2640 error at boot.
Has started happening ab...
Craig Weber
10:01 AM Feature #10318 (Pull Request Review): Do not restart PPPoE server after adding/modifying users
Jim Pingle
09:55 AM Feature #10318: Do not restart PPPoE server after adding/modifying users
https://github.com/pfsense/pfsense/pull/4453 Viktor Gurov
09:11 AM pfSense Packages Feature #10897 (Pull Request Review): SNMPV3-trap/inform Add Snmpv3 trap/inform Field
Jim Pingle
05:29 AM pfSense Packages Feature #10897: SNMPV3-trap/inform Add Snmpv3 trap/inform Field
https://github.com/pfsense/FreeBSD-ports/pull/939 Viktor Gurov
09:09 AM Feature #10910 (Pull Request Review): Backup/restore DHCP v4/v6 leases
Jim Pingle
03:48 AM Feature #10910: Backup/restore DHCP v4/v6 leases
https://github.com/pfsense/pfsense/pull/4452 Viktor Gurov
08:44 AM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
Steve Wheeler wrote:
> After upgrading to todays snap with this change I am seeing this error:
> [...]
>
> The c...
Ben Hughes
08:20 AM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
Steve Wheeler wrote:
> The console hung at 'Writing configuration...' at boot after the update requiring me to Ctl+C...
Jim Pingle
08:19 AM pfSense Packages Feature #10789: FRR integrated configuration and hitless reloads
After upgrading to todays snap with this change I am seeing this error:... Steve Wheeler
08:26 AM Bug #10155 (Resolved): sshguard is not compatible with RFC 5424 log format
This looks good now, thanks!... Jim Pingle
07:43 AM pfSense Packages Bug #10917 (Resolved): snort: invalid pidfile suffix error
Renato Botelho
01:43 AM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
I don't think NAT-T is the issue. All my firewalls have public IPs, and my tunnels don't have NAT-T (see status outpu... Brian Candler
01:17 AM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
Could another difference-maker be NAT-T? As reported above, i'm consistently seeing duplicates on a cluster i'm opera... Marc L

09/21/2020

09:13 PM pfSense Docs Correction #10924: Update information on distributed vswitch behavior in VMware vSphere / ESXi
This ticket is probably meant for this page instead - https://pfsense-docs.readthedocs.io/en/latest/highavailability/... Nathan M
08:07 PM pfSense Docs Correction #10924 (New): Update information on distributed vswitch behavior in VMware vSphere / ESXi
*Page:* https://docs.netgate.com/pfsense/en/latest/recipes/virtualize-esxi.html
*Feedback:*
Vmware has added su...
Nathan M
07:01 PM Revision c4251167: Fix ui/json replace error
Steve Beaver
06:46 PM Revision 82289330: Merge pull request #4176 from vktg/maxikev1exchanges
Renato Botelho
06:46 PM Revision 08ff1f65: Merge pull request #4436 from f-bor/ipsec_custom_port
Renato Botelho
03:26 PM Bug #10861 (Resolved): net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
I've upgraded a few systems and they all came through OK. Had the wrong value before upgrade and expected value after. Jim Pingle
03:25 PM pfSense Packages Bug #10917: snort: invalid pidfile suffix error
The pull requests against pfSense-2.4.5-RELEASE and pfSense-2.5-DEVELOPMENT have been merged. This issue can be marke... Bill Meeks
03:13 PM pfSense Packages Bug #10917 (Feedback): snort: invalid pidfile suffix error
PR has been merged. Thanks! Renato Botelho
03:11 PM pfSense Packages Bug #10917: snort: invalid pidfile suffix error
PRs:
* https://github.com/pfsense/FreeBSD-ports/pull/937
* https://github.com/pfsense/FreeBSD-ports/pull/938
Jim Pingle
03:10 PM pfSense Packages Bug #10917 (Pull Request Review): snort: invalid pidfile suffix error
Jim Pingle
03:09 PM pfSense Packages Bug #10917: snort: invalid pidfile suffix error
Two pull requests have been submitted against pfSense-2.4.5 and pfSense-2.5 to fix the issue reported in this ticket.... Bill Meeks
09:48 AM pfSense Packages Bug #10917: snort: invalid pidfile suffix error
This issue also impacts the Snort package on pfSense-2.5 under the same conditions when the physical interface name a... Bill Meeks
03:05 PM Feature #6324 (Closed): Improve IKEv2 multiple traffic selector per SA configuration GUI
There is no need for a separate option here. If you check Split Connections it does the right thing on 2.5.0.
It m...
Jim Pingle
02:30 PM Bug #10923 (Resolved): Update ixl Driver on pfSense 2.5.0 to bring back Intel X710-T2L/T4L support that was present on version 2.4.5-P1.
Intel X710 T-2L/T-4L devices were supported on pfSense 2.4.5-P1, however a regression from FreeBSD 12 onwards meant s... Abhinav Tella
02:21 PM Bug #8686: IPsec VTI: Assigned interface firewall rules are never parsed
I thought it was noted here but I don't see it. There is another FreeBSD issue at https://bugs.freebsd.org/bugzilla/s... Jim Pingle
01:58 PM Bug #9710 (Resolved): IPv6 RA: prefix option does not contain router address in spite of "R" flag being set
Jim Pingle
01:18 PM Bug #9710: IPv6 RA: prefix option does not contain router address in spite of "R" flag being set
Feedback:
Tested on:
2.5.0-DEVELOPMENT (amd64)
built on Mon Sep 21 07:00:38 EDT 2020
FreeBSD 12.2-PRERELEASE
R...
Rick Coats
01:47 PM Feature #10870 (Feedback): Allow custom IPSEC NAT-T port
PR has been merged. Thanks! Renato Botelho
01:47 PM Bug #9331 (Feedback): Parallel Rekey fails for multiple Child SAs
PR has been merged. Thanks! Renato Botelho
12:26 PM Revision 9372c82c: Adjust ETCDIR for frr7
Renato Botelho
12:16 PM Bug #10155 (Feedback): sshguard is not compatible with RFC 5424 log format
Renato Botelho
12:15 PM Bug #10155: sshguard is not compatible with RFC 5424 log format
sshguard 2.4.1 is now imported into pfSense 2.5.0 Renato Botelho
10:40 AM pfSense Packages Bug #10922 (Rejected): Gmail smtp relay TLS stopped working.
Hi, a few days ago up to a week my stunnel connection to smtp-gmail.gmail.com. stopped working with the error:
ep...
Anton Palmgard
09:54 AM Bug #7096: Unbound fails to start on boot if specific network devices are configured in the "Network Interfaces"
Just to add I Dont get this issue anymore, I think the problem may have been related to unbound starting "before" wan... Chris Collins
09:34 AM Todo #9417: Convert LDAP TLS setup from environment to LDAP_OPT_X_TLS_* set options
This is working better but today I'm seeing some inconsistencies in the behavior. I can flip back and forth between t... Jim Pingle
08:47 AM Bug #10921 (Not a Bug): Firewall rule removed and activated, but still active
https://docs.netgate.com/pfsense/en/latest/firewall/firewall-rule-troubleshooting.html#dangling-states Jim Pingle
08:31 AM Bug #10921 (Not a Bug): Firewall rule removed and activated, but still active
Hello everybody,
I'm currently testing pfsense in my laboratory. I couldn't ping the WAN interface, which is corre...
Jens Bauer
07:44 AM Bug #10560 (Duplicate): Connection fails connecting to (my) OpenVPN instance.
Jim Pingle
07:43 AM Bug #10560: Connection fails connecting to (my) OpenVPN instance.
We already have an issue for that particular problem: #4521 Jim Pingle
07:39 AM pfSense Packages Feature #10665 (Feedback): Manual OSPF neighbor definitions
I committed fixes which should fix this. Will be available shortly. Jim Pingle
07:21 AM pfSense Packages Feature #10665: Manual OSPF neighbor definitions
Looks like it's missing entries in pkg-plist and Makefile to install that file. Jim Pingle
07:00 AM pfSense Packages Feature #10665 (Assigned): Manual OSPF neighbor definitions
Tested on:
2.5.0-DEVELOPMENT (amd64)
built on Mon Sep 21 01:04:35 EDT 2020
FreeBSD 12.2-PRERELEASE
I didn't fin...
Azamat Khakimyanov
07:33 AM pfSense Packages Feature #10789 (Feedback): FRR integrated configuration and hitless reloads
PR has been merged only on 2.5.0 branch for now so we can get it properly tested Renato Botelho
06:54 AM Bug #10827 (Confirmed): Cannot add or delete separators when no rules are present
Marcos M
06:38 AM Feature #10743 (In Progress): Traffic shaper wizard: Add Google Stadia port range
Renato Botelho
06:38 AM Bug #10889: Hover text missing from Static Routes Page
Kris Phillips wrote:
> Renato Botelho wrote:
> > PR has been merged. Thanks!
>
> Hello Renato,
>
> Do you ha...
Renato Botelho
02:31 AM Bug #9024: Ping packet loss under load when using limiters
Problem also seems to be related to download limiter only, as traceroute is displayed correctly if fq-codel is applie... Thomas Pilgaard

09/20/2020

04:56 PM pfSense Docs Correction #10920 (Resolved): Feedback on Packages — Using the Package Manager
*Page:* https://docs.netgate.com/pfsense/en/latest/packages/manager.html
*Feedback:*
The information on this page...
Michael Sonstein
04:42 PM Bug #10560: Connection fails connecting to (my) OpenVPN instance.
TL;DR: It is a bug or feature of fcgicli in fact. It doesn't handle long strings being sent to the application. The "... Stefan Smietanowski
04:04 PM Bug #10892 (Resolved): Large number of VLAN/LANs make floating rules are to read
Tested in
2.5.0-DEVELOPMENT (amd64)
built on Sun Sep 20 06:59:15 EDT 2020
FreeBSD 12.2-PRERELEASE
and patch ...
Max Leighton
02:30 PM Bug #9383 (Resolved): dhcpleases kqueue error
Validated the behavior in 2.4.5_1
Tested again in
2.5.0-DEVELOPMENT (amd64)
built on Sun Sep 20 06:59:15 EDT 2...
Max Leighton
12:13 PM pfSense Packages Bug #10884 (Resolved): wrong link on haproxy-devel
Tested on
2.5.0-DEVELOPMENT (amd64)
built on Sun Sep 20 06:59:15 EDT 2020
FreeBSD 12.2-PRERELEASE
Related ...
Max Leighton
08:36 AM pfSense Packages Feature #10725 (Resolved): Squid disable multiple login sessions
Azamat Khakimyanov
08:35 AM pfSense Packages Feature #10725: Squid disable multiple login sessions
Tested on:
2.5.0-DEVELOPMENT (amd64)
built on Sun Sep 20 01:01:05 EDT 2020
FreeBSD 12.2-PRERELEASE
With default...
Azamat Khakimyanov
06:56 AM pfSense Packages Bug #8625 (Resolved): PFsense squidGuard faulty URL check
Tested on 2.4.4_p3, 2.4.4_p1 and 2.5-DEV (built on Sun Sep 20 01:01:05 EDT 2020):
- no issue if there is an url with...
Azamat Khakimyanov
05:26 AM Bug #10919 (Resolved): Improve handling of OpenVPN data cipher negotiation options
TL;DR: the cipher that is selected as --cipher in the openvpn config, should always be added to ncp-ciphers
In Ope...
Arne Schwabe
02:37 AM pfSense Packages Bug #7455: Unbound DNS Resolver failed with pfBlockerNG after reboot with /var mounted on ramfs
Similar issue over here, 2.4.5-RELEASE-p1 having LAN, VLAN and WAN1, WAN2 (LoadBalancing&Failover) and IPv4, IPv6 and... Marc Dorando
02:35 AM Bug #9567: Unbound DNS Resolver does not start up when using IPv6 DHHCPv6 WAN DHCPv6 LAN coupled with v6 Prefix Delegation
Similar issue over here, 2.4.5-RELEASE-p1 having LAN, VLAN and WAN1, WAN2 (LoadBalancing&Failover) and IPv4, IPv6 and... Marc Dorando
02:32 AM Bug #7096: Unbound fails to start on boot if specific network devices are configured in the "Network Interfaces"
Same issue over here, Unbound does not start after rebooting on 2.4.5-RELEASE-p1 having LAN, VLAN and WAN1, WAN2 (Loa... Marc Dorando
12:00 AM Feature #10918 (New): IP Aliases de-duplication
when i add an IP Aliases with duplicate or same IP-address, it will add those IPs without any warning about duplicate... Nima Mohammadi

09/19/2020

10:10 PM Feature #10743: Traffic shaper wizard: Add Google Stadia port range
Option for Stadia exists when running wizard but is not selectable on 2.5.0.a.20200919.1850 Jordan G
07:31 PM Bug #9024: Ping packet loss under load when using limiters
Well I turned off the Open VPN client and it worked. The traffic shaper is working normally. For some reason Open VPN... Joshua Babb
06:49 PM Bug #9024: Ping packet loss under load when using limiters
I as well can replicate this issue, I have outbound NAT setup and tried to setup a traffic limiter + fq_codel and see... Joshua Babb
02:04 PM Bug #10674: Port Forward Address Fields not becoming active in Safari
Unable to reproduce on Safari 13.1.2 with pfSense 2.5.0.a.20200910.1250 Michael Spears
01:41 PM pfSense Packages Bug #10602: Dashboard->Traffic Graphs bandwidth designations on hover pop-ups
Randall Barth wrote:
> The scales are reporting Mbytes/sec but the pop-up is using the Mbits/sec designation: Mb/s. ...
Kris Phillips
01:19 PM Bug #10889: Hover text missing from Static Routes Page
Renato Botelho wrote:
> PR has been merged. Thanks!
Hello Renato,
Do you have a System Patch for applying thi...
Kris Phillips
01:02 PM Bug #10827: Cannot add or delete separators when no rules are present
This item should be moved from Feedback to Confirmed, please. I also tested this and can confirm that it is present ... Kris Phillips
12:31 PM pfSense Packages Bug #10917: snort: invalid pidfile suffix error
According to the "pfsense forum":https://forum.netgate.com/topic/156861/upcoming-snort-package-updates-for-pfsense-2-... Anonymous
04:42 AM pfSense Packages Bug #10917 (Resolved): snort: invalid pidfile suffix error
After upgrading snort package from *@3.2.9.14_1@* to *@4.1.2@*, I have two interfaces where snort gives the following... Anonymous
06:52 AM Feature #9639 (Resolved): Cloudflare DDNS "API Token"
Tested on :... Danilo Zrenjanin
06:15 AM Revision 92ed9792: add custom ipsec ports
Frederic Bor

09/18/2020

07:06 PM Revision 5cbea686: Revert "Use user DN for RFC2307 membership search. Issue #9527"
This reverts commit e924485c9e681771806fe3ee63ed746152fcbcb9. Jim Pingle
06:55 PM Revision 39f48832: Use correct LDAP_OPT_X_TLS_* syntax. Fixes #9417
Also clean up the code a little, use the proper CA hash for filename. Jim Pingle
06:55 PM Revision b0c7d642: Revert "Revert LDAP_OPT_X_TLS changes since they do not work. Issue #9417"
This reverts commit 7729c5a163fb8acaca8d3f43b557176a9ed4a8db. Jim Pingle
06:32 PM Bug #10916 (Rejected): Cannot create bootle USB drive using ISO
We stopped using hybrid images on purpose. The memstick has a separate FAT partition to make it easier to load config... Jim Pingle
06:28 PM Bug #10916 (Rejected): Cannot create bootle USB drive using ISO
Using the latest daily snapshot (pfSense-CE-2.5.0-DEVELOPMENT-amd64-20200918-1020), writing the ISO to a USB drive us... Marcos M
05:42 PM Revision fd2533ab: Merge pull request #4451 from vktg/backupextradatacheckbox
Renato Botelho
05:28 PM Revision d56f80bb: Remove FRR multipath option
Jim Pingle
04:14 PM Revision 3d21e635: Merge pull request #4369 from vktg/hidemobpskfields
Renato Botelho
04:06 PM Revision 8f4b8ff2: Handle net.pf.request_maxcount via sysctl. Fixes #10861
Jim Pingle
03:15 PM Revision 35fa566c: Include extra data backup checkbox. Implements #10914
Viktor Gurov
02:59 PM Feature #7671: Gateway Monitoring Via Custom Script or Telnet.
Since the target version has been deleted, is there anyway to prove to the pfSense devs that this feature is importan... Web Dawg
02:55 PM Bug #10397 (Feedback): Changing default or static route gateway on 2.5.0 does not remove old route
It should be fixed on recent 2.5.0 snapshots Renato Botelho
02:54 PM pfSense Packages Todo #9158 (Feedback): Updates for Squid 4.x
AFAIK it's been working for some time now. Move to feedback! Renato Botelho
02:32 PM Revision ffcb0b7f: Add function to list recent backups as JSON array
Steve Beaver
02:08 PM Feature #9527 (New): Add ability for LDAP extended query on groups in RFC2307 containers.
I reverted commit:e924485c9e681771806fe3ee63ed746152fcbcb9 -- Previously working LDAP servers started to fail with no... Jim Pingle
02:05 PM Todo #9417 (Feedback): Convert LDAP TLS setup from environment to LDAP_OPT_X_TLS_* set options
Applied in changeset commit:39f48832cd45cc3a5f5f8d355bbd9253c7bcf7ae. Jim Pingle
01:55 PM Todo #9417: Convert LDAP TLS setup from environment to LDAP_OPT_X_TLS_* set options
And back on 2.5.0... Looks like there is some slightly different required syntax than I was using before. I can now u... Jim Pingle
01:43 PM Revision 40609fff: Remove commented out line
Renato Botelho
01:42 PM Revision fa343c99: Merge pull request #4400 from bonald/master
Renato Botelho
01:15 PM Bug #9643 (New): Limiters do not function properly on 2.5 snapshots
Renato Botelho
12:57 PM Bug #10861: net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
With the fix I checked in, the value is tied to the max table size, as it was before. The value is set at boot time, ... Jim Pingle
11:15 AM Bug #10861 (Feedback): net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
Applied in changeset commit:8f4b8ff22ed9cef5f1bbb8269bdc5bae8c29b959. Jim Pingle
10:48 AM Bug #10861 (In Progress): net.pf.request_maxcount value set in loader.conf not respected on latest snapshot
Jim Pingle
12:54 PM Feature #9716 (Resolved): Italian translation
Renato Botelho
12:54 PM Bug #10438 (Resolved): Prepare pfSense-upgrade to deal with pkg 1.13.x+
Renato Botelho
12:53 PM Bug #10331 (Resolved): French language give a Warning: sprintf(): in system_advanced_admin.php
Renato Botelho
12:53 PM Feature #9544 (New): Enable ``ROUTE_MPATH`` multipath routing
This was too unstable to keep for the time being. Retargeting to Future for now. Will revisit when stability issues i... Jim Pingle
12:52 PM Feature #9545 (New): Enable Multipath Routing in the Kernel
This requires RADIX_MPATH in the kernel which proved to be too unstable, thus had to be removed. See #9544.
We wil...
Jim Pingle
12:52 PM Revision 3ef8d632: Merge pull request #4439 from vktg/cpcpdbbackup
Renato Botelho
12:52 PM Todo #10659 (Resolved): PHP: Update to 7.4.x
PHP has moved to 7.4.x. If specific bugs are found new tickets must be opened. Renato Botelho
12:51 PM Todo #10353 (Resolved): Update pkg to 1.13.x
Renato Botelho
12:46 PM Bug #9872 (Resolved): Error during build when compiling a non pfSense software
Renato Botelho
12:45 PM Todo #9360 (Resolved): Switch to Python 3.x
1 year is enough time for testing :) Renato Botelho
12:44 PM Revision 1af1e47e: Backup Captive Portal DB files. Implements #10868
Viktor Gurov
12:44 PM Feature #10914 (Feedback): Skip extra data checkbox
PR has been merged. Thanks! Renato Botelho
12:10 PM Feature #10914 (Pull Request Review): Skip extra data checkbox
Jim Pingle
10:20 AM Feature #10914: Skip extra data checkbox
https://github.com/pfsense/pfsense/pull/4451 Viktor Gurov
08:59 AM Feature #10914: Skip extra data checkbox
I was just talking with Steve B earlier this week about the way these options are worded. They shouldn't be negative ... Jim Pingle
08:28 AM Feature #10914 (Resolved): Skip extra data checkbox
Add "Skip extra data" checkbox to allow skipping backup/restore:
- Captive Portal DB (#10868), Captive Portal UsedMA...
Viktor Gurov
12:28 PM Revision 022ef976: Only set headers if called from UI
Steve Beaver
12:02 PM Bug #10544 (New): It's not possible to add a user to group operator using the gui
Renato Botelho
11:50 AM Bug #10710 (Resolved): L2TP secret uses empty value
works as expected on 2.5.0.a.20200917.1311
now it doesn't leave empty 'set l2tp secret ""'
Viktor Gurov
11:33 AM pfSense Packages Feature #10915 (Pull Request Review): security/pfSense-pkg-sudo sudo.inc enhancement for better support of NRPE
Jim Pingle
10:19 AM pfSense Packages Feature #10915: security/pfSense-pkg-sudo sudo.inc enhancement for better support of NRPE
Pull request:
https://github.com/pfsense/FreeBSD-ports/pull/936
Infra Weavers
10:06 AM pfSense Packages Feature #10915 (Resolved): security/pfSense-pkg-sudo sudo.inc enhancement for better support of NRPE
We have a requirement to permit NRPE to run custom commands as root so that we can, for instance, monitor VPN connect... Infra Weavers
11:14 AM Bug #10532 (Feedback): Mobile PSK users don't have 'mobile-userpool' section
PR has been merged. Thanks! Renato Botelho
09:03 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
do i need to open another request for the pimd part? xavier Lemaire
09:01 AM pfSense Packages Feature #10909 (Pull Request Review): #define MAXVIFS 32 to 64
Jim Pingle
12:50 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
https://github.com/pfsense/FreeBSD-src/pull/37
see also https://www.freebsd.org/cgi/man.cgi?query=multicast&apro...
Viktor Gurov
08:44 AM Bug #10838 (Feedback): mask options didn't apply to the sched limiter
PR has been merged. Thanks! Renato Botelho
08:24 AM pfSense Packages Feature #10893 (Feedback): TFTP package improvements
PR has been merged. Thanks! Renato Botelho
08:24 AM pfSense Packages Bug #10884 (Feedback): wrong link on haproxy-devel
PR has been merged. Thanks! Renato Botelho
07:54 AM Feature #10868 (Feedback): Backup Captive Portal DB
PR has been merged. Thanks! Renato Botelho
07:48 AM Bug #10844 (Resolved): DHCPv6 service Dynamic DNS revisions made to fix Bug #10346 violates RFC/is too restrictive
Danilo Zrenjanin
07:47 AM Bug #10844: DHCPv6 service Dynamic DNS revisions made to fix Bug #10346 violates RFC/is too restrictive
Tested on :... Danilo Zrenjanin
07:12 AM Bug #10846 (Resolved): Icon area within buttons are not clickable
Tested on :... Danilo Zrenjanin
07:03 AM Feature #10837 (Resolved): Update wizardapp.inc XBox and Wii ports
Tested on :... Danilo Zrenjanin
06:09 AM Revision b862ffc5: Hide IPsec Pre-Shared Keys non-psk fields. Issue #10532
Viktor Gurov
04:53 AM pfSense Packages Feature #10913 (Resolved): Allow disabling caching in Squid completly
We use Squid as a proxy to audit access to websites (or reject as needed). We disabled the disk cache and set the mem... Florian Apolloner
04:07 AM Feature #10912: DNS Domain Overrides - more than one target IP
If there are multiple authoritative DNS servers available for a domain then make a separate entry for each, using the... Viktor Gurov
02:32 AM Feature #10912 (Resolved): DNS Domain Overrides - more than one target IP
Currently when pfSense is acting as a DNS server it can configure Domain Overrides. This is possible with dnsmasq and... Pim Pish

09/17/2020

09:20 PM Revision 8774f2c7: Add red border for disabled rules
Jared Dillard
06:18 PM Revision bfdc9966: Accept backup XML data as string or file
Steve Beaver
05:30 PM Revision c19c0944: Style changes
Renato Botelho
05:28 PM Revision 45ad8273: Style changes
Renato Botelho
05:28 PM Revision 123ec43c: $a_vtimaps is always an array
Renato Botelho
05:23 PM Revision 8cfc4ab9: Style changes
Renato Botelho
05:17 PM Revision bbaedc1b: Fix indent
Renato Botelho
05:15 PM Revision 2fef80c3: Change comment to match function
Renato Botelho
05:14 PM Revision 568ec5d9: Simplify logic
Renato Botelho
05:12 PM Revision 6c08d089: Remove unused variable
Renato Botelho
05:12 PM Revision 2548a32c: Initialize config item
Renato Botelho
05:11 PM Revision d0b8c0e9: Return 1 when config section is empty
Renato Botelho
05:10 PM Revision 2420538b: Break long line
Renato Botelho
05:09 PM Revision a51fbefa: Initialize config item and remove unneded var
Renato Botelho
04:55 PM Revision f75b5662: Initialize config item and remove unneded var
Renato Botelho
04:53 PM Revision d31d3e64: Merge pull request #4190 from vktg/remove00vti
Renato Botelho
02:11 PM Revision 9c6d6a06: Merge pull request #4427 from vktg/vtinodestroy
Renato Botelho
02:00 PM Revision 4740c4b1: Don't complain about SMTP port if service is disabled
Renato Botelho
01:56 PM Revision 2c133df1: Merge pull request #4447 from overtninja/master
Renato Botelho
01:32 PM Revision dac0e1f3: Merge pull request #4448 from vktg/dhcp6dnsprefix
Renato Botelho
01:31 PM Revision 50b721ac: Merge pull request #4444 from vktg/cpmacmask
Renato Botelho
01:30 PM Revision 2440f3bd: Merge pull request #4443 from vktg/unboundmultiip
Renato Botelho
01:29 PM Revision 2ff70d34: Merge pull request #4441 from vktg/floatrulesimp
Renato Botelho
01:29 PM Revision 688b4c29: Merge pull request #4440 from vktg/rmcpfiles
Renato Botelho
01:28 PM Revision babfff05: Merge pull request #4438 from vktg/staticroutestooltip
Renato Botelho
01:27 PM Revision 59e57ed3: Merge pull request #4257 from vktg/ovpnclientpass
Renato Botelho
01:26 PM Revision be1396d0: Merge pull request #4449 from vktg/dhcpv6rmrouterip
Renato Botelho
01:25 PM Revision db7f8fef: Merge pull request #4442 from vktg/dhcp6staticdns
Renato Botelho
01:24 PM Revision 0946ad1f: Merge pull request #4315 from vktg/localradiusauth
Renato Botelho
01:22 PM Revision 48d8bd79: Merge pull request #4450 from vktg/pppalias
Renato Botelho
12:31 PM Bug #9592 (Feedback): VTI interface down because interface number created is greater than ipsec32768
PR has been merged. Thanks! Renato Botelho
12:28 PM Revision 16091d6e: Fix backup of 'all' areas01~
Steve Beaver
12:22 PM Bug #10236: Cannot add more than 2 VMXNET3 Adapters in vSphere
I believe this to be a bug in the vSphere HOST Web GUI. I have run into very similar problems with other hardware co... Patrick Sanderson
11:27 AM Bug #7379 (Resolved): Virtual IPs/Proxy ARP: Not defined pid file on starting choparp.
works as expected on 2.5.0.a.20200916.1850
choparp is restarted on vip change
Viktor Gurov
11:10 AM pfSense Packages Bug #10911 (Resolved): Bandwidthd iframe not resizing in 2.4.5/2.4.5p1
Forum thread from several posters: https://forum.netgate.com/topic/152323/bandwidthd-in-pfsense-2-4-5
Looking at 2...
Steve Y
10:29 AM Feature #10392 (Resolved): GRE: Tunnels cannot have IPv6 and IPv4 addresses at the same time
tested on two 2.5.0.a.20200916.1850
works as expected:...
Viktor Gurov
10:19 AM Feature #10910 (Resolved): Backup/restore DHCP v4/v6 leases
Backup/restore dynamic DHCP leases files /var/dhcpd/var/db/dhcpd.leases and /var/dhcpd/var/db/dhcpd6.leases
in the...
Viktor Gurov
09:38 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
Moving the feature request since it's requesting a change to the kernel. Jim Pingle
08:55 AM pfSense Packages Feature #10909 (New): #define MAXVIFS 32 to 64
as discussed in this thread https://forum.netgate.com/topic/156398/deploy-disk-images-with-inter-vlans-mulicast/7
Is...
xavier Lemaire
09:12 AM Bug #10842 (Feedback): Not destroying VTI interfaces when booting before creating a new one
PR has been merged. Thanks! Renato Botelho
08:57 AM Feature #10495 (Feedback): Add support of Pushover API for notifications
PR has been merged. Thanks! Renato Botelho
08:34 AM pfSense Packages Feature #10908 (Feedback): FreeRADIUS server certificate not using full CA chain
https://forum.netgate.com/topic/153316/freeradius-acme-built-in-cert-manager-workarounds-with-intermediate-certificat... Viktor Gurov
08:33 AM Bug #7384 (Feedback): DHCPv6 doesn't merge IPv6 prefix with the input submitted in DNS servers field when using Track Interface IPv6 configuration parameter for the LAN interface.
PR has been merged. Thanks! Renato Botelho
08:32 AM Feature #2424 (Feedback): Allow masking of pass-thru MACs
PR has been merged. Thanks! Renato Botelho
08:31 AM Feature #10896 (Feedback): Multiple IPs for one DNS entry in unbound resolver override
PR has been merged. Thanks! Renato Botelho
08:30 AM Bug #10892 (Feedback): Large number of VLAN/LANs make floating rules are to read
PR has been merged. Thanks! Renato Botelho
08:29 AM Bug #10891 (Feedback): Captive Portal related files are not deleted after deleting CP zone in WebGUI
PR has been merged. Thanks! Renato Botelho
08:28 AM Bug #10889 (Feedback): Hover text missing from Static Routes Page
PR has been merged. Thanks! Renato Botelho
08:27 AM Bug #10409 (Feedback): OpenVPN client without userpass hangs system startup
PR has been merged. Thanks! Renato Botelho
08:26 AM Bug #9710 (Feedback): IPv6 RA: prefix option does not contain router address in spite of "R" flag being set
PR has been merged. Thanks! Renato Botelho
08:25 AM Bug #10882 (Feedback): DHCPv6 Static Mappings requires applying changes on DNS resolver setup
PR has been merged. Thanks! Renato Botelho
08:24 AM Feature #10545 (Feedback): RADIUS authenticated users should be able to log in via ssh
PR has been merged. Thanks! Renato Botelho
08:23 AM Bug #7132 (Feedback): PPPoE IP Alias
PR has been merged. Thanks! Renato Botelho
07:41 AM Bug #7132 (Pull Request Review): PPPoE IP Alias
Jim Pingle
03:00 AM Bug #7132: PPPoE IP Alias
https://github.com/pfsense/pfsense/pull/4450 Viktor Gurov
12:54 AM Bug #7132: PPPoE IP Alias
It's possible to use IP Alias on PPPoE interface by setting isp gw ip
https://forum.netgate.com/topic/147135/virtual...
Viktor Gurov
08:01 AM Bug #10906 (Resolved): can't download backup Crash report begins
This is already fixed in the repo. It was broken on the latest snapshot but works after a gitsync. Jim Pingle
05:29 AM Bug #10906: can't download backup Crash report begins
same problem with backup Area : RRD Data
empty config file and crash report
all other Area work ok
Manuel Piovan
05:08 AM Bug #10906 (Resolved): can't download backup Crash report begins
latest snpshot
only if I select backup area ALL
Crash report begins. Anonymous machine information:
amd64
1...
Manuel Piovan
07:57 AM Revision ec49a8af: Allow to use IP Alias on PPP interfaces. Issue #7132
Viktor Gurov
07:40 AM Feature #10904 (Pull Request Review): Support vti interfaces in dhcrelay
Jim Pingle
12:22 AM Feature #10904: Support vti interfaces in dhcrelay
PR for the binary part: https://github.com/pfsense/FreeBSD-ports/pull/935 Frederic Bor
12:19 AM Feature #10904 (Pull Request Review): Support vti interfaces in dhcrelay
One can want to relay dhcp requests using pfSense threw IPsec vti interfaces.
It's quite easy to support them, sin...
Frederic Bor
07:14 AM Bug #10850 (Duplicate): GoDaddy (v6) returns error when creating or updating
Jim Pingle
05:25 AM Bug #10850: GoDaddy (v6) returns error when creating or updating
Ok, looks like this can be closed then, since it's a duplicate. Sorry for that, didn't realize! Anonymous
05:22 AM Bug #10850: GoDaddy (v6) returns error when creating or updating
seems the same issue as #8432
dyndns client tries to use parent interface instead of gif/lagg etc.
Viktor Gurov
05:40 AM Bug #10836 (Resolved): TSO option does not fully toggle TSO on the interface
Tested on :... Danilo Zrenjanin
05:23 AM Bug #8432: Dynamic DNS Client gives an error that it can't find IPv6 address when WAN interface is a LAGG
seems the same issue as #10850 Viktor Gurov
03:07 AM pfSense Packages Bug #10905 (Resolved): Integration between captive portal and squid. Usernames are not showing in access.log file
https://forum.netgate.com/topic/147868/integration-between-captive-portal-and-squid-usernames-are-not-showing-in-acce... Viktor Gurov

09/16/2020

08:03 PM Revision c428cdf4: Rework route functions
- Created route_table() that returns an array containing all items from
route table. It uses --libxo to get a json...
Renato Botelho
05:33 PM Revision 530e157e: Support JSON format when retrieving XML to backup
Steve Beaver
10:31 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
I believe pf is only capable of symmetric NAT. I know pfSense pf is different from FreeBSD pf but I'm curious about t... Mike Smith
07:19 AM pfSense Packages Bug #5168 (Assigned): squid doesn't function during/after HA failover
I've tested it on 2.4.4_p3 - HA cluster with simple Squid config (Transparent mode) so Squid is active on both Primar... Azamat Khakimyanov
05:35 AM pfSense Packages Feature #10689 (Resolved): Squid Reverse proxy IPv6 and HA support
tested on:
2.5.0-DEVELOPMENT (amd64)
built on Wed Sep 16 01:00:40 EDT 2020
FreeBSD 12.2-PRERELEASE
Ticket reso...
Azamat Khakimyanov
03:27 AM Revision 187da3ef: Provide option for default notification tone to play, rather than being overridden.
overtninja
 

Also available in: Atom