Project

General

Profile

Activity

From 10/30/2020 to 11/28/2020

11/28/2020

10:04 PM Feature #11068: Safari 14.0.1 on MacOS 11.0.1 (Big Sur) asked for the favicon apple-touch-icon-precompressed.png instead of apple-touch-icon.png
Did not see any log errors when accessing SG-3100 on 2.5.0.a.20201127.0650 from MacOS 11.0.1 using Safari Jordan G
09:39 PM Feature #1984: Allow CP Voucher submission via URL so they can be distributed as QR code
url http://pfsenseip:8002/index.php?zone=zone_name&redirurl=redir_url&voucher=voucher_code
pfsenseip:192.168.1.11
...
Alhusein Zawi
09:57 AM Feature #1984: Allow CP Voucher submission via URL so they can be distributed as QR code
small fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/72
Viktor Gurov
06:28 PM pfSense Docs Correction #11114 (Duplicate): SG-2100 Missing from Hardware Sizing Guide
The SG-2100 is missing from our list here:
https://docs.netgate.com/pfsense/en/latest/hardware/size.html
Kris Phillips
03:40 PM pfSense Packages Bug #9866: freeradius_view_config.php: File contents are displayed without encoding
Tested in freeradius3 version 0.15.7_20. I see special characters are being converted as expected. This issue can be ... Max Leighton
01:11 PM Bug #7547: Static routes using aliases are not automatically updated when alias content changes
I can confirm this issue is present in 2.4.5p1. The alias needs to be edited and resaved for the changes to take eff... Kris Phillips
01:06 PM pfSense Packages Bug #8306 (Rejected): HAproxy in pfsense 2.42-p1 ha pair generates XMLRPC errors
Closing this ticket as rejected, since sync should not be enabled on the secondary unit for any HA configuration. Kris Phillips
01:04 PM Bug #8207: 2.4 cannot boot as a Xen VM with more than 7 NICs
Elias Seccom wrote:
> Same problem here with the newest Version (2.4.4-RELEASE-p3) of PFSense.
> Any ideas or solut...
Kris Phillips
10:33 AM Bug #10960 (Resolved): Bring up VXLANs correctly at boot
works as expected on 2.5.0.a.20201127.1850:... Viktor Gurov
10:18 AM Feature #8794 (New): NTP authentication support
after configuring ntpd authentication on Debian peer I can see packets with MAC:... Viktor Gurov
07:24 AM Bug #11100 (Resolved): dhcp6c never run rc.newwanipv6
works as expected on 2.5.0.a.20201127.1850 -
now it runs rc.newwanipv6 on receiving DHCPv6 REPLAY and I can see name...
Viktor Gurov
07:20 AM Bug #5135: DHCP interfaces are always treated as having a gateway, even if one is not assigned by the upstream DHCP server
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/71 Viktor Gurov
05:01 AM Bug #10366: Captive Portal Allowed MAC bandwidth Issue
unable to reproduce on 2.5.0.a.20201127.1850
related to #9311 ?
Viktor Gurov
02:57 AM Bug #3965: dhcp6c started before bridge configured at boot, preventing interface tracking
Kewin Christensen wrote:
> Updated to 2.5.0.a.20201127.0050 - still no dice :(
> Dunno if it makes a difference, bu...
Viktor Gurov

11/27/2020

05:56 PM Revision ef094bef: Ticket #9270: Make sure parameters are UTF-8
As described on ticket, for some reason we still don't know, when
pfSense_kill_states() is called with subnet as para...
Renato Botelho
03:51 PM Bug #11105: IPv6 RA RDNSS lifetime is too short, not compliant with RFC 8106
Just including my post from the thread for a bit of attional info.
The radvd.conf is getting generated without Adv...
Brandon Jackson
03:48 PM Bug #9270 (Feedback): "Remove all states to and from the filtered address" does not remove all states
Can you please give next round of snapshots a try and see if the workaround I committed help? Renato Botelho
01:25 PM Bug #11109: WebGUI RADIUS authentication doesn't work if WAN is down
I am able to reproduce this in
2.5.0-DEVELOPMENT (amd64)
built on Fri Nov 27 07:03:36 EST 2020
FreeBSD 12.2-STAB...
Max Leighton
12:29 AM Bug #11109: WebGUI RADIUS authentication doesn't work if WAN is down
Fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/68
Viktor Gurov
12:09 AM Bug #11109 (Resolved): WebGUI RADIUS authentication doesn't work if WAN is down
The GUI login screen works as intended, then if you use a local (not RADIUS) credential with no WAN IP configured it ... Viktor Gurov
11:31 AM Feature #8786: Wireguard VPN
Please don't lock this issue, it is very important feature to have for many people. Ter Ted
11:19 AM Feature #8698: LDAP authenticated users should be able to log in via ssh
Tested in
2.5.0-DEVELOPMENT (amd64)
built on Fri Nov 27 07:03:36 EST 2020
FreeBSD 12.2-STABLE
Appears to be w...
Max Leighton
09:17 AM pfSense Packages Feature #11113 (Resolved): New phishing feeds
https://phishing.army/
feed https://phishing.army/download/phishing_army_blocklist.txt
https://oisd.nl/
feed htt...
Viktor Gurov
08:41 AM Bug #11110: Backup file should be checked before restoring a specific area
Opened https://redmine.pfsense.org/issues/11112 for tracking the documentation changes. Danilo Zrenjanin
08:26 AM Bug #11110: Backup file should be checked before restoring a specific area
"keep switch configuration" checkbox is not detailed in docs
Viktor Gurov
06:34 AM Bug #11110: Backup file should be checked before restoring a specific area
Also, it would be helpful to note "This value must match the Backup area chosen when creating the backup." next to th... Danilo Zrenjanin
06:08 AM Bug #11110 (New): Backup file should be checked before restoring a specific area
There is no check which would prevent restoring a specific area from the full backup.
I have successfully restore...
Danilo Zrenjanin
08:39 AM pfSense Docs Correction #11112 (Resolved): "Preserve switch configuration" option is not documented
The checkbox *Preserve switch configuration* under Diagnostics > Backup & Restore is not explained here:
https://doc...
Danilo Zrenjanin
07:44 AM Bug #3965: dhcp6c started before bridge configured at boot, preventing interface tracking
Kewin Christensen wrote:
> Updated to 2.5.0.a.20201127.0050 - still no dice :(
as bridge track interface issue is...
Viktor Gurov
05:30 AM Bug #3965: dhcp6c started before bridge configured at boot, preventing interface tracking
Updated to 2.5.0.a.20201127.0050 - still no dice :(
*After update:*
Nov 27 11:59:15 router dhcp6c[28729]: failed ...
Kewin Christensen
04:15 AM Bug #3965: dhcp6c started before bridge configured at boot, preventing interface tracking
Kewin Christensen wrote:
> I'm afraid the issue wasn't fixed.
try to update to the latest snapshot,
works as ex...
Viktor Gurov
02:30 AM Bug #3965: dhcp6c started before bridge configured at boot, preventing interface tracking
I'm afraid the issue wasn't fixed.
Tested on 2.5.0.a.20201126.1250 (Hardware: APU2):
*Reboot:*
Nov 26 22:13:5...
Kewin Christensen
07:33 AM pfSense Packages Bug #11111 (Duplicate): Squidguard_configurator bug
duplicate of https://redmine.pfsense.org/issues/9364#note-4 Viktor Gurov
07:11 AM pfSense Packages Bug #11111 (Duplicate): Squidguard_configurator bug
On line 1293 of file squidguard_configurator.inc.
The result is force to : $rdr_path = "$guiproto://$guiip:$guipor...
Gael Richier
06:02 AM Feature #10811: Randomize time of scheduled AutoConfigBackup runs
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/69 Viktor Gurov
03:30 AM Bug #11078 (Resolved): IPsec PH2 incorrect proposals order
Tested on :... Danilo Zrenjanin
02:38 AM pfSense Packages Bug #11107: pfBlockerNG 3.0.0_1 doesn't have some feeds fixes
https://github.com/pfsense/FreeBSD-ports/pull/996 Viktor Gurov
01:59 AM pfSense Packages Bug #11108: pfsense 2.5.0-DEVELOPMENT (amd64) pfBlockerNG-devel 3.0.0_1
Fix:
https://github.com/pfsense/FreeBSD-ports/pull/995
Viktor Gurov

11/26/2020

11:42 PM pfSense Packages Bug #11108 (Resolved): pfsense 2.5.0-DEVELOPMENT (amd64) pfBlockerNG-devel 3.0.0_1
after install pfblockerng 3.0.0_1 on pfsense 2.5.0-dev
i got the following crash report
Crash report begins. Ano...
khaled osama
02:54 PM Bug #9270: "Remove all states to and from the filtered address" does not remove all states
Just complementing the experiments I did today:
adding utf8_encode() to pfSense_kill_states() parameter fix the is...
Renato Botelho
11:32 AM Bug #9270 (In Progress): "Remove all states to and from the filtered address" does not remove all states
Renato Botelho
11:32 AM Bug #9270: "Remove all states to and from the filtered address" does not remove all states
Jim Pingle wrote:
> There does seem to be an issue here, looks like it's in the pfSense module function @pfSense_kil...
Renato Botelho
02:49 PM Bug #3808 (Resolved): Disabled OpenVPN tunnel cause network port disappear after reboot
Tested on 2.4.5p1
This has been resolved. The ovpnsX network port stays assigned to the proper interface after a reb...
Marcos M
02:21 PM Feature #3356 (Resolved): Document functionality of unclear DynDNS providers
This has been resolved - current docs reflect the steps needed for he.net. Marcos M
08:47 AM pfSense Packages Bug #11107 (Resolved): pfBlockerNG 3.0.0_1 doesn't have some feeds fixes
some fixes from the previous PRs is not merged to 3.0.0_1:
#10933 - Lashback LB_BL - host not found
#10930 - correc...
Viktor Gurov
08:02 AM Revision 8d4adafb: Add AdvRASrcAddress to radvd.conf if linklocal vip is selected, refs: #11103
znerol
07:59 AM Bug #5999: IPv6 IP Alias prevents Track Interface from working with DHCPv6 and RA
Allen Balaj wrote:
> Thanks Viktor, I'll keep an eye on those feature requests. That said, I may have spoken too soo...
Viktor Gurov
04:12 AM pfSense Packages Bug #8827: Squidguard: ACL redirect modes 'redirect' and 'err page' send unresolvable URLs to the client.
You have to append... Viktor Gurov
04:09 AM pfSense Packages Bug #9364: squidguard int error page does not use https
regression fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/12
Viktor Gurov
02:25 AM Feature #11103: Use virtual link local IP address as RA source address for HA environments
Filed PR: https://github.com/pfsense/pfsense/pull/4487
Instructions for testing this feature:
* Setup HA cluste...
znerol znerol
02:01 AM Bug #11106: idn_to_ascii() with URL/URLTable aliases incorrect behavior
similar issue #10434
Fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/67
Viktor Gurov
01:56 AM Bug #11106 (Resolved): idn_to_ascii() with URL/URLTable aliases incorrect behavior
idn_to_ascii() incorrectly converts some URLs,
for example it returns empty for "https://endpoints.office.com/endpoi...
Viktor Gurov
12:43 AM Bug #11105: IPv6 RA RDNSS lifetime is too short, not compliant with RFC 8106
https://tools.ietf.org/html/rfc8106#section-5.1:... Viktor Gurov
12:11 AM Bug #11105 (Resolved): IPv6 RA RDNSS lifetime is too short, not compliant with RFC 8106
https://forum.netgate.com/topic/158615/pfsense-ipv6-ra-rdnss-lifetime-is-too-short-not-compliant-with-rfc8106:
Is th...
Viktor Gurov
12:05 AM pfSense Packages Feature #11102: Include a dictionary for mpd5 in Freeradius
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/11 Viktor Gurov

11/25/2020

11:11 PM pfSense Packages Bug #10608: Update squid port to 4.11-p2
the latest version of squid for FreeBSD 11 is 4.13:
https://www.freshports.org/www/squid/
Viktor Gurov
07:13 PM Revision 4cea5c50: Support %%PRODUCT_NAME%% on make.conf
Renato Botelho
01:45 PM Bug #11104: OpenVPN does not start with several authentication sources selected
There is no limit we are aware of specifically, the only way to find out would be to test it with one, two, three, et... Jim Pingle
01:21 PM Bug #11104 (Closed): OpenVPN does not start with several authentication sources selected
When I add several LDAP servers to an OpenVPN server it won't start anymore because the limit of more than 256 charac... Moritz Schwarz
12:52 PM Feature #11103 (Resolved): Use virtual link local IP address as RA source address for HA environments
If radvd is configured with _RA interface_ set to a virtual link local IP, then add it to @AdvRASrcAddress@ in @radvd... znerol znerol
12:49 PM Revision 6005c9f5: IPsec PH2 proposals order fix. Issue #11078
Viktor Gurov
12:48 PM Revision de2d64ab: Run dhcp6c enabled interfaces after track interfaces is UP. Fixes #3965
Viktor Gurov
12:31 PM Revision 06f386f6: Run rc.newwanipv6 on dhcp6c REQUEST reason. Issue #9634
Viktor Gurov
12:24 PM Bug #11087 (Resolved): Unbound fails to start if it binds to down/nocarrier interface
Replicated the issue on 2.4.5-p1.
Re-tested on:...
Danilo Zrenjanin
11:12 AM Revision 8ea7bf87: Respect %%PRODUCT_NAME%%
Renato Botelho
11:10 AM Feature #11081 (Closed): Wifi Open authentication support
This works fine currently using compatible harwdware:... Steve Wheeler
11:03 AM Revision 86afee72: Remove drm-kmod
Renato Botelho
10:46 AM pfSense Packages Feature #11102 (Resolved): Include a dictionary for mpd5 in Freeradius
In order to pass mpd specific attributes from Freeradius to, for example, provide rate limits to PPPoE clients a dict... Steve Wheeler
10:24 AM Feature #8946 (Duplicate): Add field to show IA_PD to DHCP6 Server page
Jim Pingle
06:12 AM Feature #8946: Add field to show IA_PD to DHCP6 Server page
added in https://redmine.pfsense.org/issues/5999#note-17 Viktor Gurov
08:59 AM Bug #5999: IPv6 IP Alias prevents Track Interface from working with DHCPv6 and RA
Thanks Viktor, I'll keep an eye on those feature requests. That said, I may have spoken too soon regarding this fix w... Allen Balaj
08:15 AM Bug #11082: XMLRPC synchronization restarts all OpenVPN instances on the secondary node when making any change on the primary node
We have a customer with a very complex HA setup, who has implemented the new xmlrpc.php file. It works stable and fix... Danilo Zrenjanin
07:56 AM pfSense Packages Bug #11098: Backup Files and Directories plugin crashes firewall if /root specified as backup location
I was not able to reproduce the issue either:... Marcos M
06:33 AM pfSense Packages Bug #11098: Backup Files and Directories plugin crashes firewall if /root specified as backup location
I can't replicate this by simply attempting to backup /root.
The backup file is not included in the .tgz.
Testi...
Steve Wheeler
12:41 AM pfSense Packages Bug #11098: Backup Files and Directories plugin crashes firewall if /root specified as backup location
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/10 Viktor Gurov
06:55 AM Bug #3965: dhcp6c started before bridge configured at boot, preventing interface tracking
Applied in changeset commit:de2d64abc0bad744ecb34cdd4bda890c60026dca. Viktor Gurov
06:48 AM Bug #3965 (Feedback): dhcp6c started before bridge configured at boot, preventing interface tracking
PR has been merged. Thanks! Renato Botelho
06:31 AM Bug #3965 (Pull Request Review): dhcp6c started before bridge configured at boot, preventing interface tracking
Renato Botelho
05:55 AM Bug #3965: dhcp6c started before bridge configured at boot, preventing interface tracking
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/65 Viktor Gurov
03:46 AM Bug #3965: dhcp6c started before bridge configured at boot, preventing interface tracking
Seems Vyatta also suffers from this bug: https://phabricator.vyos.net/T2741 Kewin Christensen
03:10 AM Bug #3965: dhcp6c started before bridge configured at boot, preventing interface tracking
For reference. I'm seeing the same issues without having a bridge - but just multiple tracked VLAN interfaces. It see... Kewin Christensen
06:49 AM Bug #11078 (Feedback): IPsec PH2 incorrect proposals order
PR has been merged. Thanks! Renato Botelho
06:39 AM pfSense Packages Bug #11101 (Resolved): Bind DNS Server won't start
If the "Enable Forwarding" checkbox is enabled, and a Forwarder IP is defined, and there is no semicolon at the end, ... Danilo Zrenjanin
06:35 AM Bug #11100 (Feedback): dhcp6c never run rc.newwanipv6
PR has been merged. Thanks! Renato Botelho
06:31 AM Bug #11100 (Pull Request Review): dhcp6c never run rc.newwanipv6
Renato Botelho
03:49 AM Bug #11100: dhcp6c never run rc.newwanipv6
Revert:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/64
Viktor Gurov
03:48 AM Bug #11100 (Resolved): dhcp6c never run rc.newwanipv6
See original issue #9634
Martin Wasley wrote:
> just to put you right on this Jim as there seems some confusion. ...
Viktor Gurov
06:29 AM Bug #6507 (Pull Request Review): GRE and GIF tunnels on dynamic IPv6 interface are not brought up during boot
Renato Botelho
12:35 AM Bug #6507: GRE and GIF tunnels on dynamic IPv6 interface are not brought up during boot
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/63
TODO:
correctly restart tunnels on track interface
Viktor Gurov
06:29 AM pfSense Packages Bug #11089 (Resolved): BIND service is started when disabled
Tested on:... Danilo Zrenjanin
12:35 AM Bug #8273 (Duplicate): IPv6 GRE tunnel over PPPoE fails on startup
Duplicate of #6507 Viktor Gurov
12:12 AM pfSense Packages Feature #11099 (New): DNSBL blocking by schedule
It would be nice to allow using DNSBL blocking by schedule to enable/disable it during school hours.
maybe improve p...
Viktor Gurov

11/24/2020

02:37 PM Bug #10690: Not possible to make UFS install on ZFS formatted drive
It's inconsistent, unfortunately. From a fresh 2.5.0 snapshot ISO I can install and reinstall any combination of UFS ... Jim Pingle
10:38 AM Bug #10690 (New): Not possible to make UFS install on ZFS formatted drive
I'm still hitting this on current snapshots. It gives an error similar to that in the description and even trying to ... Jim Pingle
02:37 PM Revision e65b646f: Do not bind unbound to disabled/nocarrier interfaces. Fixes #11087
Viktor Gurov
02:36 PM Revision cd60d729: Dynamic IPv6 DNS servers fix. Feature #10931
Viktor Gurov
02:36 PM Revision cf3096df: VXLAN restart on newwanip event. Bug #10960
Viktor Gurov
01:35 PM pfSense Packages Bug #11098 (Resolved): Backup Files and Directories plugin crashes firewall if /root specified as backup location
The Backup Files and Directories plugin crashes firewall if @/root@ specified as backup location. The plugin creates ... Privacy Please
12:04 PM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
I have the same thing happening; post upgrade to 2.4.5 p1
R side: Other side is a Cisco Meraki appliance in Azure
...
Gautam Parthasarathy
11:46 AM Bug #11097 (Duplicate): Child SAs incrementing constantly for multiple IPSec S2S tunnels
Duplicate of #10176 Jim Pingle
11:24 AM Bug #11097 (Duplicate): Child SAs incrementing constantly for multiple IPSec S2S tunnels
pfSense appliance in Azure recently updated to 2.4.5 from 2.4.4 p1
Multiple IPsec tunnels now showing Child SAs th...
Gautam Parthasarathy
10:41 AM pfSense Docs Correction #11096 (Closed): Feedback on pfSense Configuration Recipes — IPsec Site-to-Site VPN Example with Pre-Shared Keys
*Page:* https://docs.netgate.com/pfsense/en/latest/recipes/ipsec-s2s-psk.html
*Feedback:* (from twitter:) Your exa...
Jared Dillard
10:20 AM Bug #11095: pfSense will not reply to NS on WAN where src is set to a global IPv6 address
Thank you, my use case would be that; this is how my ISP's routers behave. I have send my ISP an email and I will wai... Conrad Andersen
09:32 AM Bug #11095: pfSense will not reply to NS on WAN where src is set to a global IPv6 address
I briefly searched and couldn't find anything that said it should work or that it was invalid, so it may vary by oper... Jim Pingle
09:27 AM Bug #11095: pfSense will not reply to NS on WAN where src is set to a global IPv6 address
> pfSense responds to NS from global to global in the same prefix and from link local to link local.
Is it specifi...
Conrad Andersen
09:19 AM Bug #11095 (Rejected): pfSense will not reply to NS on WAN where src is set to a global IPv6 address
That's up to the OS (FreeBSD) and not pfSense but I don't think your example is valid. You're sending a NS from globa... Jim Pingle
08:45 AM Bug #11087: Unbound fails to start if it binds to down/nocarrier interface
Applied in changeset commit:e65b646f30245863571f8b99e8b08c4d8a595e0d. Viktor Gurov
08:37 AM Bug #11087 (Feedback): Unbound fails to start if it binds to down/nocarrier interface
PR has been merged. Thanks! Renato Botelho
08:42 AM pfSense Packages Bug #9364 (Feedback): squidguard int error page does not use https
PR has been merged. Thanks! Renato Botelho
08:42 AM pfSense Packages Bug #11089 (Feedback): BIND service is started when disabled
PR has been merged. Thanks! Renato Botelho
08:37 AM Feature #10931 (Feedback): system.php: Add option to omit DNS Servers from resolv.conf
PR has been merged. Thanks! Renato Botelho
08:36 AM Bug #10960 (Feedback): Bring up VXLANs correctly at boot
PR has been merged. Thanks! Renato Botelho

11/23/2020

05:43 PM Revision 4cc4b278: Fix icon file name
Steve Beaver
05:39 PM Revision 6620d630: Revise apple touch icons
Steve Beaver
03:47 PM Bug #11095 (Rejected): pfSense will not reply to NS on WAN where src is set to a global IPv6 address
The category for this should probably be NDP, but that category is not available.
pfSense *will not* reply with an...
Conrad Andersen
02:52 PM Bug #10176: Multiple duplicate / overlapping phase 2 Child SAs on IPsec tunnels
Above changes made no difference, Phase2's to AWS just duplicated again, I currently have 187 duplicated Phase2's. Todd Blum
11:42 AM Feature #11068: Safari 14.0.1 on MacOS 11.0.1 (Big Sur) asked for the favicon apple-touch-icon-precompressed.png instead of apple-touch-icon.png
Icon set revised to include:... Anonymous
07:47 AM Bug #10960 (Pull Request Review): Bring up VXLANs correctly at boot
Jim Pingle
07:46 AM Feature #10931 (Pull Request Review): system.php: Add option to omit DNS Servers from resolv.conf
Jim Pingle
07:44 AM pfSense Packages Bug #9364 (Pull Request Review): squidguard int error page does not use https
Jim Pingle
07:42 AM Bug #11091 (Pull Request Review): Interfaces set as disabled in the configuration have an UP status in the operating system at boot
Jim Pingle
07:15 AM pfSense Packages Bug #11094 (Not a Bug): HAProxy Stick on SSL-Session-ID Doesn't Work
Diff'ing the generated HAProxy configuration before and after enabling SSL-Session-ID on a backend doesn't alter the ... Christian McDonald

11/22/2020

02:42 AM Bug #4287: Wrong display for ppp in Interfaces page
Hi Jim
i know it's a very old report, but i have the same bug.
The Connection is online an working but the stat...
Marco Mueller

11/21/2020

05:19 PM pfSense Packages Feature #10141 (Resolved): pfBlockerNG - MaxMind License Registration
License registration is required and the appropriate links and information for this are included in the user interfac... Jordan G
04:55 PM pfSense Packages Bug #9846 (Resolved): pfBlockerNG log file download/clear lacks validation
pfBlockerNG-devel 2.2.5_37 on pfSense 2.4.5p1 only allows elements to be selected in the drop down and I did not appe... Jordan G
02:54 PM Feature #7943: Overflow scrolling for top navigation drop-down menus in Fixed mode
Scrolling the entire page down slightly will allow access to these menu items in constrained situations. However, th... Kris Phillips
02:51 PM Bug #7996: Unnecessary link tag in login page
Can confirm that its there in 2.4.5p1. In theory it doesn't do anything, since there is no href or anything. May be... Kris Phillips
10:46 AM Bug #10960: Bring up VXLANs correctly at boot
VXLAN restart on newwanip event fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/62
Viktor Gurov
10:45 AM Bug #11093 (New): ral(4) driver non-functional in arm64
Devices using the ral(4) driver do not function in arm64 images.
The driver attaches correctly and the interface u...
Steve Wheeler
10:39 AM Feature #10931: system.php: Add option to omit DNS Servers from resolv.conf
Dynamic IPv6 DNS servers fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/61
Viktor Gurov
06:43 AM Bug #11061 (Resolved): CARP rules show up as "part" of the snort package in rules.debug
Tested on:... Danilo Zrenjanin
05:34 AM Bug #11064 (Resolved): WARNING: write_config() was called without description
tested on:... Danilo Zrenjanin
04:53 AM pfSense Packages Feature #11092 (New): Detecting DNS tunneling
Using pfBlockerNG python integration it's possible to create DNS tunneling detector using regexp,
see https://www.gi...
Viktor Gurov
02:30 AM pfSense Packages Bug #9364: squidguard int error page does not use https
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/9 Viktor Gurov
01:07 AM Bug #11034 (Resolved): poesX interfaces is not created
Viktor Gurov
01:07 AM Feature #6908: Alias copy, sort, search/replace functions
jake xanaro wrote:
> I am soooooo very excited to get this feature! Way to go, I am looking forward to 2.5 that much...
Viktor Gurov
01:04 AM Bug #11090: OpenVPN assigned interfaces inconstant status
maybe related to #11091 Viktor Gurov
01:03 AM Bug #11091: Interfaces set as disabled in the configuration have an UP status in the operating system at boot
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/60 Viktor Gurov
12:05 AM Bug #11091 (Rejected): Interfaces set as disabled in the configuration have an UP status in the operating system at boot
If you disable interface on interfaces.php page it's disabled
there is no UP in ifconfig output and `get_interface_...
Viktor Gurov

11/20/2020

08:51 PM Feature #11068: Safari 14.0.1 on MacOS 11.0.1 (Big Sur) asked for the favicon apple-touch-icon-precompressed.png instead of apple-touch-icon.png
I see this also, but I see other apple icons also missing:
Nov 19 15:25:04 XX.YY.XX.ZZ nginx 2020/11/19 15:25:04 [...
Rick Coats
06:50 PM Bug #11034: poesX interfaces is not created

PPPoE Server creates interfaces "poesX"
poes1-1: flags=88d1<UP,POINTOPOINT,RUNNING,NOARP,SIMPLEX,MULTICAST> metr...
Alhusein Zawi
06:14 PM Feature #6908: Alias copy, sort, search/replace functions
I am soooooo very excited to get this feature! Way to go, I am looking forward to 2.5 that much more now!
if its g...
jake xanaro
06:12 PM Feature #6908: Alias copy, sort, search/replace functions
Hollander Hollander wrote:
> For example: copy one alias (the content of course) into another alias (like in FW rule...
jake xanaro
06:14 PM Bug #1353 (Resolved): Number of queues possible
Tested in:
2.5.0-DEVELOPMENT (amd64)
built on Fri Nov 20 13:05:16 EST 2020
FreeBSD 12.2-STABLE
Working as e...
Max Leighton
02:43 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
To be fair, it does at least hint to the fact on the setting description where it says:
"The domain in System > Gene...
Marcos M
01:46 PM Bug #8355: Upgrades and packages unavailable after upgrade from 2.3.3_1 to 2.3.4_1
Same here, no 3rd party plugins, just openvpn client builder.
After upgrade to 2.3.4-RELEASE-p1 (amd64) from 2.3.3 ...
David Tr
11:26 AM Bug #11090 (Needs Patch): OpenVPN assigned interfaces inconstant status
If this is causing no functional problems I see no reason for us to take any action on it. Certainly not a 2.5.0 bloc... Jim Pingle
11:24 AM Bug #11090 (Needs Patch): OpenVPN assigned interfaces inconstant status
If there are multiple OpenVPN instances in HA setup, and ovpnsX interfaces are assigned to each instance, their statu... Danilo Zrenjanin
10:55 AM pfSense Docs New Content #11071: Add documentation for missing configuration items on IPv6 Router Advertisements
Suggestion would be:
Minimum & Maximum RA interval
The router sends router advertisements on each interface confi...
Marcos M
10:40 AM pfSense Packages Bug #11089 (Pull Request Review): BIND service is started when disabled
Jim Pingle
09:55 AM pfSense Packages Bug #11089: BIND service is started when disabled
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/8 Viktor Gurov
09:53 AM pfSense Packages Bug #11089 (Resolved): BIND service is started when disabled
https://forum.netgate.com/topic/103370/named-bind-service-is-started-when-disabled:
If I configure the bind DNS serv...
Viktor Gurov
10:38 AM Bug #11087 (Pull Request Review): Unbound fails to start if it binds to down/nocarrier interface
Jim Pingle
06:48 AM Bug #11087: Unbound fails to start if it binds to down/nocarrier interface
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/59 Viktor Gurov
06:34 AM Bug #11087 (Resolved): Unbound fails to start if it binds to down/nocarrier interface
How to reproduce:
1) Select OPT1 for example, in "Network Interfaces" list;
2) Disable OPT1 interface;
3) Reboot f...
Viktor Gurov
09:16 AM pfSense Packages Feature #11088: populate ifAlias snmp attribute
great ! can surely wait until 2.5.0 ! Julien ROLAND
08:56 AM pfSense Packages Feature #11088: populate ifAlias snmp attribute
Actually I take that back, we added the GUI interface descriptions to the OS interfaces in #1557 which lets them show... Jim Pingle
08:49 AM pfSense Packages Feature #11088 (Needs Patch): populate ifAlias snmp attribute
Wouldn't be possible with the built-in SNMP (bsnmpd). Doubtful it can be done with NET-SNMP directly either, but perh... Jim Pingle
08:46 AM pfSense Packages Feature #11088 (Needs Patch): populate ifAlias snmp attribute
When responding to snmp queries, populate IF-MIB::ifAlias.n snmp attribute with gui configurated interface descriptio... Julien ROLAND
07:51 AM pfSense Docs Correction #11086 (Rejected): Feedback on pfSense Configuration Recipes — Configuring DNS over TLS
You must have some other problem in your setup. I have a test system setup with the exact config from the document an... Jim Pingle
01:45 AM Bug #11077 (Resolved): Kernel panic when deleting VLAN interfaces
resolved on 2.5.0.a.20201119.1850
I can remove vlan interfaces from WebGUI or command line without any issues
Viktor Gurov

11/19/2020

11:29 PM Bug #11077: Kernel panic when deleting VLAN interfaces
Update to the latest kernal fixed the issue on my sytem that was crashing when attempting to delete a vlan yesterday. andreas vesalius
12:55 PM Bug #11077 (Feedback): Kernel panic when deleting VLAN interfaces
A fix was committed to address this issue, please test with the next snapshot. Luiz Souza
09:51 AM Bug #11077 (New): Kernel panic when deleting VLAN interfaces
Anonymous
12:55 AM Bug #11077: Kernel panic when deleting VLAN interfaces
I can reproduce this issue from the command line:... Viktor Gurov
05:50 PM Feature #11079 (Resolved): Include the updated Realtek driver pkg in the pfSense repo
Looks good:... Steve Wheeler
05:42 PM Feature #11079: Include the updated Realtek driver pkg in the pfSense repo
pks is added .
[2.5.0-DEVELOPMENT][admin@pfSense.home.arpa]/root: pkg search realtek
realtek-re-kmod-v196.04_2 ...
Alhusein Zawi
10:03 AM Feature #11079 (Feedback): Include the updated Realtek driver pkg in the pfSense repo
Sorry, overlapped. Back to feedback.... Steve Wheeler
10:02 AM Feature #11079 (New): Include the updated Realtek driver pkg in the pfSense repo
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/57 Steve Wheeler
10:01 AM Feature #11079 (Feedback): Include the updated Realtek driver pkg in the pfSense repo
PR has been merged. Thanks! Renato Botelho
05:04 PM pfSense Docs Correction #11086 (Rejected): Feedback on pfSense Configuration Recipes — Configuring DNS over TLS
*Page:* https://docs.netgate.com/pfsense/en/latest/recipes/dns-over-tls.html
*Feedback:*
The recipe says
"The h...
Tim Richardson
03:57 PM Revision fd3f6f9f: Build updated Realtel driver for testing.
Exclude from ARM, it's x86 only. Steve Wheeler
03:38 PM Revision 230b6fe5: Remove net/pimd, it's already built as a dependency
Renato Botelho
03:32 PM pfSense Docs New Content #11010 (Resolved): Feedback on Hardware — Hardware Tuning and Troubleshooting
Added: https://docs.netgate.com/pfsense/en/latest/hardware/tune.html#vmware-vmx-4-interfaces Jim Pingle
02:25 PM Feature #4881 (Pull Request Review): Allow NPt to use dynamic IPv6 networks
Renato Botelho
01:59 PM pfSense Docs Correction #11085: Feedback on System Monitoring — CARP Status
That was just my best guess, but I didn't know the difference between disabling vs maintenance mode, or temporary (un... David Burgess
01:47 PM pfSense Docs Correction #11085: Feedback on System Monitoring — CARP Status
While it could use some more information, your description is not accurate. It still participates in CARP but it is d... Jim Pingle
01:35 PM pfSense Docs Correction #11085 (Closed): Feedback on System Monitoring — CARP Status
*Page:* https://docs.netgate.com/pfsense/en/latest/monitoring/status/carp.html
*Feedback:*
The section "Mainten...
David Burgess
01:26 PM Feature #11084 (New): Dynamic DNS include option to specify virtual IP addresses
When using dynamic DNS in failover situations need to be able to include virtual IP addresses vs Interface address on... Shane Poteet
08:06 AM Bug #11082 (Pull Request Review): XMLRPC synchronization restarts all OpenVPN instances on the secondary node when making any change on the primary node
Probably too late to work this in to 2.5.0 given the potential impact. Jim Pingle
04:57 AM Bug #11082: XMLRPC synchronization restarts all OpenVPN instances on the secondary node when making any change on the primary node
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/55 Viktor Gurov
03:51 AM Bug #11082 (Closed): XMLRPC synchronization restarts all OpenVPN instances on the secondary node when making any change on the primary node
Maybe there is no need for restarting OpenVPN instances on the secondary if there weren't any changes related to VIP ... Danilo Zrenjanin
08:01 AM Feature #11083 (Rejected): DHCPv6 server configuration sync
I don't think we should encourage this. It will lead to conflicting servers. ISC-DHCP doesn't support IPv6 failover, ... Jim Pingle
06:27 AM Feature #11083: DHCPv6 server configuration sync
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/56 Viktor Gurov
06:24 AM Feature #11083 (Rejected): DHCPv6 server configuration sync
Allow DHCPv6 server configuration to sync
and disable it on the secondary because isc-dhcp doesn't support failover ...
Viktor Gurov
02:36 AM Feature #11081 (Closed): Wifi Open authentication support
It's no possible to connect to Open wifi networks, only WPA/WPA2 auth,
or create Open AP (for using with captive por...
Viktor Gurov
02:07 AM Feature #3229 (Resolved): make DynDNS status accessible to the colorblind
It looks excellent now. Thank you. Ticket resolved. Danilo Zrenjanin

11/18/2020

11:05 PM Bug #10407 (Resolved): L2TP static route not re-added after connection down/up
Alhusein Zawi
10:47 PM Bug #10407: L2TP static route not re-added after connection down/up
route is not deleted if reconnecting.
Static route will be deleted if L2TP interface is down.
Static route wil...
Alhusein Zawi
07:44 PM Revision a88079e0: Update/sync DynDNS/RFC2136 status note. Fixes #3229
Jim Pingle
05:40 PM pfSense Packages Feature #11080 (Needs Patch): Original SpeedTest Ookla for FeeBSD
It's not in FreeBSD ports, it would need to be added there first. Jim Pingle
05:17 PM pfSense Packages Feature #11080 (Needs Patch): Original SpeedTest Ookla for FeeBSD
is possible add this packet?
pkg update && pkg install -g libidn2 ca_root_nss
pkg add "https://bintray.com/ookla/...
Niccolò Marchi
01:46 PM Feature #3229: make DynDNS status accessible to the colorblind
I updated the note, and also copied it over to the RFC 2136 page since it applies there as well. Jim Pingle
05:31 AM Feature #3229: make DynDNS status accessible to the colorblind
Tested the patch on 2.4.5-p1.
The status column appears and works correctly.
However, I believe the comment nee...
Danilo Zrenjanin
01:42 PM Feature #11079 (Resolved): Include the updated Realtek driver pkg in the pfSense repo
There is now a FreeBSD package for the 'official' Realtek driver, currently v1.96.04.
https://www.freshports.org/n...
Steve Wheeler
01:23 PM pfSense Docs Correction #8854: [feedback form] Define Broadcast Domain and switch loops
Comments are addressed, should be OK now. Jim Pingle
12:52 PM Revision 4faf9170: Hide poesX-Y from interface list. Issue #11034
Viktor Gurov
12:19 PM Feature #8786: Wireguard VPN
Aaron Shaffer wrote:
> PLEASE add WireGuard support! Thank you.
Stefan Meili wrote:
> For what it's worth please...
Jonathon Reinhart
11:36 AM Feature #8786: Wireguard VPN
For what it's worth please consider this my up-vote for this feature. Stefan Meili
11:32 AM pfSense Packages Todo #11033 (Feedback): Update OpenVPN Client Export with OpenVPN 2.5.0 installer
Found a couple more edge cases that needed addressing:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/commit/9...
Jim Pingle
11:31 AM Feature #4881: Allow NPt to use dynamic IPv6 networks
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/54 Viktor Gurov
09:58 AM Bug #11078 (Pull Request Review): IPsec PH2 incorrect proposals order
Jim Pingle
08:56 AM Bug #11078: IPsec PH2 incorrect proposals order
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/53 Viktor Gurov
05:49 AM Bug #11078 (Resolved): IPsec PH2 incorrect proposals order
If you choose both AES and AES-GCM ciphers, it sets the AES-CBC cipher to the first place of esp_proposals:... Viktor Gurov
08:51 AM Bug #11077: Kernel panic when deleting VLAN interfaces
I can easily reproduce the issue on :... Danilo Zrenjanin
02:04 AM Bug #11077 (Confirmed): Kernel panic when deleting VLAN interfaces
I see the same on the latest snapshot, also on interface IP/MTU change (interface_configure() issue?)
tried to rever...
Viktor Gurov
12:25 AM Bug #11077: Kernel panic when deleting VLAN interfaces
Also happening on my system with 2.5.0-DEVELOPMENT (amd64) built on Tue Nov 17 19:01:05 EST 2020. Deleting a vlan or ... andreas vesalius
08:37 AM Bug #11072 (Resolved): Setting "Inverse" to "Off" does not save in the Traffic Graphs Dashboard widget
Tested in
2.5.0-DEVELOPMENT (amd64)
built on Wed Nov 18 01:03:07 EST 2020
FreeBSD 12.2-STABLE
Seems to be wor...
Max Leighton
06:52 AM Bug #11072 (Feedback): Setting "Inverse" to "Off" does not save in the Traffic Graphs Dashboard widget
Renato Botelho
06:52 AM Bug #11072: Setting "Inverse" to "Off" does not save in the Traffic Graphs Dashboard widget
PR has been merged. Thanks! Renato Botelho
12:20 AM Bug #11072: Setting "Inverse" to "Off" does not save in the Traffic Graphs Dashboard widget
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/51 Viktor Gurov
07:38 AM pfSense Packages Bug #7267: Status Traffic Totals - Stacked Bar - Scale not high enough
This functionality is provided by a library that would need to be updated, but which appears to be no longer maintained. Anonymous
06:52 AM Bug #11034: poesX interfaces is not created
PR has been merged. Thanks! Renato Botelho
02:25 AM Bug #11034: poesX interfaces is not created
also hide 'poesX-Y' from interface list:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/52
Viktor Gurov
06:06 AM pfSense Packages Bug #11069 (Resolved): Reset Traffic Totals Not Working
Danilo Zrenjanin
06:05 AM pfSense Packages Bug #11069: Reset Traffic Totals Not Working
Tested on:... Danilo Zrenjanin
06:04 AM Revision aa71463f: Traffic Graphs widget options fix. Issue #11072
Viktor Gurov

11/17/2020

11:27 PM pfSense Packages Bug #8068 (Resolved): Status Traffic Totals package installation is not recorded in config.xml
it was fixed in #7153
I can see Status_Traffic_Totals under '<installedpackages>':...
Viktor Gurov
11:05 PM Bug #10713 (Duplicate): assigning a virtual IPv6 IP to an interface that has IPv6 PD track interface enabled makes the Virtual IP the primary IP after reboot
Viktor Gurov wrote:
> https://forum.netgate.com/topic/154856/multiple-ipv6-bugs-quirks-in-pfsense:
> Situation: you...
Viktor Gurov
11:02 PM Bug #5999: IPv6 IP Alias prevents Track Interface from working with DHCPv6 and RA
Allen Balaj wrote:
> I can confirm that this seems to resolve the original problem that I was experiencing. Really a...
Viktor Gurov
07:24 PM Bug #3965: dhcp6c started before bridge configured at boot, preventing interface tracking
It seems this is the same issue as https://github.com/opnsense/core/issues/3199
and patch https://github.com/Konte...
Manu Bretelle
06:12 PM Bug #11021 (Resolved): ral(4) driver kernel panics in arm64
The kernel panic here is resolved.
We can open a new bug report if this affects more than just my card.
Steve Wheeler
04:29 PM Bug #11077 (Resolved): Kernel panic when deleting VLAN interfaces
... Niccolò Marchi
04:13 PM Revision 5341fe71: Ticket #6028: Fix path to rules.debug.old
Renato Botelho
04:08 PM Revision 70f5cde9: Ticket #6028: Persist last valid set of rules
Save the last version of a valid set of rules under /cf/conf to make it
to persist on reboot. This allow it to be lo...
Renato Botelho
03:42 PM pfSense Packages Todo #11033: Update OpenVPN Client Export with OpenVPN 2.5.0 installer
Found some cipher list issues, all fixed now: https://github.com/pfsense/FreeBSD-ports/commit/eafeafea69ff0aae39757f4... Jim Pingle
03:21 PM pfSense Docs Correction #8854: [feedback form] Define Broadcast Domain and switch loops
I left a couple comments on the commit in GitLab. Jared Dillard
02:58 PM pfSense Docs Correction #8854 (Resolved): [feedback form] Define Broadcast Domain and switch loops
I rewrote the page and added links to pages with more information (rather than repeating it all there).
https://gi...
Jim Pingle
03:14 PM Revision d16ea02a: Add note about not using bogons on LANs. Issue #10866
Jim Pingle
02:14 PM Bug #11076: delete vlan crash system
Crash report begins. Anonymous machine information:
amd64
12.2-STABLE
FreeBSD 12.2-STABLE f47399e21af(devel-12)...
Niccolò Marchi
02:10 PM Bug #11076 (Rejected): delete vlan crash system
This site is not for support or diagnostic discussion. You have not provided nearly enough information to constitute ... Jim Pingle
02:08 PM Bug #11076 (Rejected): delete vlan crash system
delete vlan crash system Niccolò Marchi
12:40 PM pfSense Docs Correction #11075 (Resolved): Feedback on Packages — ACME package — Obtaining a Certificate
Fixed in the repo, will show up on the site shortly.
Thanks!
Jim Pingle
11:01 AM pfSense Docs Correction #11075 (Resolved): Feedback on Packages — ACME package — Obtaining a Certificate
*Page:* https://docs.netgate.com/pfsense/en/latest/packages/acme/certificate.html
*Feedback:*
This line is inco...
Robert Hirabayashi
10:28 AM pfSense Docs Todo #10866 (Resolved): "block bogon networks" silently blocks IPv6 client solicitations to DHCPv6 Server RA "managed" or "assisted"
https://gitlab.netgate.com/docs/pfSense-book/-/commit/06a28558a249d163f99617ab2f0bae7b0e815e28
* Added warning aga...
Jim Pingle
10:10 AM Bug #6028 (Feedback): no firewall rules loaded after reboot with invalid ruleset
Renato Botelho
08:43 AM pfSense Packages Feature #9563 (Resolved): Syslog-ng TLS support
Tested on 2.5.0-DEVELOPMENT (amd64)
built on Tue Nov 17 01:02:10 EST 2020
FreeBSD 12.2-STABLE
I've run Syslog-ng...
Azamat Khakimyanov
07:24 AM Bug #5476: Does not appear possible to use policy routing for traffic originating from the firewall (self)
Will this be fixed someday ? is it planned to be fixed ? Michael F
05:02 AM Bug #11053 (Resolved): PHP error on services_dhcp_relay.php
Renato Botelho
04:41 AM Bug #6880: Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
We too see this issue. Two upstream DHCP6 lines. The confusing thing is, this works *somehow*, but with intermittent ... Tobias Meyer

11/16/2020

08:27 PM Bug #6880: Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
Just ran into this and #4881 now that our backup ISP also has native v6. Looks like I'll have to work around it by ha... Caleb Carges
08:17 PM Feature #4881: Allow NPt to use dynamic IPv6 networks
Well it took until late 2020 but I finally have two local ISPs providing native /56 IPv6 routes over DHCPv6. It would... Caleb Carges
07:30 PM Revision f32d36c1: Add symlink to accommodate apple-touch-icon-precompressed.png
Steve Beaver
04:18 PM Bug #11053: PHP error on services_dhcp_relay.php
It's ok now thanks Niccolò Marchi
03:52 PM pfSense Docs Correction #11065 (Resolved): Outdated logo in diagrams
Last one: https://gitlab.netgate.com/docs/pfSense-book/-/commit/5f53ea7bc400bd5ad210bdaab5bea66710dde248 Jim Pingle
03:45 PM pfSense Docs Correction #11065: Outdated logo in diagrams
Replaced one of the others:
https://gitlab.netgate.com/docs/pfSense-book/-/commit/bf917211723d0f04167244cf0cf0fd38...
Jim Pingle
01:58 PM pfSense Docs Correction #11065 (In Progress): Outdated logo in diagrams
Replaced the diagram in OpenVPN:
https://gitlab.netgate.com/docs/pfSense-book/-/commit/a9106b92fe579a9d8fea8a62414...
Jim Pingle
01:51 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
Wouldn't it be a good idea to just add a note somewhere near the option itself, that it doesn't work and probably wil... xander bron
01:08 PM Bug #1819 (New): DNS Resolver Not Registering DHCP Server Specified Domain Name
Anonymous
01:31 PM Feature #11068 (Feedback): Safari 14.0.1 on MacOS 11.0.1 (Big Sur) asked for the favicon apple-touch-icon-precompressed.png instead of apple-touch-icon.png
Added symlink apple-touch-icon-precompressed.png -> apple-touch-icon.png Anonymous
01:13 PM Bug #9136 (New): IPv6 Tracking Interfaces Lose IPv6 Address in Certain Cases
Anonymous
12:11 PM Revision 50b84727: Create poesX interfaces for PPPoE server. Issue #11034
Viktor Gurov
12:10 PM Revision 9447acda: DynDNS status icons. Implements #3229
Viktor Gurov
12:09 PM Revision 3501e0c4: No-IP DynDNS provider API update. Implements #6638
Viktor Gurov
11:48 AM pfSense Packages Bug #11069 (Feedback): Reset Traffic Totals Not Working
Thanks! This looks good and was merged. Should be able to test the change in the next build. Jared Dillard
07:21 AM pfSense Packages Bug #11069 (Pull Request Review): Reset Traffic Totals Not Working
Jim Pingle
10:33 AM pfSense Packages Bug #11074 (Confirmed): bind Zone Settings Zones, Save button opens "Confirmation required to save changes"
possible bug (or annoyance :) ) in bind package?
When I try to hit the Save button in the Package Bind: Zone Setti...
Christian Fertig
07:53 AM pfSense Packages Feature #10242: E2guardian Web filtering package
Viktor is the person who was working on this package Renato Botelho
07:38 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
Louis van Breda wrote:
> OK, I understand. I will rebuild for 32 MAXVIFS. 32 VIFS are plenty for me, but others woul...
Renato Botelho
07:12 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
OK, I understand. I will rebuild for 32 MAXVIFS. 32 VIFS are plenty for me, but others would perhaps like to have mor... Louis B
06:08 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
Louis van Breda wrote:
> I fixed the problem. It was not in the OS. I did compile the PIMD-package in the wrong way ...
Renato Botelho
07:36 AM Bug #11073 (Duplicate): Traffic monitor widget error
Duplicate of #11072 Jim Pingle
07:35 AM Bug #11072 (Confirmed): Setting "Inverse" to "Off" does not save in the Traffic Graphs Dashboard widget
Jim Pingle
07:27 AM pfSense Packages Todo #11033 (Resolved): Update OpenVPN Client Export with OpenVPN 2.5.0 installer
Basic functions work, if anyone has new issues they find, let's move them to the forum and then we can open new issue... Jim Pingle
07:24 AM Todo #11020: Update OpenVPN to 2.5.0
Not nearly enough information, either. Post on the forum to discuss the problem and provide a lot more information ab... Jim Pingle
07:24 AM Feature #11070 (Rejected): Design and Simplicity Changes to High Availability
I don't see most of these as being feasible. Some are more error prone than the current design, others would be quite... Jim Pingle
07:19 AM Bug #11066 (Duplicate): Dashboard: Unit on Traffic Widget not consistent
Duplicate of #10602 Jim Pingle
07:17 AM pfSense Docs Correction #11067: Update status of 802.11ac support
The feedback you submitted was for a documentation update, but the text you entered sounded like a feature request. W... Jim Pingle
06:20 AM Feature #3229: make DynDNS status accessible to the colorblind
Applied in changeset commit:9447acda18c5aaca7699cd66f7aa387cc9ef82b0. Viktor Gurov
06:12 AM Feature #3229 (Feedback): make DynDNS status accessible to the colorblind
PR has been merged. Thanks! Renato Botelho
06:15 AM Todo #6638: Update no-ip DDNS to new API
Applied in changeset commit:3501e0c453b7b1498e1d7faaba324bf01be084c6. Viktor Gurov
06:09 AM Todo #6638 (Feedback): Update no-ip DDNS to new API
PR has been merged. Thanks! Renato Botelho
06:12 AM Bug #11034 (Feedback): poesX interfaces is not created
PR has been merged. Thanks! Renato Botelho
05:09 AM Bug #11006 (Resolved): L2TP Server and Client both use "l2tpX" for interface names
Renato Botelho
02:45 AM Bug #9796: kernel panic after removing interfaces
hello.
I had the same problem on the 11/11/2020 build. i made a video and here are the dumps if you want to watch ...
Anonymous

11/15/2020

08:25 PM Bug #5999: IPv6 IP Alias prevents Track Interface from working with DHCPv6 and RA
I can confirm that this seems to resolve the original problem that I was experiencing. Really appreciate the fix guys... Allen Balaj
05:07 PM Bug #6880: Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
I'm running into the same issue Randy Cross
10:33 AM Bug #8325: UPnP not available for pppoe-Clients
Thanks for taking up this topic again.
My description was not precise enough, as I learn from your answer. I will tr...
Thomas Levi
09:45 AM Bug #11073 (Duplicate): Traffic monitor widget error
On dashboard in traffic monitor widget isn't possible to save inverse "off"
Niccolò Marchi
08:06 AM pfSense Packages Feature #10356 (Resolved): Support for additional Notification Support
Tested on 2.5.0-DEVELOPMENT (amd64)
built on Sun Nov 15 01:02:10 EST 2020
FreeBSD 12.2-STABLE
Telegram notificat...
Azamat Khakimyanov
06:38 AM pfSense Packages Feature #10785 (Resolved): Allow Setting of ldapcachetime
Tested on 2.4.5_p1 and on 2.5.0-DEVELOPMENT (built on Sun Nov 15 01:02:10 EST 2020)
LDAP Cache Time option is now ...
Azamat Khakimyanov
05:04 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
I fixed the problem. It was not in the OS. I did compile the PIMD-package in the wrong way in relation MAXVIFS64. So ... Louis B
02:16 AM Bug #11072: Setting "Inverse" to "Off" does not save in the Traffic Graphs Dashboard widget
Version Is 2.5 Niccolò Marchi
02:15 AM Bug #11072 (Resolved): Setting "Inverse" to "Off" does not save in the Traffic Graphs Dashboard widget
On dashboard in traffic monitor widget isn't possible to save inverse "off" Niccolò Marchi

11/14/2020

07:24 PM pfSense Packages Todo #11033: Update OpenVPN Client Export with OpenVPN 2.5.0 installer
Tested version 1.5_1 on 2.4.5-p1 64-bit installer worked and installed config properly but did present warning during... Jordan G
04:30 PM pfSense Docs New Content #11071 (Resolved): Add documentation for missing configuration items on IPv6 Router Advertisements
*Page:* https://docs.netgate.com/pfsense/en/latest/services/dhcp/ipv6-ra.html
*Feedback:*
Include description f...
Marcos M
03:32 PM Todo #11020: Update OpenVPN to 2.5.0
Niccolò Marchi wrote:
> cipher in ovpn file is always empty
This is likely a misconfiguraiton and not a bug. If t...
Marcos M
05:08 AM Todo #11020: Update OpenVPN to 2.5.0
cipher in ovpn file is always empty Niccolò Marchi
12:02 PM Feature #11070 (Rejected): Design and Simplicity Changes to High Availability
Currently there are several "pitfalls" to setting up an HA pair with pfSense that may benefit from some design change... Kris Phillips
11:22 AM Bug #10812 (Resolved): Traffic graph shows 2X the actual traffic on VLAN interfaces.
Tested on :... Danilo Zrenjanin
10:49 AM pfSense Packages Bug #11069: Reset Traffic Totals Not Working
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/7 Viktor Gurov
10:06 AM pfSense Packages Bug #11069 (Resolved): Reset Traffic Totals Not Working
https://forum.netgate.com/topic/152088/reset-traffic-totals-not-working:
I wanted to reset the data showing in the S...
Viktor Gurov
09:03 AM Feature #11068 (Resolved): Safari 14.0.1 on MacOS 11.0.1 (Big Sur) asked for the favicon apple-touch-icon-precompressed.png instead of apple-touch-icon.png
Safari 14.0.1 on MacOS 11.0.1 (Big Sur) asked for the favicon apple-touch-icon-precompressed.png instead of apple-tou... John Jacobs
07:04 AM pfSense Docs Correction #11067 (New): Update status of 802.11ac support
*Page:* https://docs.netgate.com/pfsense/en/latest/wireless/hardware.html
*Feedback:*
FreeBSD 12.2 does support...
Jurgen Debo
06:36 AM Bug #11066 (Duplicate): Dashboard: Unit on Traffic Widget not consistent
On the pfSense Dashboard the "Traffic Graphs" widget can be set to show "Unit Size" in "Bits" or "Bytes". Positioning... Adrian Zaugg
05:41 AM pfSense Packages Bug #10936: both haproxy/haproxy-devel non-existent option lb-agent-chk
Tested:
haproxy-devel 0.61_2 - "Agent" doesn't appear under Health check method. It's fixed.

HA-Proxy 0.60_...
Danilo Zrenjanin
05:02 AM Feature #10483 (Duplicate): Add UI for EAP configuration for WLAN interfaces
Duplicate of #2400 Viktor Gurov
04:56 AM Bug #11051 (Resolved): Unbound: custom TLS listen port ignored
Tested on:... Danilo Zrenjanin
03:46 AM Todo #6638: Update no-ip DDNS to new API
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/50 Viktor Gurov
03:34 AM Feature #3229: make DynDNS status accessible to the colorblind
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/49 Viktor Gurov
03:34 AM Bug #10270 (Resolved): OMAPI / disableauthoritative / alwaysbroadcast not saved inside dhcpd.conf
Tested on:... Danilo Zrenjanin
02:42 AM Bug #11034: poesX interfaces is not created
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/48 Viktor Gurov
02:29 AM Feature #11057 (Resolved): Add default route indicator to Gateways widget
Viktor Gurov

11/13/2020

10:04 PM Feature #11045 (Resolved): Improve link state visibility on Status > Interfaces
Alhusein Zawi
07:53 PM Feature #11045: Improve link state visibility on Status > Interfaces
applied and showing up as expected Alhusein Zawi
08:20 AM Feature #11045: Improve link state visibility on Status > Interfaces
Applied in changeset commit:f35f9392543100e2b488f1942bfde608047cb4ee. Viktor Gurov
08:12 AM Feature #11045 (Feedback): Improve link state visibility on Status > Interfaces
Status interfaces icon. Implements #11045 Renato Botelho
08:00 AM Feature #11045 (Pull Request Review): Improve link state visibility on Status > Interfaces
Jim Pingle
04:25 AM Feature #11045: Improve link state visibility on Status > Interfaces
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/47 Viktor Gurov
07:32 PM Bug #8325: UPnP not available for pppoe-Clients
I'm unable to reproduce this issue. Steps followed:
1. Create PPPoE interface under Interfaces --> Assignments --...
Kris Phillips
07:25 PM Bug #9626: When deny write permission is assigned to a user, there is no error feedback if the user tries to write something
Can confirm this is definitely what occurs. However, there is a logged event in the System Logs about a write deny, ... Kris Phillips
07:15 PM pfSense Packages Bug #9849 (Rejected): NUT not starting as root? Isn't loading USB drivers?
Marking bug report as rejected, since it is unable to be confirmed as an issue. Kris Phillips
05:48 PM Feature #11057: Add default route indicator to Gateways widget
working and showing up
2.5.0.a.20201113.1250
thanks
Alhusein Zawi
04:15 PM Feature #11057: Add default route indicator to Gateways widget
It was merged after that snapshot. Try one from later today/tomorrow Jim Pingle
03:41 PM Feature #11057: Add default route indicator to Gateways widget

Default route icon is not showing up on Gateway dashboard widget.
2.5.0.a.20201113.0650
Alhusein Zawi
08:20 AM Feature #11057: Add default route indicator to Gateways widget
Applied in changeset commit:0630b8315c4eebd304f1557e50de11a1ab21b409. Viktor Gurov
08:12 AM Feature #11057 (Feedback): Add default route indicator to Gateways widget
PR has been merged. Thanks! Renato Botelho
07:59 AM Feature #11057 (Pull Request Review): Add default route indicator to Gateways widget
Jim Pingle
03:21 AM Feature #11057: Add default route indicator to Gateways widget
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/46 Viktor Gurov
02:38 PM pfSense Docs Correction #9370: Update old screenshots
Some more (may overlap the above):... Jim Pingle
02:37 PM pfSense Docs Correction #11065 (Resolved): Outdated logo in diagrams
Similar to #10782, I found a few more instances of diagrams using the old logo:
https://docs.netgate.com/pfsense/e...
Jim Pingle
02:21 PM Feature #11058: In dashboard log widget an option to automatically resolve source or destination names depending whether names exist in private address space would be extremely useful
It would be confusing and of minimal use since the log scrolls dynamically, there is no telling if the resolve would ... Jim Pingle
01:34 PM Feature #11058: In dashboard log widget an option to automatically resolve source or destination names depending whether names exist in private address space would be extremely useful
Hi Jim,
Would a button that does a one shot resolve on the widget be an option?
Thanks,
Andy
And Ritchie
02:12 PM Revision f35f9392: Status interfaces icon. Implements #11045
Viktor Gurov
02:12 PM Revision 0630b831: Gateways widget improvements. Implements #11057
Viktor Gurov
02:11 PM Revision b3cc5117: Backup extra data fixes. Issue #11050
Viktor Gurov
11:01 AM Bug #6321: Problem with connecting l2tp over ipsec from android and windows
Windows settings:
https://docs.microsoft.com/en-us/troubleshoot/windows-server/networking/configure-l2tp-ipsec-serve...
Viktor Gurov
10:58 AM Bug #11006: L2TP Server and Client both use "l2tpX" for interface names
Works fine !
Thanks a lot !!!
Best of the best !!!
Evgeny Korostelev
10:20 AM pfSense Docs Correction #9520 (Closed): Feedback on Routing and Multi-WAN — Gateway Settings
This looks good for the current version. Jared Dillard
10:13 AM pfSense Docs Correction #10643 (Closed): Feedback on Routing and Multi-WAN — Gateway Settings
This looks good. Jared Dillard
10:11 AM pfSense Docs Correction #9570 (Closed): Feedback on Routing and Multi-WAN — Gateway Settings
This looks good. Jared Dillard
09:46 AM Bug #11059 (Resolved): L2TP Server is restarted when administering users
Renato Botelho
09:30 AM Bug #11059: L2TP Server is restarted when administering users
Thanks a lot !!! Evgeny Korostelev
09:27 AM Feature #4278 (Resolved): Mail notification change name of the interface info more readable - pfsense 2.2
Current message includes friendly interface name for years
HA cluster member "(172.16.185.250@em0): (WAN)" has res...
Renato Botelho
09:14 AM Bug #11064 (Feedback): WARNING: write_config() was called without description
Fixed. Renato Botelho
09:02 AM Bug #11064 (In Progress): WARNING: write_config() was called without description
I've changed it on ports but didn't bump PORTREVISION so new packages were not built. I'll take care of that Renato Botelho
08:35 AM Bug #11064 (Resolved): WARNING: write_config() was called without description
found some files with 'write_config()' without description:... Viktor Gurov
08:38 AM Bug #4740: Intel wireless kernel panic in infrastructure mode with WPA
Considering all big FreeBSD changes since 2.2.x I must ask. Is it still happening on current versions? Renato Botelho
08:34 AM pfSense Packages Feature #4335 (Resolved): NUT send notifications via built in smtp notification feature
NUT sends SMTP notification using pfSense main notification settings since 2016 Renato Botelho
08:32 AM Todo #2942 (Rejected): PHP-Growl: Growl Talk Notifications UDP 9887 implementation deprecated. GNTP is the new standard notification protocol.
Growl support was removed on pfSense 2.5.0 Renato Botelho
08:26 AM Bug #11050 (Feedback): "Backup extra data" does not behave properly
PR has been merged. Thanks! Renato Botelho
08:20 AM Bug #11050: "Backup extra data" does not behave properly
Viktor Gurov wrote:
> https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/45
Merged. Thanks!
Renato Botelho
08:11 AM Bug #11050: "Backup extra data" does not behave properly
bsdinstall fix:
https://gitlab.netgate.com/pfSense/FreeBSD-src/-/merge_requests/1
Viktor Gurov

11/12/2020

11:39 PM Feature #11041 (Resolved): Add hardware interface name to popup hint in Interfaces Dashboard widget
Alhusein Zawi
11:37 PM Feature #11041: Add hardware interface name to popup hint in Interfaces Dashboard widget
applied
when I put the mouse on interface block in dashboard it popups interface name (emx).
example:
LAN > e...
Alhusein Zawi
07:25 AM Feature #11041: Add hardware interface name to popup hint in Interfaces Dashboard widget
Applied in changeset commit:c073d66224cc6ea122cec2a6067b038ed2593043. Viktor Gurov
07:16 AM Feature #11041 (Feedback): Add hardware interface name to popup hint in Interfaces Dashboard widget
PR has been merged. Thanks! Renato Botelho
06:44 PM Bug #11021: ral(4) driver kernel panics in arm64
Testing:... Steve Wheeler
11:40 AM Bug #11021 (Feedback): ral(4) driver kernel panics in arm64
A new fix was committed by bz@ and imported to our tree. Next round of snapshots will have it Renato Botelho
04:59 PM Revision e9119e9a: Catch up with the pfSense-module-0.69 which renamed the interface create function.
Luiz Souza
04:45 PM pfSense Docs Correction #10782 (Closed): Outdated pfSense logo is still in use
This looks good. I added the source locations in this commit: https://gitlab.netgate.com/docs/pfSense-book/-/commit/2... Jared Dillard
03:44 PM pfSense Docs Correction #10782 (Feedback): Outdated pfSense logo is still in use
Addressed in https://gitlab.netgate.com/docs/pfSense-book/-/commit/83082ffa5c605fc424f04ea25bfcde4320892206 Jim Pingle
04:15 PM Revision d0f746e3: Remove old nss_ldap.conf if it exists before symlinking. Fixes #8698
Jim Pingle
04:08 PM Revision e6e6ad5c: Merge pull request #4326 from vktg/voucherviaurl
Renato Botelho
03:44 PM pfSense Docs Correction #10643 (Feedback): Feedback on Routing and Multi-WAN — Gateway Settings
Addressed in https://gitlab.netgate.com/docs/pfSense-book/-/commit/83082ffa5c605fc424f04ea25bfcde4320892206 Jim Pingle
03:44 PM pfSense Docs Correction #9570 (Feedback): Feedback on Routing and Multi-WAN — Gateway Settings
Addressed in https://gitlab.netgate.com/docs/pfSense-book/-/commit/83082ffa5c605fc424f04ea25bfcde4320892206 Jim Pingle
03:43 PM pfSense Docs Correction #9520 (Feedback): Feedback on Routing and Multi-WAN — Gateway Settings
Addressed in https://gitlab.netgate.com/docs/pfSense-book/-/commit/83082ffa5c605fc424f04ea25bfcde4320892206 Jim Pingle
02:49 PM pfSense Packages Bug #10429 (Feedback): Status Traffic Total broken 2.4.5
The diff was applied in this commit and should be testable once the packages rebuild for package version 2.3.2: https... Jared Dillard
01:54 PM Bug #9450: Multiwan gateway group fail-over not working as expected (possible race condition)
I’m not getting desired behavior but I don’t know if it’s caused by changes to this
output of /tmp/rules.debug aft...
Dee D
01:50 PM Revision 2a50b9b4: Fix #11053: Check variable before call implode()
Renato Botelho
01:37 PM Revision 7a8e671f: Merge pull request #4486 from apollo13/patch-2
Renato Botelho
01:29 PM Revision 53ea4b8b: Allow to submit voucher via URL. Implements #1984
Viktor Gurov
01:21 PM Revision 21654184: Fixed #11062 by adding support for fingerprint specification
Steve Beaver
01:20 PM Bug #7307 (Feedback): ZFS installer - shuts down instead of rebooting
Jim Pingle
01:18 PM Revision 8693a501: Do not restart L2TP VPN server when deleting user. Fixes #11059
Viktor Gurov
01:17 PM Revision 298df54d: Unbound custom TLS port fix. Issue #11051
Viktor Gurov
01:15 PM Revision c073d662: Dashboard widget interface name popup hint. Implements #11041
Viktor Gurov
01:13 PM Todo #9417: Convert LDAP TLS setup from environment to LDAP_OPT_X_TLS_* set options
See also: #10704 Jim Pingle
01:13 PM Todo #10704 (Feedback): Work around PHP issues with SSL LDAP and multiple authentication servers
This is technically waiting for feedback on #9417 so I'm changing the status accordingly.
If #9417 has to be backe...
Jim Pingle
12:31 PM Revision b704b6ef: Add a warning when write_config() is called without description
Renato Botelho
12:31 PM Revision e85ae672: Fix #204: Add messages to all write_config() calls
Renato Botelho
12:31 PM Revision 526df36e: Remove commented out lines
Renato Botelho
12:31 PM Revision cffb85bf: Fix indent
Renato Botelho
12:30 PM Bug #6025: Load balancing fails when one gateway has a weight of 1 and another gateway has a weight >1
Fabian Schnelle wrote:
> After this change, policy based routing no longer works.
> The entry in the firewall rule...
Jim Pingle
11:32 AM Feature #11058 (Rejected): In dashboard log widget an option to automatically resolve source or destination names depending whether names exist in private address space would be extremely useful
That would be overkill for a dashboard widget. Someone can resolve via the firewall log view if needed. There are als... Jim Pingle
11:14 AM Bug #11063: PHP error if SMTP notification fails
This happens if an SMTP notification can't be sent (e.g. WAN down, no default route, etc). Not specific to any interf... Jim Pingle
11:06 AM Bug #11063 (Resolved): PHP error if SMTP notification fails
amd64
12.2-STABLE
FreeBSD 12.2-STABLE 573bcbb6506(devel-12) pfSense
Crash report details:
PHP Errors:
[12-No...
Niccolò Marchi
10:20 AM Feature #7467 (Feedback): Add iPhone/Android/Generic USB tethering support
I've enabled it to build on armv7 and arm64 on 2.5.0. Please check next round of snapshots Renato Botelho
09:40 AM Feature #7467: Add iPhone/Android/Generic USB tethering support
I am on the 2.4.5-RELEASE-p1 (arm64), SG-1100
The if_ipheth kernel module is missing:...
Oleg Tyaglo
10:17 AM Feature #8698: LDAP authenticated users should be able to log in via ssh
Looks like the errors some are seeing (including myself) are from @/usr/local/etc/nss_ldap.conf@ not being setup as a... Jim Pingle
04:54 AM Feature #8698: LDAP authenticated users should be able to log in via ssh
pfSense 2.5.0.a.20201111.1850 test with FreeIPA server 4.8.4:
Authentication server configuration:...
Viktor Gurov
10:15 AM Feature #1984: Allow CP Voucher submission via URL so they can be distributed as QR code
Applied in changeset commit:53ea4b8b8b0c4a05c3d11bae8d26504e17e161dd. Viktor Gurov
10:08 AM Feature #1984 (Feedback): Allow CP Voucher submission via URL so they can be distributed as QR code
PR has been merged. Thanks! Renato Botelho
09:51 AM Bug #11037 (Resolved): Change APIs for HE.net Tunnelbroker dynamic DNS update
Tested the patch on the 2.4.5-p1. It works fine.
Ticket resolved.
Danilo Zrenjanin
09:45 AM Revision d2db8e58: Add a comment about CARP in generated rules
Currently the rules.debug file looks like this:
```
# Snort package
block log quick from <snort2c> to any tracker 100...
Florian Apolloner
09:21 AM Bug #6028 (In Progress): no firewall rules loaded after reboot with invalid ruleset
Renato Botelho
08:09 AM Bug #11050: "Backup extra data" does not behave properly
The PR Addresses the last three points but not the first.
Part of the first one will need fixed in the src repo in...
Jim Pingle
07:51 AM Bug #11050 (Pull Request Review): "Backup extra data" does not behave properly
Renato Botelho
02:17 AM Bug #11050: "Backup extra data" does not behave properly
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/45 Viktor Gurov
08:00 AM Bug #11053 (Feedback): PHP error on services_dhcp_relay.php
Applied in changeset commit:2a50b9b49e47e9d2113facd7b97d25478135e3d6. Renato Botelho
07:59 AM Bug #10919: Improve handling of OpenVPN data cipher negotiation options
The changes through comment 12 appear to fix my issue. S Premeau
07:41 AM Bug #11061: CARP rules show up as "part" of the snort package in rules.debug
Thank you very much. Florian Apolloner
07:38 AM Bug #11061 (Feedback): CARP rules show up as "part" of the snort package in rules.debug
PR has been merged. Thanks! Renato Botelho
03:47 AM Bug #11061 (Resolved): CARP rules show up as "part" of the snort package in rules.debug
This is only a cosmetic change, but it adds a header to the generated rules to separate it from the snort package. Se... Florian Apolloner
07:25 AM Bug #11059: L2TP Server is restarted when administering users
Applied in changeset commit:8693a501df0d4c791a0858f7460db1b580fe337d. Viktor Gurov
07:19 AM Bug #11059 (Feedback): L2TP Server is restarted when administering users
PR has been merged. Thanks! Renato Botelho
07:17 AM Bug #11051 (Feedback): Unbound: custom TLS listen port ignored
PR has been merged. Thanks! Renato Botelho
06:35 AM Todo #204: All write_config() statements should include a reason of some sort
Applied in changeset commit:e85ae672e45f0e883478c74b630b1723908998dd. Renato Botelho
06:32 AM Todo #204 (Feedback): All write_config() statements should include a reason of some sort
All write_config() calls on base and ports now have a description. Added a Warning when it's called without it so de... Renato Botelho
02:43 AM pfSense Packages Feature #11060 (Resolved): Block access to consumer Google accounts
WebGUI feature for:
https://support.google.com/a/answer/1668854?hl=en:
To prevent users from signing in to Goog...
Viktor Gurov
12:36 AM Bug #11005 (Closed): IPv6 Prefix Delegation not requested if no interfaces set to track6
This seems to work great now. Thank you.
Chris Linstruth
12:09 AM pfSense Packages Feature #10950 (Resolved): Allow to select only netmap-compatible cards for inline mode
tested
Jordan Greene wrote:
> I was able to add and start an interface using snort with a USB ethernet adapter (...
Viktor Gurov

11/11/2020

11:57 PM Bug #11059: L2TP Server is restarted when administering users
Fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/44
Viktor Gurov
11:18 PM Bug #11059 (Resolved): L2TP Server is restarted when administering users
pfSense 2.5.0 development
When i delete l2tp user on l2tp server, all users are disconnected :(
Please fix it again
Evgeny Korostelev
08:17 PM Bug #10942: LDAP Auth error after update 2.5.0.a.20200930.1303
Testing LDAP authentication in
2.5.0-DEVELOPMENT (amd64)
built on Wed Nov 11 12:59:57 EST 2020
FreeBSD 12.2-STA...
Max Leighton
07:17 PM Feature #11057: Add default route indicator to Gateways widget
Apologies, should be gateways widget in dashboard. And Ritchie
06:48 PM Feature #11057 (Resolved): Add default route indicator to Gateways widget
Routing page under system tab indicates the current default route with an icon.
This would be ideal on the routing w...
And Ritchie
07:01 PM Feature #11058 (Rejected): In dashboard log widget an option to automatically resolve source or destination names depending whether names exist in private address space would be extremely useful
I understand that there may not be a desire based on performance reasons to resolve ip addresses from an external sou... And Ritchie
06:11 PM pfSense Packages Feature #9833: ACME: add ability to use custom ACME server
Michael Long wrote:
> I'll add my voice to this request. I just set up a local step-ca ACME server and would love t...
Stanislav Dimov
06:06 PM Revision 9bf4a147: OpenVPN client fallback cipher variable changed. Fixes #10919
Jim Pingle
05:19 PM Bug #6025: Load balancing fails when one gateway has a weight of 1 and another gateway has a weight >1
After this change, policy based routing no longer works.
The entry in the firewall rule is completely ignored and t...
Fabian Schnelle
03:58 PM Feature #11056 (New): Add option to disable flow-control on interfaces in GUI
Add toggle on/off function for Flow Control on interfaces as alternative to adding lines to loader.conf.local
Requ...
Paighton Bisconer
02:53 PM Revision 85652efd: Retire some packages from pfSense 2.5.0:
OpenBGPd - replaced by FRR
Quagga_OSPF - replaced by FRR
routed - not actively maintained and rarely used
blinkled - ...
Renato Botelho
01:33 PM pfSense Packages Bug #11055 (Resolved): Insecure FreeRADIUS defaults
* "Disable Weak EAP Types" (EAP tab, EAP section) should be enabled by default
* "Default EAP Types" (EAP tab, EAP s...
Anonymous
01:32 PM Feature #8698: LDAP authenticated users should be able to log in via ssh
Testing this with Active Directory, I'm able to successfully log into the webGUI with LDAP credentials, but attemptin... Max Leighton
01:23 PM pfSense Packages Bug #11054 (Assigned): Check Client Certificate CN not working as described
Page: Services / FreeRADIUS
Tab: EAP
Section: EAP-TLS
Option: Check Client Certificate CN
Actual result when en...
Anonymous
01:15 PM Feature #11041 (Pull Request Review): Add hardware interface name to popup hint in Interfaces Dashboard widget
Jim Pingle
12:13 PM Feature #11041: Add hardware interface name to popup hint in Interfaces Dashboard widget
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/43 Viktor Gurov
12:07 PM Bug #10919: Improve handling of OpenVPN data cipher negotiation options
Nice catch, I've pushed a fix. Thanks! Jim Pingle
12:05 PM Bug #10919: Improve handling of OpenVPN data cipher negotiation options
OpenVPN client edit is not saving / loading the Fallback cypher setting.
Looking through /usr/local/www/vpn_openvp...
Anonymous
12:03 PM Bug #11051 (Pull Request Review): Unbound: custom TLS listen port ignored
Jim Pingle
10:34 AM Bug #11051: Unbound: custom TLS listen port ignored
Fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/42
Viktor Gurov
11:42 AM Bug #11053 (Resolved): PHP error on services_dhcp_relay.php

amd64
12.2-STABLE
FreeBSD 12.2-STABLE 573bcbb6506(devel-12) pfSense
Crash report details:
PHP Errors:
[11-...
Niccolò Marchi
10:15 AM pfSense Packages Todo #11033: Update OpenVPN Client Export with OpenVPN 2.5.0 installer
Please post on the forum for assistance. You haven't provided nearly enough information there. Jim Pingle
10:13 AM pfSense Packages Todo #11033: Update OpenVPN Client Export with OpenVPN 2.5.0 installer
i have this problem with the last client_export Niccolò Marchi
10:11 AM pfSense Packages Bug #10579 (Rejected): Blinkled segfaults with SEGV_MAPERR
blinkled package is now retired on 2.5.0 Renato Botelho
10:07 AM pfSense Packages Feature #7660 (Rejected): Please add the ability to monitor more than one CARP address to the Quagga GUI support
Quagga package is now retired on 2.5.0 Renato Botelho
10:06 AM pfSense Packages Feature #4635 (Rejected): openbgpd options applied at group level
OpenBGPD package is now retired on 2.5.0 Renato Botelho
10:06 AM pfSense Packages Feature #6479 (Rejected): Add OpenBGPD config to High Availability Sync option to sync
OpenBGPD package is now retired on 2.5.0 Renato Botelho
10:06 AM pfSense Packages Feature #7657 (Rejected): OpenBGPD local-as feature in neighbors context
OpenBGPD package is now retired on 2.5.0 Renato Botelho
09:43 AM pfSense Packages Feature #10915 (Resolved): security/pfSense-pkg-sudo sudo.inc enhancement for better support of NRPE
Tested on 2.4.5_p1 and on 2.5.0-DEVELOPMENT (built on Wed Nov 11 01:06:53 EST 2020)
With NRPE package installed th...
Azamat Khakimyanov
09:32 AM pfSense Packages Bug #10927 (Resolved): pfBlockerNG-devel fullfill the pfsense config history when RAM disk in use
Tested on 2.4.4_p3, on 2.4.5_p1 and on 2.5.0-DEVELOPMENT (built on Wed Nov 11 01:06:53 EST 2020)
On 2.4.4_p3 I sti...
Azamat Khakimyanov
08:10 AM pfSense Packages Feature #11008: Add option to mail report pkg to skip sending email if no output
The text is correct in the package. When the box is checked, it only sends the e-mail if there is output. Adding the ... Jim Pingle
05:29 AM pfSense Packages Feature #11008 (Resolved): Add option to mail report pkg to skip sending email if no output
Tested on 2.4.5_p1 and on 2.5.0-DEVELOPMENT (built on Wed Nov 11 01:06:53 EST 2020)
There is an option 'Skip If No...
Azamat Khakimyanov
07:27 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
Renato, that ^fixed^ the problem :) I did create a FreeBSD bug report (251047)
Louis B
05:26 AM pfSense Packages Feature #10909 (New): #define MAXVIFS 32 to 64
Done! It's all back to 32 Renato Botelho
12:56 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
Renato, you only have to rebuild the OS. There is no neat to do something with the pfSense pimd package since those a... Louis B
07:09 AM pfSense Packages Bug #11052 (Not a Bug): Authtype MD5-Password dont work in freeradius3
When using hashed options like MD5 the "password" field must be filled with the _pre-hashed_ password, not the actual... Jim Pingle

11/10/2020

07:22 PM pfSense Packages Bug #11052: Authtype MD5-Password dont work in freeradius3
I tested in menu Diagnostic->authentication Teste Teste
07:20 PM pfSense Packages Bug #11052 (Not a Bug): Authtype MD5-Password dont work in freeradius3
system: PFsense 2.5
package: freeradius3
issue: I create a user in *users tab* with option *Password Encription* MD...
Teste Teste
07:20 PM pfSense Packages Bug #11030 (Resolved): OpenVPN Client Export shows server certs as clients
Tested pkg version 1.5_1 in:... Steve Wheeler
09:52 AM pfSense Packages Bug #11030 (Feedback): OpenVPN Client Export shows server certs as clients
I committed a variation of that instead:
https://github.com/pfsense/FreeBSD-ports/commit/0e72ef35bbb0f9dc370141cb9...
Jim Pingle
06:14 PM Revision 16fe7982: OpenVPN compression settings improvements. Issue #11020
* Hide compression options when compression is not allowed
* Omit compression options from the OpenVPN configuration ...
Jim Pingle
04:48 PM Revision 65831b5b: Fix display of OpenVPN dev mode when empty/missing. Issue #10919
Jim Pingle
02:37 PM pfSense Packages Feature #10909 (In Progress): #define MAXVIFS 32 to 64
right, I'm going to revert it and rebuild pimd and igmoproxy Renato Botelho
01:01 PM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
Renato,
Restore to MAXVIFS 32 is a good idea for two reasons:
- it would allow me to test the actual package beha...
Louis B
11:35 AM Bug #8611: unable to receive IPv6 RA's on SG-1000, default route lost
looks like bxe(4) driver bug, see #8324 Viktor Gurov
09:54 AM pfSense Packages Todo #11033: Update OpenVPN Client Export with OpenVPN 2.5.0 installer
No negative feedback thus far and further testing I've done has been positive as well. Picked back to 2.4.5 for more ... Jim Pingle
09:33 AM Bug #11051: Unbound: custom TLS listen port ignored
More context: running on bare metal Celeron 3160 with 8gb RAM. Landing page reports:
> 2.4.5-RELEASE-p1 (amd64)
>...
Brad Edmondson
09:31 AM Bug #11051 (Resolved): Unbound: custom TLS listen port ignored
Using latest stable pfSense: 2.4.5-RELEASE-p1 (amd64)
Attempting to configure two-tier DNS cache, using either BIN...
Brad Edmondson

11/09/2020

09:06 PM Revision 1cc93005: Improve OpenVPN Duplicate Connections option description. Fixes #10363
Jim Pingle
08:48 PM Revision c948bc45: Change default config domain to home.arpa. Implements #10533
Jim Pingle
06:24 PM Revision 3adc4134: Fix display of OpenVPN data cipher when NCP is disabled. Issue #10919
Jim Pingle
03:45 PM Bug #10363 (Resolved): Clarify behavior of OpenVPN server option for Duplicate Connections
This looks good! Jared Dillard
03:15 PM Bug #10363 (Feedback): Clarify behavior of OpenVPN server option for Duplicate Connections
Applied in changeset commit:1cc930053c02a9768494980bf70b9faf2fb46ee1. Jim Pingle
03:44 PM Revision 924eeefb: OpenVPN Data Cipher changes. Fixes #10919
* Change handling of data ciphers so they work properly for TLS and
shared key
* Move some duplicate code to a functi...
Jim Pingle
03:01 PM Revision 29f185b1: Merge pull request #4484 from emes/he-net-tunnelbroker-update-api
Renato Botelho
02:55 PM Todo #10533 (Feedback): Change default domain for new installations from "localdomain" to "home.arpa"
Applied in changeset commit:c948bc45f6f70ff35074129858a2dfa4e3f64a37. Jim Pingle
02:42 PM Todo #10533: Change default domain for new installations from "localdomain" to "home.arpa"
→ luckman212 wrote:
> I'd suggest one of the following instead, since many pfSense installs are not used in home env...
Jim Pingle
02:51 PM Bug #9385 (Closed): OpenVPN logs a "Device busy" error when opening tap interfaces, but continues to function
Doesn't appear to affect anything and I can find similar messages in logs going back several years, so it's not new i... Jim Pingle
02:15 PM Revision ca8459cd: LDAP shell authentication. Implements #8698
Viktor Gurov
01:56 PM Revision 34a06728: interfaces_vlan_configure_mtu(): Style fixes
Renato Botelho
01:52 PM Revision be732dba: Set child interfaces MTU fix. Issue #11035
Viktor Gurov
01:51 PM Revision 8f09cee9: IKEv2 vtimap creation fix. Issue #9592
Viktor Gurov
01:50 PM Revision 05af3262: Auto add static routes for PPP interfaces. Fixes #10407
Viktor Gurov
01:49 PM Revision 967d16ae: VXLAN bootup fix. Issue #10960
Viktor Gurov
01:42 PM Bug #11021 (Confirmed): ral(4) driver kernel panics in arm64
Tested:... Steve Wheeler
05:47 AM Bug #11021 (Feedback): ral(4) driver kernel panics in arm64
I've merged recent stable/12 which contains a fix for that. Please test it again on when a new round of snapshots is... Renato Botelho
01:40 PM pfSense Packages Feature #11042: Verify backup- / configuration-file after creation
Looks like your actual problem (based on your forum thread) is this: #11050
Under normal conditions on a release, ...
Jim Pingle
12:10 PM pfSense Packages Feature #11042: Verify backup- / configuration-file after creation
That is true but is also a non-statement. I already explained why that is irrelevant. Jim Pingle
12:01 PM pfSense Packages Feature #11042: Verify backup- / configuration-file after creation
Jim, if the software which checks the backup-file when loaded can check if backup is OK, the same software could do ... Louis B
11:03 AM pfSense Packages Feature #11042: Verify backup- / configuration-file after creation
Your logic is flawed because if it could detect the backup was bad it could just not make a bad backup. If it generat... Jim Pingle
10:23 AM pfSense Packages Feature #11042: Verify backup- / configuration-file after creation
Jim, at the moment you need the backup, *the firewall is probably down*. So *you need to have it fixed as soon as pos... Louis B
07:26 AM pfSense Packages Feature #11042 (Needs Patch): Verify backup- / configuration-file after creation
In the unlikely case that a bad backup was generated, it is unlikely anything could be done to repair it in the GUI, ... Jim Pingle
01:31 PM Bug #11050 (Resolved): "Backup extra data" does not behave properly
When backup up with "Backup Extra Data" checked, there are a few problems:
* Tags are not removed during every res...
Jim Pingle
01:24 PM pfSense Packages Bug #10911 (Resolved): Bandwidthd iframe not resizing in 2.4.5/2.4.5p1
Tested pfSense-pkg-bandwidthd-0.7.4_3 in Chrome, Edge, Firefox with no sizing issues. Working as expected. Marking th... Max Leighton
12:06 PM Feature #1984: Allow CP Voucher submission via URL so they can be distributed as QR code
Viktor, could you please update PR with changes suggested by jimp? Renato Botelho
10:02 AM pfSense Packages Feature #11043: pfSense GUI for iperf3 / perf
Maintaining a list of public servers is outside the scope of the package, and encouraging users to use a high-through... Jim Pingle
09:54 AM pfSense Packages Feature #11043: pfSense GUI for iperf3 / perf
Jim Pingle wrote:
> There is already a package for iperf3 with a GUI.
But not useful: no quick servers selection (b...
Sergei Shablovsky
07:27 AM pfSense Packages Feature #11043 (Rejected): pfSense GUI for iperf3 / perf
There is already a package for iperf3 with a GUI. Jim Pingle
09:57 AM pfSense Packages Feature #11044: pfSense GUI for OOKLA Speedtest
No, it is not reasonable. Any speed test run from the firewall is not a valid metric and adding a GUI only encourages... Jim Pingle
09:51 AM pfSense Packages Feature #11044: pfSense GUI for OOKLA Speedtest
Jim Pingle wrote:
> There is a CLI speed test package already (py37-speedtest-cli on 2.5.0, similar name on 2.4.5))....
Sergei Shablovsky
07:29 AM pfSense Packages Feature #11044 (Rejected): pfSense GUI for OOKLA Speedtest
There is a CLI speed test package already (py37-speedtest-cli on 2.5.0, similar name on 2.4.5)). There are no plans f... Jim Pingle
09:50 AM Bug #10919 (Feedback): Improve handling of OpenVPN data cipher negotiation options
Applied in changeset commit:924eeefb45222ee5bbf813b8d3d0b3ab704fcede. Jim Pingle
07:33 AM Bug #10919 (In Progress): Improve handling of OpenVPN data cipher negotiation options
Jim Pingle
09:38 AM Feature #11049 (Rejected): Improving GUI for Interfaces Assignment by adding Graphics View of physical port
There is no viable way to make this happen in a maintainable way, and it's largely unnecessary.
Please submit thes...
Jim Pingle
09:34 AM Feature #11049 (Rejected): Improving GUI for Interfaces Assignment by adding Graphics View of physical port
Hi pfSense DevTeam !
We appreciate You work!
Please Improve GUI for *Interfaces Assignment* by adding graphics vi...
Sergei Shablovsky
09:38 AM Feature #11048 (Rejected): Improving GUI for Interfaces by adding Graphics View of physical port
There is no viable way to make this happen in a maintainable way, and it's largely unnecessary.
Please submit thes...
Jim Pingle
09:19 AM Feature #11048 (Rejected): Improving GUI for Interfaces by adding Graphics View of physical port
Hi pfSense DevTeam !
We appreciate You work!
Please *Improve GUI for Interfaces by adding graphics view of physic...
Sergei Shablovsky
09:14 AM Feature #11047 (Rejected): Add Encryption Password suggestions and Restriction
That is way too much text to add to the GUI. There is a help link if anyone wants to follow it. Maybe a small note wi... Jim Pingle
09:10 AM Feature #11047: Add Encryption Password suggestions and Restriction
Sergei Shablovsky wrote:
> *Warning*
> 1. *Do not use online password generators* (You never know and control who...
Sergei Shablovsky
09:07 AM Feature #11047 (Rejected): Add Encryption Password suggestions and Restriction
Hi pfSense DevTeam !
We appreciate You work!
Please add to the
WebUI *Services* / *Auto Configuration Backup* /...
Sergei Shablovsky
09:02 AM Bug #11037 (Feedback): Change APIs for HE.net Tunnelbroker dynamic DNS update
PR has been merged. Thanks! Renato Botelho
08:25 AM Feature #8698: LDAP authenticated users should be able to log in via ssh
Applied in changeset commit:ca8459cdafafd225fbc07edbc32679b8301298fc. Viktor Gurov
08:16 AM Feature #8698 (Feedback): LDAP authenticated users should be able to log in via ssh
PR has been merged. Thanks! Renato Botelho
08:00 AM Bug #10407: L2TP static route not re-added after connection down/up
Applied in changeset commit:05af32629d9259817070a72f388a7d4c4835d76d. Viktor Gurov
07:51 AM Bug #10407 (Feedback): L2TP static route not re-added after connection down/up
PR has been merged. Thanks! Renato Botelho
07:53 AM Bug #11035 (Feedback): PPPoE: can't remove hook
PR has been merged. Thanks! Renato Botelho
07:15 AM Bug #11035 (Pull Request Review): PPPoE: can't remove hook
Jim Pingle
07:52 AM Bug #9592 (Feedback): VTI interface down because interface number created is greater than ipsec32768
PR has been merged. Thanks! Renato Botelho
07:50 AM Bug #10960 (Feedback): Bring up VXLANs correctly at boot
PR has been merged. Thanks! Renato Botelho
07:16 AM Bug #10960 (Pull Request Review): Bring up VXLANs correctly at boot
Jim Pingle
07:33 AM Bug #11046 (Duplicate): Openvpn missing cipher option inside config file
Already being worked on: #10919 Jim Pingle
05:30 AM Bug #11046: Openvpn missing cipher option inside config file
ncp-ciphers also missing
Version 2.5.0-DEVELOPMENT (amd64)
built on Sun Nov 08 13:03:56 EST 2020
FreeBSD 12.2-ST...
Manuel Piovan
04:29 AM Bug #11046 (Duplicate): Openvpn missing cipher option inside config file
latest snapshot
openvpn not connecting anymore between pfsense 2.5.0 and 2.4.5-p1
log full of ...
Manuel Piovan
07:31 AM Feature #11045: Improve link state visibility on Status > Interfaces
It shouldn't rely only on iconography on that page. It would be OK to add the icons alongside the text, but the text ... Jim Pingle
01:17 AM Feature #11045: Improve link state visibility on Status > Interfaces
Sergei Shablovsky wrote:
> Please change in GUI for Interface on Status / Interfaces page the items:
> Status
> DH...
Sergei Shablovsky
12:24 AM Feature #11045 (Resolved): Improve link state visibility on Status > Interfaces
Hi pfSense DevTeam !
We appreciate You work!
Please change in GUI for Interface on Status / Interfaces page the i...
Sergei Shablovsky
06:01 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
Louis van Breda wrote:
> Almost sure that MAXVIFS 64 does very likely! break the system!
>
> Yesterday, I spend t...
Renato Botelho
05:52 AM pfSense Packages Feature #11012 (Resolved): Add Zabbix 5.2 (agent and proxy) packages
Renato Botelho

11/08/2020

11:45 PM pfSense Packages Feature #11044 (Rejected): pfSense GUI for OOKLA Speedtest
Hi pfSense DevTeam !
We appreciate You work!
Please add the *GUI for OOKLA Speedtest service as pfSense-native pa...
Sergei Shablovsky
09:05 PM pfSense Packages Feature #11043 (Rejected): pfSense GUI for iperf3 / perf
Hi pfSense DevTeam !
We appreciate You work!
Please add the *GUI for iperf3 / perf as pfSense-native package*.
...
Sergei Shablovsky
12:25 PM Revision 02fb642f: Fix a typo.
Obtained from: FE Luiz Souza
11:45 AM pfSense Packages Feature #11042 (Needs Patch): Verify backup- / configuration-file after creation
I have been facing corrupt configuration files when using the file (loaded on an usb-stick) during an new installatio... Louis B
04:49 AM pfSense Packages Feature #10909: #define MAXVIFS 32 to 64
Almost sure that MAXVIFS 64 does very likely! break the system!
Yesterday, I spend the whole day! , together with ...
Louis B

11/07/2020

09:18 PM Feature #10280: DHCP Leases widget
Jim Pingle wrote:
> The author needs to submit that as a pull request. And that repository has not been updated in s...
Sergei Shablovsky
09:04 PM Feature #11041 (Resolved): Add hardware interface name to popup hint in Interfaces Dashboard widget
Hi dear pfsense devteam!
Please add appropriate BSD network port name (i.e. *igb3*, *bce1*, etc) to popup hint 90:...
Sergei Shablovsky
07:39 PM Bug #10919: Improve handling of OpenVPN data cipher negotiation options
The issue does also occur if ncp negotiation is enabled. I could not get any ciphers into the openvpn config file wi... S Premeau
07:31 PM Bug #10919: Improve handling of OpenVPN data cipher negotiation options
This change set does not appear to be writing cipher or data-ciphers to the openvpn configuration file.
Here's my ...
S Premeau
05:08 PM Bug #6880: Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
Confirmation that issue is still present in 2.4.5p1.
Log messages:
dhcp6c 4633 Sending Solicit
dhcp6c 38399...
Kris Phillips
02:38 PM pfSense Packages Feature #10950: Allow to select only netmap-compatible cards for inline mode
I was able to add and start an interface using snort with a USB ethernet adapter (ue0) on SG-5100
2.5.0-DEVELOPMEN...
Jordan G
01:44 PM pfSense Packages Bug #11040: pfb_filter core faults when clearing firewall log
Jim Pingle wrote:
> That instance of the program is from pfBlockerNG, not the base system.
>
> Nothing to fix in ...
John Jacobs
12:47 PM pfSense Packages Bug #11040: pfb_filter core faults when clearing firewall log
That instance of the program is from pfBlockerNG, not the base system.
Nothing to fix in the base system since the...
Jim Pingle
12:40 PM pfSense Packages Bug #11040: pfb_filter core faults when clearing firewall log
Adding: clog_pfb drops the core, pfb_filter stops. John Jacobs
12:37 PM pfSense Packages Bug #11040 (New): pfb_filter core faults when clearing firewall log
The clog_pfb drops a core when the firewall log is cleared. I can replicate this on demand. Clearing the log from Sta... John Jacobs
06:51 AM Bug #11035: PPPoE: can't remove hook
Set child interfaces MTU fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/41
Viktor Gurov
02:39 AM Bug #11035: PPPoE: can't remove hook
partially fixed in #9154 - on 2.5 I can get this error only when MTU is changed Viktor Gurov
04:42 AM pfSense Packages Feature #11012: Add Zabbix 5.2 (agent and proxy) packages
https://www.zabbix.com/life_cycle_and_release_policy
The sad part about the proxy is that they are not backwards com...
Pim Janssen
04:29 AM pfSense Packages Bug #8264: Radiusd restart on WAN change results in freeradius not running (and possible solution)
see also #11013 Viktor Gurov
12:15 AM pfSense Packages Bug #11039: route-map not working if Address Family is enabled.
no such issue on 2.5 branch (frr 0.6.8_8),
fixed in #10789
Viktor Gurov

11/06/2020

08:54 PM Revision 189edaf3: OpenVPN data cipher negotiation updates. Fixes #10919
* Rename "NCP Algorithms" to "Data Encryption Algorithms" to reflect the change in OpenVPN (frontend and backend, e.g... Jim Pingle
08:42 PM pfSense Packages Feature #11012: Add Zabbix 5.2 (agent and proxy) packages
Zabbix 5 (agent and proxy) have been added to packages.
Note: package manager list many Zabbix version , is there ...
Alhusein Zawi
07:14 AM pfSense Packages Feature #11012 (Feedback): Add Zabbix 5.2 (agent and proxy) packages
Thanks Danilo! Packages added to 2.5.0 and 2.4.5 Renato Botelho
06:29 PM pfSense Packages Bug #11039 (Resolved): route-map not working if Address Family is enabled.
enabling Address Family (Allow neighbor to advertise and receive routes for both IPv4 and IPv6) under BGP Neighbors w... Alhusein Zawi
03:25 PM Revision 56e031a7: OpenVPN compression options update. Issue #11020
* Add new "Allow Compression" option for OpenVPN 2.5.0. Defaults to asymmetric
(Decompress incoming packets, do not...
Jim Pingle
03:05 PM Bug #10919: Improve handling of OpenVPN data cipher negotiation options
Applied in changeset commit:189edaf33bb2b21761d9ace0b3fd0119955f8726. Jim Pingle
02:58 PM Bug #10919 (Feedback): Improve handling of OpenVPN data cipher negotiation options
I pushed a commit which implements everything above except for the warning message. It'll be set to feedback by the c... Jim Pingle
11:56 AM Bug #10919: Improve handling of OpenVPN data cipher negotiation options
Sounds like a good plan! Arne Schwabe
10:11 AM Bug #10919 (In Progress): Improve handling of OpenVPN data cipher negotiation options
Just a note to myself before I start on this:
The OpenVPN 2.5.0 changes doc and some info on the links above do st...
Jim Pingle
01:29 PM Todo #11020 (Feedback): Update OpenVPN to 2.5.0
The remaining items which need updated are all related to Data Ciphers (Formerly known as NCP) which have a separate ... Jim Pingle
09:28 AM Todo #11020: Update OpenVPN to 2.5.0
I pushed a commit to update the compression options to match changes in OpenVPN 2.5.0:
* Add new "Allow Compressio...
Jim Pingle
01:26 PM pfSense Packages Bug #11036: HAproxy ACL
I was able to reproduce this on pfSense 2.5 with haproxy-devel 0.61_1. Marcos M
01:00 PM Revision 482ffce8: Enable zabbix 5.2 packages
(cherry picked from commit 779cb929fb962c119150c7f8b57dca2b1d3fce74) Renato Botelho
01:00 PM Revision 779cb929: Enable zabbix 5.2 packages
Renato Botelho
12:58 PM Revision 5773fa70: Add Zabbix 5.2 config options
(cherry picked from commit 0fb3a92f80a9c3dfc5c54b27400819dea9f3434a) Danilo Baio
12:57 PM Revision 47a0afad: Merge pull request #4485 from dbaio/zabbix52
Renato Botelho
11:25 AM Bug #7547: Static routes using aliases are not automatically updated when alias content changes
See also: #9743, #11038 Jim Pingle
11:25 AM Bug #9743 (Duplicate): Missing dependency check(s) on aliases in static routes
There was already an issue for this: #7547 Jim Pingle
11:21 AM Bug #9743: Missing dependency check(s) on aliases in static routes
Jens Groh wrote:
> forgot the "pre" tags around the example so just ignore the strike-through ;) Can't edit the orig...
Kris Phillips
11:21 AM Bug #11038 (Duplicate): Editing Alias Used in Static Route Doesn't Update Routing Table
Duplicate of #7547 Jim Pingle
11:18 AM Bug #11038 (Duplicate): Editing Alias Used in Static Route Doesn't Update Routing Table
If you add an IP or subnet to an alias that is used in a static route, you have to edit and re-save the static route ... Kris Phillips
10:40 AM Bug #10407 (Pull Request Review): L2TP static route not re-added after connection down/up
Jim Pingle
05:12 AM Bug #10407: L2TP static route not re-added after connection down/up
Fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/39
Viktor Gurov
10:39 AM Bug #11037 (Pull Request Review): Change APIs for HE.net Tunnelbroker dynamic DNS update
Jim Pingle
10:06 AM Bug #9592 (Pull Request Review): VTI interface down because interface number created is greater than ipsec32768
Viktor Gurov
08:33 AM Bug #9592 (New): VTI interface down because interface number created is greater than ipsec32768
First IPsec IKEv2 creates bogus vtimap entry:... Viktor Gurov
05:08 AM pfSense Packages Feature #10612 (Resolved): Add pfSense package for Zeek (formerly Bro) Network Security Monitor
Thanks! I'll mark this one as resolved. Bugs found on new package should have their own tickets. Renato Botelho
12:31 AM Bug #11035: PPPoE: can't remove hook
see also https://forum.netgate.com/topic/135920/pfsense-2-4-4-fails-all-pppoe-s-after-disabling-one
and #9148
Viktor Gurov

11/05/2020

10:36 PM Revision 0fb3a92f: Add Zabbix 5.2 config options
Danilo Baio
10:15 PM Bug #10660 (Resolved): PHP errors in the traffic shaper wizard
Tested patch in 2.4.5p1 and in 2.5.0-DEVELOPMENT built on Thu Nov 05 19:03:52 EST 2020
Seems to be working as expe...
Max Leighton
09:13 PM Revision 4af6affa: Remove OpenVPN tun server IPv4 tunnel network requirement. Issue #11020
No longer required on OpenVPN 2.5.0 Jim Pingle
08:20 PM Revision f8690774: Style fixes
Renato Botelho
07:51 PM Revision a8627e2c: Remove redundant isset() check
Renato Botelho
07:51 PM Revision 2d3cd379: Do not unset() variables that were never defined
Renato Botelho
07:48 PM Revision 75a42ff7: Simplify logic
Renato Botelho
07:47 PM Revision a94ab4b8: Style fixes
Renato Botelho
07:36 PM Revision f03f4cc3: mwexec() 2nd parameter default value is false. Remove it from caller
Renato Botelho
07:34 PM Revision cc0618e2: Change client endpoint update API for he.net tunnelbroker dynamic dns
Michael Smith
05:25 PM pfSense Packages Feature #11012: Add Zabbix 5.2 (agent and proxy) packages
https://github.com/pfsense/pfsense/pull/4485
https://github.com/pfsense/FreeBSD-ports/pull/985
Danilo Baio
04:47 PM pfSense Packages Feature #10612: Add pfSense package for Zeek (formerly Bro) Network Security Monitor
the package has been added to pfSense Available Packages.
Installed smoothly.
Alhusein Zawi
08:20 AM pfSense Packages Feature #10612: Add pfSense package for Zeek (formerly Bro) Network Security Monitor
Applied in changeset pfsense:commit:13d19df75f52d18f67172b3cd6a4bdfd982d9d24. Renato Botelho
08:19 AM pfSense Packages Feature #10612 (Feedback): Add pfSense package for Zeek (formerly Bro) Network Security Monitor
Done! Renato Botelho
03:16 PM Todo #11020: Update OpenVPN to 2.5.0
I pushed a commit which removes the IPv4 tunnel network requirement from the GUI and backend code. I was able to make... Jim Pingle
02:39 PM Revision 29131ce9: Track Interface / PD improvements. Issue #5999
Viktor Gurov
02:37 PM Revision bf9d8809: HA Sync input validation message fix. Issue #11017
Viktor Gurov
02:37 PM Revision c150479c: Different interface name for L2TP VPN. Fixes #11006
Viktor Gurov
02:35 PM Revision 7ccff001: CBQ borrow option input validation. Issue #7915
Viktor Gurov
02:32 PM Bug #11035: PPPoE: can't remove hook
Is this the problem?
> kernel vlan2: changing name to 'igb4.7'
Grischa Zengel
02:31 PM Bug #11035: PPPoE: can't remove hook
I replayed this bug again:... Grischa Zengel
12:01 PM Bug #11035 (Resolved): PPPoE: can't remove hook
I have seen this with 2 Pfsense.
After changing a single RAW interface (change from none to staticIP on igb4/opt11 o...
Grischa Zengel
02:16 PM Revision 13d19df7: Fix #10612: Add pfSense-pkg-zeek
Renato Botelho
02:03 PM Bug #11017 (Resolved): Incorrect synchronizetoip value causing XMLRPC errors
Tested the patch on 2.4.5-p1. It works fine. Danilo Zrenjanin
08:38 AM Bug #11017: Incorrect synchronizetoip value causing XMLRPC errors
PR has been merged. Thanks! Renato Botelho
12:06 AM Bug #11017: Incorrect synchronizetoip value causing XMLRPC errors
error message fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/36
Viktor Gurov
01:57 PM Revision 94cd71a4: Merge pull request #4483 from emes/he-net-tunnelbroker-ipfix
Renato Botelho
01:54 PM Bug #11037: Change APIs for HE.net Tunnelbroker dynamic DNS update
PR: https://github.com/pfsense/pfsense/pull/4484 Michael Smith
01:53 PM Bug #11037 (Resolved): Change APIs for HE.net Tunnelbroker dynamic DNS update
Currently using a deprecated client update API for HE.net Tunnelbroker dynamic DNS (https://ipv4.tunnelbroker.net/ipv... Michael Smith
01:32 PM pfSense Packages Bug #11036 (New): HAproxy ACL
If you try to edit an existing Access Control list on already defined TCP type Frontend, an unsupported Expression li... Danilo Zrenjanin
01:14 PM Bug #11024 (Resolved): Dynamic DNS update for HE.net Tunnelbroker always sets IP address of default WAN interface
Renato Botelho
12:46 PM Bug #11024: Dynamic DNS update for HE.net Tunnelbroker always sets IP address of default WAN interface
Tested and works as expected. Michael Smith
07:57 AM Bug #11024 (Feedback): Dynamic DNS update for HE.net Tunnelbroker always sets IP address of default WAN interface
PR has been merged. Thanks! Renato Botelho
10:48 AM Bug #9072: RRD graph mouseover information shows up as Mb when unit size is set to MB
I can't reproduce, did you toggle the *Unit Size* from *Bits* to *Bytes* and back again (hitting *Save* each time) on... Jared Dillard
08:45 AM Bug #11006: L2TP Server and Client both use "l2tpX" for interface names
Applied in changeset commit:c150479cc4476b07460a7b3578fba5cac7c6b30b. Viktor Gurov
08:37 AM Bug #11006 (Feedback): L2TP Server and Client both use "l2tpX" for interface names
PR has been merged. Thanks! Renato Botelho
03:46 AM Bug #11006: L2TP Server and Client both use "l2tpX" for interface names
Jim Pingle wrote:
> I see what you mean and have adjusted the subject to match. Both the L2TP Server and L2TP interf...
Viktor Gurov
08:39 AM Bug #5999: IPv6 IP Alias prevents Track Interface from working with DHCPv6 and RA
PR has been merged. Thanks! Renato Botelho
08:36 AM Bug #7915 (Feedback): CBQ Child queue set bandwidth does not apply correctly
PR has been merged. Thanks! Renato Botelho
08:27 AM Bug #7915: CBQ Child queue set bandwidth does not apply correctly
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/38 Viktor Gurov
07:43 AM Bug #10998 (Resolved): traffic shaper php error
Renato Botelho
12:51 AM Bug #10998: traffic shaper php error
It's ok now thanks. Niccolò Marchi
06:01 AM Bug #11034 (Resolved): poesX interfaces is not created
PPPoE Server creates "ngX" interfaces instead of "poesX"
"POESX" tab on services_dhcpv6.php page does not work as ex...
Viktor Gurov

11/04/2020

03:35 PM pfSense Packages Todo #11033 (Feedback): Update OpenVPN Client Export with OpenVPN 2.5.0 installer
Committed to devel (pfSense 2.5.0) for further testing
https://github.com/pfsense/FreeBSD-ports/commit/b7a70d0c6ff...
Jim Pingle
03:16 PM pfSense Packages Todo #11033 (Closed): Update OpenVPN Client Export with OpenVPN 2.5.0 installer
OpenVPN 2.5.0 is out and needs added to the client export package.
* OpenVPN 2.5.0 has separate 64-bit and 32-bit ...
Jim Pingle
03:35 PM Todo #11020 (In Progress): Update OpenVPN to 2.5.0
Jim Pingle
03:33 PM Todo #11020 (Feedback): Update OpenVPN to 2.5.0
Jim Pingle
03:27 PM Revision bf4c4d12: Traffic shaper wizard fix. Issue #10998
Viktor Gurov
03:06 PM Revision 1c3a5b0b: HA sync synchronizetoip input validation. Issue #11017
Viktor Gurov
02:34 PM Revision a62b14a7: Set correct cat command path. Fixes #11032
Viktor Gurov
11:37 AM Bug #5999: IPv6 IP Alias prevents Track Interface from working with DHCPv6 and RA
fixes/improvements:
- Show Track6IP correctly if there is no VIPs on the interface;
- Show PD on the `services_dhc...
Viktor Gurov
11:09 AM pfSense Packages Bug #11031 (Resolved): FRR: PHP error in frr_bgp.inc
Tested in pkg 0.6.8_8
Looks good. Starts at boot correctly. No errors generated.
Steve Wheeler
05:18 AM pfSense Packages Bug #11031 (Feedback): FRR: PHP error in frr_bgp.inc
PR has been merged. Thanks! Renato Botelho
03:32 AM pfSense Packages Bug #11031: FRR: PHP error in frr_bgp.inc
Fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/5
Viktor Gurov
10:58 AM Revision da637044: IPv6 Port Forward 6RD/6to4 interface support. Feature #10984
Viktor Gurov
10:28 AM Bug #11032 (Resolved): Setting Log compression to None disables all entries in log view
Tested the patch. It fixes the issue. Ticket resolved. Danilo Zrenjanin
08:40 AM Bug #11032: Setting Log compression to None disables all entries in log view
Applied in changeset commit:a62b14a7c729331383e94f086fb3d569726d1830. Viktor Gurov
08:34 AM Bug #11032 (Feedback): Setting Log compression to None disables all entries in log view
PR has been merged. Thanks! Renato Botelho
08:17 AM Bug #11032 (New): Setting Log compression to None disables all entries in log view
Fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/33
Viktor Gurov
05:42 AM Bug #11032 (Rejected): Setting Log compression to None disables all entries in log view
Viktor Gurov
09:27 AM Bug #10998 (Feedback): traffic shaper php error
Renato Botelho
09:09 AM Bug #10998 (Pull Request Review): traffic shaper php error
Jim Pingle
01:09 AM Bug #10998: traffic shaper php error
Fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/31
Viktor Gurov
09:20 AM pfSense Packages Bug #11030 (Pull Request Review): OpenVPN Client Export shows server certs as clients
Jim Pingle
09:16 AM pfSense Packages Bug #11030: OpenVPN Client Export shows server certs as clients
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/6 Viktor Gurov
09:07 AM Bug #11017 (Feedback): Incorrect synchronizetoip value causing XMLRPC errors
PR has been merged. Thanks! Renato Botelho
08:37 AM Bug #11017: Incorrect synchronizetoip value causing XMLRPC errors
`synchronizetoip` input validation to avoid XMLRPC errors:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_reques...
Viktor Gurov
07:09 AM Bug #10960 (In Progress): Bring up VXLANs correctly at boot
I'll work on this one Renato Botelho
05:22 AM Feature #10984 (Feedback): Port Forward IPv6
PR has been merged. Thanks! Renato Botelho
05:00 AM Feature #10984 (New): Port Forward IPv6
6RD/6to4 interfaces support:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/32
Viktor Gurov
12:43 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
Jörn Greszki wrote:
> Now tested with 2.5.0.a.20201101.1850
>
> I still get for unknown reasons sometimes partial...
Viktor Gurov

11/03/2020

11:39 PM Bug #11025 (Duplicate): traffic shaper PHP error
Duplicate of #10998#note-5 Viktor Gurov
11:32 PM Todo #11020: Update OpenVPN to 2.5.0
+ Add ability to create IPv6-only OpenVPN networks
from https://github.com/OpenVPN/openvpn/blob/release/2.5/Change...
Viktor Gurov
07:11 PM Revision ce9d7ba1: Allow shell users to enable history. Implements #11029
Jim Pingle
06:02 PM Bug #11032 (Resolved): Setting Log compression to None disables all entries in log view
If Log compression is set to "None" all entries in all logs are hidden (not deleted).
To reproduce:
- Go to Statu...
T Toft
05:43 PM pfSense Packages Bug #11031 (Resolved): FRR: PHP error in frr_bgp.inc
I am seeing an error at boot triggered by FRR:... Steve Wheeler
04:18 PM pfSense Packages Bug #11030: OpenVPN Client Export shows server certs as clients
Once upon a time it used to work, they must have locked that down at some point.
Back in the day, all certs were "...
Jim Pingle
04:12 PM pfSense Packages Bug #11030: OpenVPN Client Export shows server certs as clients
Tested in openvpn-client-export 1.4.23_2
Installed in:...
Steve Wheeler
04:04 PM pfSense Packages Bug #11030 (Resolved): OpenVPN Client Export shows server certs as clients
If you have an SSL/TLS only remote access OpenVPN server coinfigured the Client Export tab will show exportable confi... Steve Wheeler
01:20 PM Feature #11029 (Feedback): Enable command history in the shell
Applied in changeset commit:ce9d7ba143c968e672abb4265cca19f93d851e7e. Jim Pingle
10:18 AM Feature #11029 (Resolved): Enable command history in the shell
Historically we disabled shell command history tracking primarily because embedded/NanoBSD had a read-only filesystem... Jim Pingle
01:04 PM Bug #10875: PPP periodic reset does not fully restore gateway group round-robin functionality
seems related to #10716 Viktor Gurov
12:08 PM Bug #11023: route_get('default', 'inet') always returns empty
Jim Pingle wrote:
> That is not relevant to this bug report, and is likely a problem in the script maintained by acm...
Christian Knop
12:02 PM Bug #11023: route_get('default', 'inet') always returns empty
Stop posting to this bug report. The one single issue for this report is resolved. If you have some other issue, it d... Jim Pingle
11:59 AM Bug #11023: route_get('default', 'inet') always returns empty
ow to fix cURL error 60: SSL certificate problem
Narendra Vaghela
Narendra Vaghela
Sep 1, 2016·1 min read
Somet...
Christian Knop
11:54 AM Bug #11023: route_get('default', 'inet') always returns empty
I tried the following https://chasingcode.dev/blog/fix-curl-error-60-ssl-certificate-problem/. The entry in the php.i... Christian Knop
11:29 AM Bug #11023: route_get('default', 'inet') always returns empty
That is not relevant to this bug report, and is likely a problem in the script maintained by acme.sh and not us. Jim Pingle
11:20 AM Bug #11023: route_get('default', 'inet') always returns empty
All 3 domains are with Namecheap. 3 different endings .net, .fit and .vip. It doesn't matter in which order the domai... Christian Knop
11:12 AM Bug #11023: route_get('default', 'inet') always returns empty
Many thanks for the support. The gateway ip is now correctly recognized.
I have now found the other bug. The 1st d...
Christian Knop
07:26 AM Bug #11023 (Resolved): route_get('default', 'inet') always returns empty
The specific error "No Source IP specified for Namecheap API" was due to a bug in the routing code as I mentioned. It... Jim Pingle
06:34 AM Bug #11023: route_get('default', 'inet') always returns empty
I just looked to see if the same error existed under ubuntu. Christian Knop
05:48 AM Bug #11023: route_get('default', 'inet') always returns empty
Christian Knop wrote:
> Under Ubuntu I entered my public ip by hand in the config and was able to solve the problem ...
Renato Botelho
10:52 AM Bug #10947 (Resolved): Virtual interface assignment can't be done in CLI interface assignment
Tested on:... Danilo Zrenjanin
10:22 AM pfSense Docs New Content #11010: Feedback on Hardware — Hardware Tuning and Troubleshooting
I will check on 2.5. Though reading this:
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=237166
If it has chan...
Marcos M
06:07 AM pfSense Docs New Content #11010: Feedback on Hardware — Hardware Tuning and Troubleshooting
not working for me, 2.5.0, maybe they are valid for 2.4.5 but I can't test on it.
if it's only for 2.4.5 it will bec...
Manuel Piovan
07:27 AM pfSense Docs Correction #11028 (Duplicate): Feedback on Hardware — Hardware Sizing Guidance
Duplicate of #9228
We'll be removing the list entirely and linking to the store/site data instead so it's always c...
Jim Pingle
07:12 AM pfSense Docs Correction #11028 (Duplicate): Feedback on Hardware — Hardware Sizing Guidance
*Page:* https://docs.netgate.com/pfsense/en/latest/hardware/size.html
*Feedback:*
Can the SG-2100 be added to t...
Chris Macmahon
05:46 AM pfSense Packages Bug #11013: FreeRADIUS does not start after a package reload or a router bootup/reboot
Michael Klein wrote:
> Hi Renato, I tested the fix on both SG-3100's and it works very well. I'm glad that this issu...
Renato Botelho
04:36 AM pfSense Packages Bug #11013 (Resolved): FreeRADIUS does not start after a package reload or a router bootup/reboot
Tested with 0.15.7_20 FreeRADIUS version on SG-3100.
The issue has been solved. Ticket resolved.
Danilo Zrenjanin

11/02/2020

09:02 PM Bug #8870 (Resolved): Webgui incorrectly reports "The system is on the latest version".
Tested in
2.5.0-DEVELOPMENT (amd64)
built on Thu Oct 29 07:01:19 EDT 2020
FreeBSD 12.2-STABLE
Received "Unabl...
Max Leighton
05:25 PM pfSense Packages Bug #11013: FreeRADIUS does not start after a package reload or a router bootup/reboot
Hi Renato, I tested the fix on both SG-3100's and it works very well. I'm glad that this issue has finally been resol... Michael Klein
03:18 PM pfSense Packages Bug #11013: FreeRADIUS does not start after a package reload or a router bootup/reboot
Renato, thank you for all your help. I look forward to the new version and will provide feedback. I'm not sure why Ji... Michael Klein
06:24 AM pfSense Packages Bug #11013 (Feedback): FreeRADIUS does not start after a package reload or a router bootup/reboot
This should be fixed in 0.15.7_20 Renato Botelho
04:27 AM pfSense Packages Bug #11013 (New): FreeRADIUS does not start after a package reload or a router bootup/reboot
I'll take this one Renato Botelho
03:53 PM Revision b1558574: Ticket #10955: Fix "default" case
Make a string check to cover "default" gateway Renato Botelho
02:10 PM Bug #11023: route_get('default', 'inet') always returns empty
Under Ubuntu I entered my public ip by hand in the config and was able to solve the problem with it.
However, the...
Christian Knop
02:05 PM Bug #11023: route_get('default', 'inet') always returns empty
I am surprised that it is not ACME. I tested ACME on Ubuntu 20.04.1 and sometimes the same problem. I suspect a probl... Christian Knop
09:56 AM Bug #11023 (Feedback): route_get('default', 'inet') always returns empty
Actually this isn't a problem in ACME, it's a problem in a base system function which only exists on 2.5.0.
@route...
Jim Pingle
10:22 AM Bug #11024 (Pull Request Review): Dynamic DNS update for HE.net Tunnelbroker always sets IP address of default WAN interface
Jim Pingle
07:33 AM Todo #11020 (In Progress): Update OpenVPN to 2.5.0
2.5.0 was cherry-picked to devel ports tree Renato Botelho
07:25 AM Todo #11020: Update OpenVPN to 2.5.0
We already plan on updating OpenVPN to 2.5.0, and it was added to FreeBSD ports over the weekend.
But those other ...
Jim Pingle
07:21 AM pfSense Packages Feature #11026: Feedback on Packages — FreeRADIUS package
That is not a documentation problem, or a bug. It's a feature you want that does not yet exist. Jim Pingle
04:09 AM pfSense Packages Feature #11026 (New): Feedback on Packages — FreeRADIUS package
*Page:* https://docs.netgate.com/pfsense/en/latest/packages/freeradius.html
*Feedback:*
This file is not preser...
pf Driver
07:15 AM Bug #11027 (Duplicate): traffic shaper php error
Duplicate of #11025 Jim Pingle
07:11 AM Bug #11027 (Duplicate): traffic shaper php error

amd64
12.2-STABLE
FreeBSD 12.2-STABLE 2841d41b090(devel-12) pfSense
Crash report details:
PHP Errors:
[0...
Niccolò Marchi
07:09 AM Bug #9058: Kernel panic during L2TP retransmit
Mark, it crashed again after Luiz pushed 2c7ab6a3c3f on devel-12 branch Renato Botelho
07:03 AM Bug #10812: Traffic graph shows 2X the actual traffic on VLAN interfaces.
Fixed by commit 2841d41b090 on branch devel-12 of FreeBSD-src repository Renato Botelho
06:32 AM Bug #10812 (Feedback): Traffic graph shows 2X the actual traffic on VLAN interfaces.
Fix committed.
The fix is a bit different with the new code.
Luiz Souza
06:58 AM pfSense Packages Bug #10936 (Feedback): both haproxy/haproxy-devel non-existent option lb-agent-chk
PR has been merged. Thanks! Renato Botelho
06:58 AM pfSense Packages Bug #10885 (Feedback): HAProxy DNS statistics not working
PR has been merged. Thanks! Renato Botelho
06:29 AM Bug #6528 (Resolved): The captive portal cannot be used on interface lan since it is part of a bridge but works anyway
Renato Botelho
04:51 AM Bug #10998 (New): traffic shaper php error
Renato Botelho
04:30 AM Bug #10965 (Resolved): rtsold not starting dhcp6c when managed bit is set
Renato Botelho
04:29 AM pfSense Packages Bug #11014 (Resolved): sudo update failure
Renato Botelho
04:10 AM Bug #9054: Gateway Group slow (or never) to switch back to Tier 1
Now tested with 2.5.0.a.20201101.1850
I still get for unknown reasons sometimes partial or full loss for alive-pin...
Jörn Greszki
04:08 AM Bug #10546: Gateways removed from routing groups based on low alert thresholds
Now tested with 2.5.0.a.20201101.1850
I still get for unknown reasons sometimes partial or full loss for alive-pin...
Jörn Greszki
04:00 AM Bug #9450: Multiwan gateway group fail-over not working as expected (possible race condition)
I get for unknown reasons sometimes partial or full loss, but this is not the issue.
Nov 2 10:37:56 dpinger 1623...
Jörn Greszki
01:11 AM Feature #2622: Allow DHCP without a range so that only static mappings may be used on an interface
+1 B D

11/01/2020

04:13 PM Bug #4510 (Resolved): Crash & reboot loop when configure PPPoE server on PPPoE client interface
Tested in
2.5.0-DEVELOPMENT (amd64)
built on Sun Nov 01 13:02:32 EST 2020
FreeBSD 12.2-STABLE
Fix works as e...
Max Leighton
02:05 PM pfSense Packages Bug #10885: HAProxy DNS statistics not working
Should be fixed in haproxy 0.61.1
PR: https://github.com/pfsense/FreeBSD-ports/pull/984
Pi Ba
02:03 PM pfSense Packages Bug #10936: both haproxy/haproxy-devel non-existent option lb-agent-chk
In haproxy-devel package 0.61.1 this 'Agent' health-check method should no longer be visible (unless already configur... Pi Ba
09:08 AM Bug #11025 (Duplicate): traffic shaper PHP error
amd64
12.2-STABLE
FreeBSD 12.2-STABLE 2841d41b090(devel-12) pfSense
Crash report details:
PHP Errors:
[01-No...
Niccolò Marchi
05:48 AM Bug #10998: traffic shaper php error
amd64
12.2-STABLE
FreeBSD 12.2-STABLE 2841d41b090(devel-12) pfSense
Crash report details:
PHP Errors:
[01-No...
Niccolò Marchi

10/31/2020

10:59 PM Revision 048d4cdb: HE.net Tunnelbroker dynamic dns not supplying ip address parameter
Michael Smith
07:15 PM pfSense Packages Bug #11014: sudo update failure
sudo 0.3_5 is installed on 2.4.5-p1 Alhusein Zawi
11:21 AM pfSense Packages Bug #11014: sudo update failure
Issue fixed in 0.3_5, thank you. James Baker
06:57 PM Bug #10965: rtsold not starting dhcp6c when managed bit is set
Tested for several weeks and works as expected. Michael Smith
06:21 PM Bug #11023: route_get('default', 'inet') always returns empty
can the domain cause the problem? a .net works and a .fit and a .vip cause the error. Christian Knop
05:48 AM Bug #11023 (Resolved): route_get('default', 'inet') always returns empty
ip address is missing [NAMECHEAP_SOURCEIP]
test.com
Renewing certificate
account: testing
server: letsencry...
Christian Knop
06:07 PM Bug #11024: Dynamic DNS update for HE.net Tunnelbroker always sets IP address of default WAN interface
PR https://github.com/pfsense/pfsense/pull/4483 Michael Smith
05:58 PM Bug #11024 (Resolved): Dynamic DNS update for HE.net Tunnelbroker always sets IP address of default WAN interface
The update uri does not include the dynamic DNS IP address, but relies on the tunnel client endpoint update API to de... Michael Smith
03:37 PM Bug #6528: The captive portal cannot be used on interface lan since it is part of a bridge but works anyway
* Created captive portal server(interface is LAN)
* Created openvpn server.
* Assigned interface for openvpn.
wh...
Alhusein Zawi
11:41 AM pfSense Packages Bug #11013: FreeRADIUS does not start after a package reload or a router bootup/reboot
Sorry to hear you couldn't recreate this issue which affects both of our *Netgate SG-3100* appliances. The insertion ... Michael Klein
10:39 AM pfSense Packages Bug #11013 (Rejected): FreeRADIUS does not start after a package reload or a router bootup/reboot
Kris Phillips
10:39 AM pfSense Packages Bug #11013 (Feedback): FreeRADIUS does not start after a package reload or a router bootup/reboot
Michael Klein wrote:
> The FreeRADIUS package is the _only_ package that does not startup after the router reboots o...
Kris Phillips
11:24 AM pfSense Docs Correction #11019: Feedback on pfSense Configuration Recipes — Configuring a Single Multi-Purpose OpenVPN Instance
Indeed a rewrite would be good.
The remote IPv4 Remote field is missing from the Remote Access server mode which w...
Marcos M
11:19 AM pfSense Packages Bug #10983: pfBlockerNG not cleaning everything behind it
Given this seems to be VM and sounds similar to issues that can happen when interfaces disappear or otherwise change ... Marcos M
10:58 AM pfSense Packages Bug #8340 (Rejected): Status_Traffic_Totals Error
Unable to reproduce and reported that the issue was resolved by disabling and re-enabling graphing. Likely a file co... Kris Phillips
10:46 AM pfSense Packages Bug #6736 (Closed): Snort fails to start after upgrade to 2.3.2-RELEASE
Closing this very old bug report out, as this issue is from an unsupported version of pfSense and there is no issues ... Kris Phillips

10/30/2020

08:36 PM pfSense Packages Feature #11022: Add feeds from Firebog.net to pfBlockerNG
Pull Request to 2.4.5 branch: https://github.com/pfsense/FreeBSD-ports/pull/983
Pull Request to devel: https://git...
Matthew Hildebrand
07:44 PM pfSense Packages Feature #11022 (Resolved): Add feeds from Firebog.net to pfBlockerNG
Add additional dnsbl feeds listed at firebog.net to feeds.json. Only add green and blue without strikethrough (strike... Matthew Hildebrand
07:10 PM Revision acb79de0: Ticket #8136: Make sure dpinger is configured
Improve solution applied in 37194aa24e calling setup_gateways_monitor()
instead of running rc.newwanipv6
Renato Botelho
06:33 PM Revision 37194aa2: Ticket #8136: Reconfigure dpinger when IPv6 reconnects
When SLAAC interface is disconnected and reconnected, rc.newwanipv6 is
never executed because dhcp6c is the only trig...
Renato Botelho
06:17 PM Bug #11021 (Resolved): ral(4) driver kernel panics in arm64
Testing with an RT2700e card:... Steve Wheeler
06:11 PM Revision c909609c: Disable accept_rtadv flag when remove IPv6 from interface
Renato Botelho
06:02 PM Revision bf335b2b: Revert "Remove non captive-portal logs from Local4 syslog facility."
This reverts commit 6960993dc53c559619fe3f8d8ea903e7730b4fa6. Renato Botelho
05:21 PM Revision f1fcc3ce: Revert "Adjust some missing ident on syslog"
This reverts commit 12719a87e3ba77f5459938a4cfec7f007bbe0c4a. Renato Botelho
05:21 PM Revision ac40d093: Revert "Add rtsold logs to dhcpd.log"
This reverts commit c37ea049dcc8ea490278fe4414847012300c4e96. Renato Botelho
04:02 PM Todo #11020 (Resolved): Update OpenVPN to 2.5.0
Update OpenVPN to 2.5.0 and make necessary adjustments, including:
* Add ability to create network interfaces for VL...
Matthew Ray
03:45 PM pfSense Docs Correction #11019 (Rejected): Feedback on pfSense Configuration Recipes — Configuring a Single Multi-Purpose OpenVPN Instance
That whole thing needs rewritten for subnet topology, it has several outdated techniques. If routes need to be added ... Jim Pingle
03:38 PM pfSense Docs Correction #11019 (Rejected): Feedback on pfSense Configuration Recipes — Configuring a Single Multi-Purpose OpenVPN Instance
*Page:* https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-multi-purpose.html
*Feedback:*
On the "OpenVPN...
Marcos M
03:20 PM Bug #11018 (Resolved): Hostname is ignored when DNS Lookup calculates response time
When performing a DNS Lookup from diag_dns.php, the page performs a response time test by using @drill@, but the vari... Jim Pingle
01:50 PM pfSense Packages Feature #11008: Add option to mail report pkg to skip sending email if no output
2.4.5 PR has also been merged. Thanks! Renato Botelho
01:34 PM pfSense Packages Feature #11008: Add option to mail report pkg to skip sending email if no output
Pull Request to 2.4.5. https://github.com/pfsense/FreeBSD-ports/pull/976 Matthew Hildebrand
01:45 PM Revision 664fcdcc: Remove line commented out in 2015
Renato Botelho
01:41 PM Revision af6be5f3: Remove dhcp6c without RA script when not used
Renato Botelho
01:36 PM Bug #8136 (Feedback): dpinger for WAN DHCPv6 gets fails to update gateway IP
This problem should not happen in this case if you check the option "Use IPv4 connectivity as parent interface". Cou... Renato Botelho
08:24 AM Bug #8136 (In Progress): dpinger for WAN DHCPv6 gets fails to update gateway IP
Renato Botelho
01:33 PM Bug #9349 (Confirmed): IPSec service start/stop/restart fails after settings change
I can still reproduce this on 2.5.0.
* Navigate to VPN > IPsec > Advanced
* Make a change, click Save
* Try to s...
Jim Pingle
01:21 PM Revision 13fde8fa: Fix #11005: Allow to request PD with no track ifs
Allow DHCP6 to solicit PD even when no interfaces are tracking Renato Botelho
01:21 PM Revision 81ed0cf5: Check correct value and fix regression introduced by 9eae3005e1200319a14d6ebafe92c52885bf1cfd
Renato Botelho
01:19 PM Feature #9768 (Duplicate): IPsec for site-to-site scenario where one side has dynamic ip
Jim Pingle
01:13 PM Revision dd2fd981: Revert "Fix monitor address on correct variable"
This reverts commit 9eae3005e1200319a14d6ebafe92c52885bf1cfd. Renato Botelho
12:57 PM Revision ab03cc9a: Revert "Revert "Request PD even if no interfaces are set to track6 (Bug #4544)""
This reverts commit 51d1aca9859f980ca53f606c9f3696e7b9901125. Renato Botelho
10:54 AM pfSense Docs New Content #10774 (Resolved): Feedback on Installing and Upgrading — Upgrade Troubleshooting
Jim Pingle
10:52 AM pfSense Docs New Content #10774 (New): Feedback on Installing and Upgrading — Upgrade Troubleshooting
Jim Pingle
09:53 AM Bug #11017: Incorrect synchronizetoip value causing XMLRPC errors
noticed now but can be the same reason as/a duplicate of
https://redmine.pfsense.org/issues/11014
Manuel Piovan
06:13 AM Bug #11017: Incorrect synchronizetoip value causing XMLRPC errors
https://forum.netgate.com/topic/157998/error-installing-stunnel-package
https://forum.netgate.com/topic/158001/upgra...
Manuel Piovan
06:12 AM Bug #11017 (Resolved): Incorrect synchronizetoip value causing XMLRPC errors
install or updating stunnel 5.50_5
was working on the previus version...
Manuel Piovan
09:33 AM Bug #10986 (Resolved): dynamic interface address for 1:1 NAT works incorrectly in some dual-stack cases
Tested on:... Danilo Zrenjanin
09:22 AM Bug #8377 (Duplicate): Traffic graph widget mouse over always shows b/s even when the value is in B/s
Jim Pingle
08:30 AM Bug #11005: IPv6 Prefix Delegation not requested if no interfaces set to track6
Applied in changeset commit:13fde8fabb8e7ad6bc588b13504ad1068e4c45ba. Renato Botelho
08:24 AM Bug #11005: IPv6 Prefix Delegation not requested if no interfaces set to track6
Resolved now. Renato Botelho
08:23 AM Bug #4544 (Resolved): PD not requested if no interfaces set to track6
Patch was re-applied and this ticket remains the same Renato Botelho
08:17 AM Bug #10325 (New): System/Advanced/Notifications/E-Mail - SMTP Notification E-Mail auth password Unexpected Bahaviour
Jim Pingle
08:12 AM Bug #10325: System/Advanced/Notifications/E-Mail - SMTP Notification E-Mail auth password Unexpected Bahaviour
Tested on:... Danilo Zrenjanin
07:53 AM Feature #11016 (Rejected): Openvpn remove "status" file after service close
It's an unsupported directive. Code won't be added to pfSense to manage a file for it.
Use the management interfac...
Jim Pingle
07:02 AM Bug #10968 (Resolved): Mixed & Upper case Alias table names broken.
Tested on:... Danilo Zrenjanin
12:55 AM Bug #11015: Unable to use double quotes in openvpn custom options
Well, yes you are right. But it's confusing as openvpn's config file format has no semicolons, the example also has n... Todor K
 

Also available in: Atom