Activity
From 05/27/2021 to 06/25/2021
06/25/2021
-
04:25 PM pfSense Packages Bug #11459 (Resolved): pfBlockerNG doesn't include WireGuard interface in outbound floating rules
- After enabling the Wireguard service, the system automatically creates an interface group with the name WireGuard (Fi...
-
04:03 PM pfSense Packages Bug #11878 (Resolved): squidguard dependencies missing
- Tested on:...
-
03:55 PM pfSense Packages Bug #12073: ``netsnmptrapd.conf`` syntax for ``snmpTrapdAddr`` is wrong
- Tested on :...
-
03:19 PM pfSense Packages Bug #12080: Setting a route-map to redistribute in BGP leads to invalid configuration preventing frr from starting
- https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/98
-
03:14 PM pfSense Packages Bug #12080 (Resolved): Setting a route-map to redistribute in BGP leads to invalid configuration preventing frr from starting
- Selecting a route map under @Services / FRR BGP // Network Distribution / Redistribute Local@ results in an invalid @...
-
02:52 PM Bug #12079 (Closed): Kernel panic when running IGMP Proxy: Sleeping thread owns a non-sleepable lock
- IGMPProxy can trigger a kernel panic in 2.5.2-RC....
-
01:57 PM Bug #10956: Panic configuring LAGG+VLAN interfaces when using a kernel with ``INVARIANTS``.
- Updating subject but excluding from release notes since it wouldn't affect any potential release, only debugging kern...
-
01:54 PM Bug #10956 (New): Panic configuring LAGG+VLAN interfaces when using a kernel with ``INVARIANTS``.
- A fix has been committed to FreeBSD, we will make sure it gets into 2.5.2....
-
12:55 PM Regression #11910: IPsec status tunnel descriptions are incorrect
- Also in another setup, just having two VTI tunnels seems to do the same thing. See image attached.
-
12:04 PM Bug #11960: Gateway Monitoring Traffic Goes Out Default Gateway
- UPDATE! Bug only exists upon "link down"
+SETUP:+
# Dual WAN connections
# GW group configured as
## failover... -
10:03 AM Feature #9092 (Pull Request Review): Option to set interval of forced Dynamic DNS updates
-
07:38 AM Bug #12075: Changes to an existing IPsec configuration are not applied on HA secondary after XMLRPC sync
- Copied from my comments on the PR:
Skipping entries negates the entire point of doing the configure during XMLRPC ... -
07:38 AM Bug #12075 (Pull Request Review): Changes to an existing IPsec configuration are not applied on HA secondary after XMLRPC sync
-
03:21 AM Bug #12075: Changes to an existing IPsec configuration are not applied on HA secondary after XMLRPC sync
- PH1 entries with BACKUP VIP or VIPs aliased to BACKUP CARP must be skipped in `ipsec_get_phase1_src()` (see also http...
-
03:12 AM Bug #12075: Changes to an existing IPsec configuration are not applied on HA secondary after XMLRPC sync
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/292
-
07:33 AM Bug #12078 (Not a Bug): DNS Resolution Behavior does not consider named when setting localhost
- Since named is a package, it doesn't integrate into base in that way by design. If someone wants to set that up and u...
-
01:49 AM Bug #12072: FQDN L2TP server address is only resolved at boot
- works as expected as reported on the forum:
https://forum.netgate.com/topic/164614/pfsense-2-4-5-p1-l2tp-server-ip-r...
06/24/2021
-
11:52 PM pfSense Packages Bug #12031: Wireguard Package Produces Crash in 2.5.2
no crash report after installing WireGuard .
2.6.0.a.20210624.0100
WireGuard ver. 0.1.3-
07:24 PM Revision 7fededa1: Revert "Welcome pfSense CE 2.5.2-RELEASE"
- This reverts commit 6bc442e71f8061aaae5cf29e106305f20697e1d5.
-
07:24 PM Revision 2e248c0e: Move FreeBSD-src back to RELENG_2_5_0
-
07:23 PM Revision e0e318ad: Revert "schedule: Use the new multi-label support"
- This reverts commit 765277ba6d873847c6c5b5657877e9fb0cec4357.
-
07:23 PM Revision 54f72904: Revert "Tell pf to keep counter values"
- This reverts commit 0b817201399fb7252aeb09eca94362618728183f.
-
07:23 PM Revision 23253139: Revert "Use 'tos' rather than 'dscp' keyword for pf DSCP matching"
- This reverts commit 27a8acbb5455c3b3516d844024d9208ef23649bf.
-
07:23 PM Revision 4ea084cc: Revert "Correct pfctl syntax to kill by label. Fixes #12040"
- This reverts commit 21fb5288f829b7efcad71c0610df3cf6cb2fba81.
-
04:19 PM Bug #12078 (Not a Bug): DNS Resolution Behavior does not consider named when setting localhost
- With dnsmasq and unbound disabled, and instead using Bind/named, the setting @DNS Resolution Behavior@ under @System ...
-
02:53 PM Regression #11910: IPsec status tunnel descriptions are incorrect
- Another scenario which may be related to whatever root cause this is:
While DPD is happening, i.e. waiting for the... -
02:23 PM Bug #12071: Responder Only IPsec tunnel tries to connect on secondary node when a failover happens in HA
- Yes, DPD does have to timeout (which can take several minutes), unfortunately by the time the primary goes into BACKU...
-
02:10 PM Bug #12071 (Closed): Responder Only IPsec tunnel tries to connect on secondary node when a failover happens in HA
-
02:09 PM Bug #12071: Responder Only IPsec tunnel tries to connect on secondary node when a failover happens in HA
- I re-tested this and indeed the issue is the "apply-after-sync" behavior.
Further testing explained the following ... -
02:15 PM Bug #12075: Changes to an existing IPsec configuration are not applied on HA secondary after XMLRPC sync
- Perhaps it could be treated similarly to FRR and OpenVPN where the secondary checks whether its interface is CARP, an...
- 01:32 PM Revision daaa7474: Changes requested
- - if formatting
- removing temporary variable -
12:05 PM pfSense Packages Bug #11887 (Feedback): Squid service starts twice by /etc/rc.start_packages
- PR has been merged. Thanks!
-
12:05 PM pfSense Packages Bug #11711 (Feedback): New Squid Status Page Non-Functional
- PR has been merged. Thanks!
-
12:03 PM pfSense Packages Bug #11878 (Feedback): squidguard dependencies missing
- PR merged on 2.6.0 CE. Thanks
-
08:45 AM Feature #12077 (New): Allow stick-connections per gateway group
- Currently the Sticky Connections option for load-balance gateway groups is globally applied.
However it's actually... -
07:30 AM Bug #6507 (Pull Request Review): GRE and GIF tunnels on dynamic IPv6 interface are not brought up during boot
-
06:56 AM Bug #6507: GRE and GIF tunnels on dynamic IPv6 interface are not brought up during boot
- small fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/291 -
07:29 AM Bug #12072 (Pull Request Review): FQDN L2TP server address is only resolved at boot
-
06:51 AM Bug #12072: FQDN L2TP server address is only resolved at boot
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/290 -
07:22 AM pfSense Packages Bug #12065 (Feedback): PHP crash when creating a new report in mailreport 3.6.3_2
- PR has been merged. Thanks!
-
06:43 AM Regression #12069: Panic in ``pfctl`` with large numbers of states
- This issue doesn't have anything to do with Unbound directly. The screenshots I added above were from a system which ...
-
05:34 AM Regression #12069: Panic in ``pfctl`` with large numbers of states
- Issue unlikely to be limited to or related to Unbound. Unbound was mentioned originally in the context that it is a g...
-
05:22 AM Regression #12069: Panic in ``pfctl`` with large numbers of states
- I have more details...
I unplug LAN and WAN cable and wait 4-5 minutes.... Then I plug them both in. After few sec... -
12:18 AM Bug #12076: OpenVPN RADIUS-based firewall rules do not use expected value for RADIUS-assigned IP addresses
- https://github.com/pfsense/pfsense/pull/4526
06/23/2021
- 09:13 PM Revision 6e8c4db2: Cisco-AVPair + Framed-IP-Address: correcting clientip
- Workaround to substitute Framed-IP-Address value in Cisco-AVPair ACL's where {clientip} is used
-
05:23 PM Revision d1b2d749: Merge pull request #4522 from fl0l0u/patch-1
-
05:23 PM Revision 994699bd: Merge pull request #4524 from raphendyr/feature-dyndns-leeway
-
05:23 PM Revision 170b1df3: Merge pull request #4510 from BBcan177/patch-2
-
05:08 PM Revision fe7667b0: Merge pull request #4523 from raphendyr/cleanup-dyndns
-
04:24 PM Bug #12076 (Resolved): OpenVPN RADIUS-based firewall rules do not use expected value for RADIUS-assigned IP addresses
- Current OpenVPN script implemented to trigger Cisco-AVPair ACL in PF chains allows the ...
-
03:40 PM Regression #12069: Panic in ``pfctl`` with large numbers of states
- Retested on pfSense+ 21.05. Found the systems still pass traffic, even with 7.1M states.
pfSenseCE 2.5.2 did no... -
03:11 PM Regression #12069: Panic in ``pfctl`` with large numbers of states
- Additional panic output from a system in the test lab with >1M states
-
01:08 PM Regression #12069: Panic in ``pfctl`` with large numbers of states
- I can reproduce this now but it took a few tries.
Here is what I did:
First, set the firewall to conservative m... -
03:35 PM Bug #12071: Responder Only IPsec tunnel tries to connect on secondary node when a failover happens in HA
- Since the apply-after-sync thing seems to be its own legitimate issue, I created #12075 for it. If this turns out to ...
-
03:17 PM Bug #12071 (Feedback): Responder Only IPsec tunnel tries to connect on secondary node when a failover happens in HA
- I can't reproduce this as stated, at least on 2.5.2. I set the HA pair as responder only and set the far side to alwa...
-
03:34 PM Bug #12075 (Resolved): Changes to an existing IPsec configuration are not applied on HA secondary after XMLRPC sync
- When synchronizing settings over XMLRPC, the secondary only reconfigures the IPsec daemon if IPsec is enabled or disa...
-
02:34 PM pfSense Packages Bug #12074: Freeradius: Additional Information field descriptions swapped
- https://gitlab.netgate.com/pfSense/factory-ports/-/merge_requests/6
-
02:00 PM pfSense Packages Bug #12074 (Resolved): Freeradius: Additional Information field descriptions swapped
- In Freeradius > Settings > Logging Configuration the field descriptions for 'Additional Information for Bad Attempts'...
-
01:12 PM pfSense Packages Bug #12031 (Feedback): Wireguard Package Produces Crash in 2.5.2
- WireGuard package version 1.1.3 was merged into 2.6.0 and 2.5.2
-
01:12 PM pfSense Packages Bug #11950 (Feedback): Wireguard Package Errors and DNS problem
- WireGuard package version 1.1.3 was merged into 2.6.0 and 2.5.2
-
12:23 PM Bug #11701 (Feedback): Missing global ``$g`` declaration in ``config.lib.inc`` function ``pfSense_clear_globals()``
- PR has been merged. Thanks!
-
12:23 PM Bug #12007 (Feedback): Dynamic DNS cache expiration time check calculation method may cause update to happen on the wrong day
- PR has been merged. Thanks!
-
12:23 PM Bug #12020 (Feedback): OpenVPN RADIUS-based firewall rules use incorrect port ranges
- PR has been merged. Thanks!
-
12:09 PM Todo #11976 (Feedback): Compliance with pfSense style guide in Dynamic DNS service code
- PR has been merged. Thanks!
-
10:10 AM pfSense Packages Bug #11687 (Feedback): Fix download URLs for SecuriteInfo.com
- PR has been merged. Thanks!
-
10:09 AM pfSense Packages Bug #12073 (Feedback): ``netsnmptrapd.conf`` syntax for ``snmpTrapdAddr`` is wrong
- PR has been merged. Thanks!
-
10:07 AM pfSense Packages Bug #12073 (New): ``netsnmptrapd.conf`` syntax for ``snmpTrapdAddr`` is wrong
- The snmptrapd configuration uses the keyword "snmpTrapdAddr" instead of
"agentaddress". This is probably a copy-past... -
10:03 AM pfSense Packages Feature #11310 (Feedback): Adding a widget to apcupsd plug-in
- PR has been merged to CE 2.6.0 so we can get it tested and then cherry-pick to stable branches
-
09:50 AM pfSense Packages Feature #11948 (Feedback): ACME: Support specifying non-default port for nsupdate DNS validation method
- PR has been merged. Thanks!
-
09:41 AM Bug #9362: rc.dyndns.update: Cloudflare DDNS with proxy enabled doesn't work at all
- thx for the patch Robert R. :)
-
09:22 AM Bug #12072: FQDN L2TP server address is only resolved at boot
- we need to restart the L2TP/PPTP interfaces that use WAN as parent on /etc/rc.newwanip event
like GRE/GIF: https://g... -
05:45 AM Bug #12072 (Resolved): FQDN L2TP server address is only resolved at boot
- Hello!
Im using "russian vpn" scheme to connect with ISP - WAN interface with DHCP (actually internal ISP network)... -
08:01 AM pfSense Packages Bug #9895: snort reinstallation failed
- Viktor Gurov wrote:
> same issue on 2.6.0.a.20210622.0100:
> [...]
>
> Another solution: https://forum.netgate.c... -
06:18 AM pfSense Packages Bug #9895: snort reinstallation failed
- same issue on 2.6.0.a.20210622.0100:...
-
07:05 AM pfSense Docs Correction #11735 (Closed): Feedback on Hardware — Hardware Tuning and Troubleshooting
-
07:01 AM pfSense Packages Feature #11210: 3rd party rulesets
- >
> For example https://sslbl.abuse.ch/blacklist/#ssl-certificates-suricata
- added to 6.0.0_11
see https://for... -
05:44 AM pfSense Packages Bug #11459: pfBlockerNG doesn't include WireGuard interface in outbound floating rules
- You will need to assign the WireGuard tunnel to a pfSense interface. pfBlocker can't 'see' unassigned WireGuard tunnels.
06/22/2021
-
07:58 PM Bug #12071 (Closed): Responder Only IPsec tunnel tries to connect on secondary node when a failover happens in HA
- Normally with an IPsec tunnel on a pfSense HA setup, failing over to the secondary makes the IPsec start on the new m...
-
04:24 PM pfSense Docs Correction #11735: Feedback on Hardware — Hardware Tuning and Troubleshooting
- Looks good.
-
02:35 PM pfSense Docs Correction #11735: Feedback on Hardware — Hardware Tuning and Troubleshooting
- Check the doc again now.
Should be better.
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/1a8fd83fbc4bc389... -
02:59 PM Feature #12070 (Resolved): Support for VLAN ``0``
- Hello, I'm not sure if this should be a bug or feature request. Internet fiber providers in the USA and abroad tag th...
-
12:45 PM Bug #12061 (Closed): Update NGINX to address CVE-2021-23017
- @nginx-1.20.1,2@ is in the latest test build. GUI, XMLRPC, and captive portal are all working as expected.
While I... -
12:07 PM pfSense Packages Bug #12065 (Pull Request Review): PHP crash when creating a new report in mailreport 3.6.3_2
-
10:50 AM pfSense Packages Bug #12065: PHP crash when creating a new report in mailreport 3.6.3_2
- fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/96 -
08:48 AM pfSense Packages Bug #11766 (Feedback): Certificate no more pointed "in use" by haproxy
- PR has been merged. Thanks!
-
08:48 AM pfSense Packages Bug #11937 (Feedback): HAproxy "Use Client-IP" option breaks Captive Portal
- PR has been merged. Thanks!
-
08:47 AM pfSense Packages Feature #10779 (Feedback): HAProxy SSL/TLS Compatibility Mode
- PR has been merged. Thanks!
-
08:46 AM pfSense Packages Bug #11491 (Feedback): haproxy-devel v0.62_2 - startup error 'httpchk'
- PR has been merged. Thanks!
-
08:46 AM pfSense Packages Feature #10739 (Feedback): Update HAproxy-devel package to 2.2 and HAproxy to 2.0
- PR has been merged. Thanks!
-
08:44 AM pfSense Packages Bug #11993 (Feedback): PHP error after disabling HAProxy
- PR has been merged. Thanks!
-
08:39 AM pfSense Packages Bug #6235 (Resolved): Snort sometimes crashes during rule update process (specifically related to VRT .so rule update?)
- PR has been merged
-
08:38 AM pfSense Packages Bug #11637 (Resolved): Preprocs - possible to create two defaults
- PR has been merged
-
08:20 AM pfSense Plus Bug #12068 (Not a Bug): Upgrade to 21.05 fails with seg fault
- There is not enough information here to classify that as a bug, and there are numerous others who have upgraded succe...
-
01:44 AM pfSense Plus Bug #12068 (Not a Bug): Upgrade to 21.05 fails with seg fault
- When trying to upgrade the sg3100 to 21.05 (from 21.02.2). The upgrade fails during the system reload during the "con...
-
07:29 AM Regression #12069 (Resolved): Panic in ``pfctl`` with large numbers of states
- Only "one report of this so far":https://forum.netgate.com/post/988755, so it's unclear how many it may affect. User ...
06/21/2021
-
11:38 PM Revision 6bc442e7: Welcome pfSense CE 2.5.2-RELEASE
-
09:31 PM pfSense Docs Correction #11735: Feedback on Hardware — Hardware Tuning and Troubleshooting
- Of note, @hw.ix.flow_control=0@ in @loader.conf.local@ can still be used, though it's probably best to keep it as dev...
-
03:43 PM pfSense Docs Correction #11735 (Feedback): Feedback on Hardware — Hardware Tuning and Troubleshooting
- Updated as a part of https://gitlab.netgate.com/docs/pfSense-docs/-/commit/35e2d56cc2f1021b58ee71135d99d371e332af1e
-
12:53 PM pfSense Docs Correction #11735 (In Progress): Feedback on Hardware — Hardware Tuning and Troubleshooting
-
06:37 PM Bug #12061 (Feedback): Update NGINX to address CVE-2021-23017
- I've cherry-picked commits to upgrade it to 1.20.1,2 on RELENG_2_5_2. Development branches will get it on next round...
-
03:43 PM pfSense Docs Correction #9228 (Feedback): Feedback on Hardware — Hardware Sizing Guidance
- Updated as a part of https://gitlab.netgate.com/docs/pfSense-docs/-/commit/35e2d56cc2f1021b58ee71135d99d371e332af1e
... -
01:06 PM pfSense Docs Correction #9228 (In Progress): Feedback on Hardware — Hardware Sizing Guidance
-
03:43 PM pfSense Docs New Content #10225 (Feedback): Add cryptographic hardware info to the SG-3100 manual
- Not in the manual, but updated related info as a part of https://gitlab.netgate.com/docs/pfSense-docs/-/commit/35e2d5...
-
03:35 PM pfSense Docs New Content #10225 (In Progress): Add cryptographic hardware info to the SG-3100 manual
-
03:10 PM Bug #11960: Gateway Monitoring Traffic Goes Out Default Gateway
- Jim, Sorry for the delay but I've been out of the office a good bit the past month.
I've updated the SG-3100 to 21... -
10:29 AM pfSense Packages Bug #12031: Wireguard Package Produces Crash in 2.5.2
- Christian McDonald wrote:
> Hi all,
>
> Yes this fix (along with a ton of other fixes) are in the current PR.
... -
09:53 AM pfSense Packages Bug #12031: Wireguard Package Produces Crash in 2.5.2
- Hi all,
Yes this fix (along with a ton of other fixes) are in the current PR. -
09:12 AM pfSense Packages Bug #12031: Wireguard Package Produces Crash in 2.5.2
- Renato Botelho wrote:
> I'll take care of this one
FWIW, I've been running 0.1.2 _(over several minor revisions)_... -
08:53 AM pfSense Packages Bug #12031: Wireguard Package Produces Crash in 2.5.2
- I'll take care of this one
-
08:34 AM pfSense Packages Bug #12031: Wireguard Package Produces Crash in 2.5.2
- Kris Phillips wrote:
> Issue continues to be present in June 17th 2.5.2 RC build
It's already fixed in the latest... -
08:39 AM Bug #12067 (New): DHCP Monitoring Statistics Error
- I have 2 DHCP pool (51 + 51 IP address) in one network (see attachments screen)
But monitoring DHCP show maximum dhc... -
08:00 AM Bug #12049 (Pull Request Review): Input validation incorrectly rejects a second IPv4-only GRE tunnel
-
07:57 AM pfSense Packages Bug #12064 (Duplicate): Navbar not responsive when running iperf
- Duplicate of #8502
-
07:44 AM Feature #12066: Include man and man pages for all core programs and packages
- Currently we deliberately remove them to save on space, though these days space isn't at as much of a premium as it w...
-
06:46 AM Regression #11316: Unbound crashes with signal 11 when reloading
- As an ugly workaround, I'm using "Service Watchdog" package to restart *unbound* when it crashes. This happens every...
-
05:44 AM pfSense Packages Feature #12042: Add Zabbix 5.4 agent and proxy packages
- Hello, thanks for the work, how long until available ?
06/20/2021
-
07:41 AM pfSense Packages Bug #12030: Startup Errors for Avahi Package
- The service warnings are expected if you don't have publishing enabled. It's disabled by default.
See: https://forum...
06/19/2021
-
09:59 PM pfSense Packages Bug #12031: Wireguard Package Produces Crash in 2.5.2
- Issue continues to be present in June 17th 2.5.2 RC build
-
08:03 PM Bug #12050: "GoTo line #" function does not work on ``diag_edit.php``
- seems working -- tested on 21.09.a.20210619.0100
-
04:44 PM Feature #12066 (New): Include man and man pages for all core programs and packages
- Having the man pages - where available - for all out-of-the-box binaries would improve scenarios where there are no o...
-
01:45 PM pfSense Packages Bug #12065 (Resolved): PHP crash when creating a new report in mailreport 3.6.3_2
- When creating a new report in mail report 3.6.3_2 a PHP crash is generated. This is triggered as soon as you save the...
-
12:54 PM pfSense Packages Bug #12030: Startup Errors for Avahi Package
- This issue is still present in the June 17th build.
-
12:14 PM Bug #12039: Gateway alarm always triggers IPsec restart
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/289
https://gitlab.netgate.com/pfSense/FreeBSD-por... -
12:13 PM pfSense Packages Bug #12064 (Duplicate): Navbar not responsive when running iperf
- In iperf 3.0.2_5, after starting iperf client or server, the navbar is visible but clicking any of the dropdown menus...
-
02:51 AM Regression #12040 (Resolved): Scheduled firewall rules failing to load
- works as expected on 2.5.2.r.20210617.1709:...
-
12:27 AM Bug #12049: Input validation incorrectly rejects a second IPv4-only GRE tunnel
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/288
06/18/2021
-
10:02 PM Bug #11581 (Resolved): Cannot configure WAN IP address with ``/32`` CIDR mask via console menu
- I was able to assign IP address with/32 via console
*** Welcome to pfSense 2.6.0-DEVELOPMENT (amd64) on pfSense *... -
08:46 PM Bug #6055: Menu items may remain from packages no longer installed
- Chris Buechler wrote:
> Adrien Carlyle wrote:
> > Is there any way to manually correct this?
>
> Edit the <menu>... -
06:48 PM Revision 56ad99b3: Add PPP interface description to mpd config. Fixes #11959
-
06:42 PM Revision c2c11dcf: Interpret numeric-only addresses as invalid in is_hostname(). Fixes #12000
-
06:39 PM Revision 99f957fe: Insert Mobile IPsec NAT/BINAT rules into pf rule set. Fixes #12023
-
06:37 PM Revision 8abff49b: Certmanager UTF8 DN support. Fixes #12041
-
06:24 PM pfSense Docs New Content #12063 (Closed): Document recently added options for Configuring RFC 2136 Dynamic DNS updates
- *Page:* https://docs.netgate.com/pfsense/en/latest/services/dyndns/rfc2136.html
*Feedback:*
# @Zone@: Field not o... -
06:08 PM Revision afab96d6: Fix #12060: Remove ZeroMQ support
-
05:21 PM pfSense Docs Correction #12062 (Closed): Add Netgate 2100 and 6100 to Throughput Considerations table
- That whole page is going to go away: #9228
Once there is a static page we can link to with the numbers from the si... -
05:19 PM pfSense Docs Correction #12062 (Closed): Add Netgate 2100 and 6100 to Throughput Considerations table
- h2. Please add the Netgate 2100 and Netgate 6100 to the table on the "Throughput Considerations page":https://docs.ne...
-
03:36 PM pfSense Packages Bug #6235: Snort sometimes crashes during rule update process (specifically related to VRT .so rule update?)
- The Snort GUI package now has additional logic to ensure running Snort interfaces at the start of a rules update cycl...
-
03:33 PM pfSense Packages Bug #11637: Preprocs - possible to create two defaults
- The remaining GUI bug reported in this issue is fixed in this Snort GUI package Pull Request: https://github.com/pfs...
-
03:16 PM Bug #12022 (Resolved): Incorrect OpenVPN Client Export help link
- fixed
openvpn help points to https://docs.netgate.com/pfsense/en/latest/packages/openvpn-client-export.html
2.6... -
08:00 AM Bug #12022 (Feedback): Incorrect OpenVPN Client Export help link
- Applied in changeset commit:62c8a02a9cc6585579fda1e5ec68a1fdbfb0d129.
-
07:46 AM Bug #12022 (In Progress): Incorrect OpenVPN Client Export help link
- Looks like the help.php line is referencing the wrong file. I'll fix it.
-
02:44 AM Bug #12022: Incorrect OpenVPN Client Export help link
- Tested on:...
-
02:40 PM Revision 68d8e58c: Use full path for executables in /usr/local/sbin/ shell scripts. Fixes #11985
-
02:37 PM Revision 692510f2: Do not escape special characters in certificate DN fields. Fixes #12034
-
01:57 PM Feature #12011: Disable log compression on new installations when ``/var/log`` is a ZFS dataset with compression enabled
- I thought perhaps I could have the default be assumed as 'none' with ZFS but in practice that didn't go as well as I'...
-
01:55 PM Bug #11959: PPP interfaces lose the description field in ``ifconfig`` output when restarted
- Applied in changeset commit:56ad99b3989f0d6bcf1f16ac3eaf727ec6b6c901.
-
01:48 PM Bug #11959 (Feedback): PPP interfaces lose the description field in ``ifconfig`` output when restarted
- PR has been merged. Thanks!
-
01:55 PM Bug #12000: Remote log server input validation allows invalid values
- Applied in changeset commit:c2c11dcf6dd2b71d554d2870a39373e75c70e624.
-
01:45 PM Bug #12000 (Feedback): Remote log server input validation allows invalid values
- PR has been merged. Thanks!
-
01:45 PM Bug #12023: Mobile IPsec NAT/BINAT entries missing from firewall rules
- Applied in changeset commit:99f957fe21d514f9b2bb945fb07c0277df210d03.
-
01:39 PM Bug #12023 (Feedback): Mobile IPsec NAT/BINAT entries missing from firewall rules
- PR has been merged. Thanks!
-
01:45 PM Bug #12041: Certificate Manager shows incorrect DN for imported entries with UTF-8 encoding
- Applied in changeset commit:8abff49b82f6a8ee143cf10f939ed6ca2ad3d4d7.
-
01:38 PM Bug #12041 (Feedback): Certificate Manager shows incorrect DN for imported entries with UTF-8 encoding
- PR has been merged. Thanks!
-
01:15 PM Todo #12060 (Feedback): Remove deprecated ``libzmq`` code and references
- Applied in changeset commit:afab96d6b3bcc47e8fb5b2cd8cbe49d4aefe1a55.
-
01:00 PM Todo #12060 (Resolved): Remove deprecated ``libzmq`` code and references
- Once upon a time ZMQ was intended to be a potential logging or notification type, but that hasn't been touched in qui...
-
01:09 PM Bug #12061: Update NGINX to address CVE-2021-23017
- http://nginx.org/en/CHANGES shows it's fixed in 1.20.1, but 1.20.1 is not yet in the ports tree: https://github.com/f...
-
01:06 PM Bug #12061 (Closed): Update NGINX to address CVE-2021-23017
- https://vuxml.freebsd.org/freebsd/0882f019-bd60-11eb-9bdd-8c164567ca3c.html
NGINX needs to be updated to resolve t... -
12:50 PM Revision 62c8a02a: Correct OpenVPN export help URLs. Fixes #12022
-
12:11 PM Bug #12059 (Rejected): After about an hour DNSSEC lookups start to fail
- There isn't enough information to definitively identify this as a bug, and this site is not for support or diagnostic...
-
12:07 PM Bug #12059 (Rejected): After about an hour DNSSEC lookups start to fail
- After a fresh restart of the server or just unbound everything works great, in the below log paste I used idrive.com....
-
11:38 AM pfSense Packages Bug #12058 (Duplicate): pfBlockerNG / "Cannot allocate memory" from Geo blocking IP list
- My pfsense emailed me an error yesterday:
```
Notifications in this message: 1
================================
... -
11:16 AM Revision 33a37573: RRD DB CPU Temperature. Feature #9297
-
11:15 AM Revision 71024ca1: Remove package-related syslog configuration on uninstall. Fixes #11846
-
11:12 AM Revision 44144b37: Hide "Reboot and run a filesystem check" for ZFS systems. Implements #11983
-
11:11 AM Revision a0892760: Mute boot messages for inactive services. Issue #12038
-
11:04 AM Revision 4d934cc4: Do not try to stop disabled packages on shutdown. Fixes #12001
-
09:50 AM Todo #11985: Ensure ``/usr/local/sbin/`` scripts use full path to executable files
- Applied in changeset commit:68d8e58c9efd5d43aa0331fa72c4140161972e36.
-
09:41 AM Todo #11985 (Feedback): Ensure ``/usr/local/sbin/`` scripts use full path to executable files
- PR has been merged. Thanks!
-
09:45 AM Bug #12034: Certificate Manager performs redundant escaping of special characters in certificate DN fields
- Applied in changeset commit:692510f22097bc6100fde467d2f6b3aea8cd51bc.
-
09:39 AM Bug #12034 (Feedback): Certificate Manager performs redundant escaping of special characters in certificate DN fields
- PR has been merged. Thanks!
-
07:12 AM Bug #12034 (Pull Request Review): Certificate Manager performs redundant escaping of special characters in certificate DN fields
-
09:05 AM Feature #12055: Option to disable XMLRPC Sync for Loopback Virtual IPs
- Changing the sync default behavior would be a POLA violation as it would break users who rely on that behavior now.
... -
08:49 AM Feature #12055: Option to disable XMLRPC Sync for Loopback Virtual IPs
- That seems unnecessarily complex and counter-intuitive. If I go that route then I have a routable IP address on two d...
-
08:39 AM Feature #12055: Option to disable XMLRPC Sync for Loopback Virtual IPs
- Then set FRR differently on each node so it only advertises the addresses you want from each node. FRR does not suppo...
-
08:35 AM Feature #12055: Option to disable XMLRPC Sync for Loopback Virtual IPs
- They should be advertised though as the loopbacks serve as the primary management addresses for their corresponding n...
-
08:26 AM Feature #12055: Option to disable XMLRPC Sync for Loopback Virtual IPs
- Use the features built into the dynamic routing protocols to prevent those addresses from being advertised. That's th...
-
08:20 AM Feature #12055: Option to disable XMLRPC Sync for Loopback Virtual IPs
- The problem is that when you configure a loopback address, it's considered a directly connected network and will be a...
-
07:43 AM Feature #12055 (Feedback): Option to disable XMLRPC Sync for Loopback Virtual IPs
- While it is capable of receiving traffic from another host, nothing could ARP for it, so it can't "conflict" as other...
-
08:34 AM Regression #12057: 21.09/2.6.0 - High CPU usage and slowness with ``pfctl -ss``
- As I mentioned on #12045 we are aware and it will be automatically addressed during the next upstream sync. 2.6.0 is ...
-
08:28 AM Regression #12057 (Resolved): 21.09/2.6.0 - High CPU usage and slowness with ``pfctl -ss``
- pfctl -ss is taking consuming large amounts of CPU and taking much longer than it should to output data on 2.6:
ht... -
08:27 AM Regression #12045: High CPU usage and slowness with ``pfctl -ss``
- Yes, we are aware, but 2.6.0 will get the fix when we do a full sync with FreeBSD sources next, which wasn't an optio...
-
08:23 AM Regression #12045: High CPU usage and slowness with ``pfctl -ss``
- 2.6 has the same problem. This fix needs to be applied there too.
https://www.reddit.com/r/PFSENSE/comments/nz8fm... -
07:37 AM pfSense Packages Bug #12054 (Feedback): "succesfully" misspelled
- Pushed a fix. The typo was repeated a total of three times in there, actually.
-
07:28 AM pfSense Plus Bug #12053 (Feedback): PRF Algorithm is Always Set to SHA256 on New Tunnel Creations
- I can't reproduce this here. I see the config.xml tag @<prf-algorithm>sha256</prf-algorithm>@ but it does not get put...
-
06:25 AM Bug #11846: Logging configuration added by a package is not removed on uninstall
- Applied in changeset commit:71024ca1064fe21145d7402ec5abc05360558f5e.
-
06:15 AM Bug #11846 (Feedback): Logging configuration added by a package is not removed on uninstall
- PR has been merged. Thanks!
-
06:20 AM Todo #11983: Hide "Reboot and run a filesystem check" for ZFS systems
- Applied in changeset commit:44144b377d3282f8e95c676e8fae1d343ba3f8b7.
-
06:13 AM Todo #11983 (Feedback): Hide "Reboot and run a filesystem check" for ZFS systems
- PR has been merged. Thanks!
-
06:17 AM Feature #9297 (Feedback): Graph for hardware temperature readings
- PR has been merged. Thanks!
-
06:12 AM Bug #12038 (Feedback): System attempts to start inactive services at boot
- PR has been merged. Thanks!
-
06:10 AM Bug #12001: System attempts to stop inactive services at shutdown
- Applied in changeset commit:4d934cc48211f4b746da6de57e6e888104694f22.
-
06:04 AM Bug #12001 (Feedback): System attempts to stop inactive services at shutdown
- PR has been merged. Thanks!
-
05:51 AM Bug #12056 (Pull Request Review): Filterlog says "Unknown Option %u"
- I see the following messages in my filter logs:...
-
05:09 AM Regression #12048: Error during XMLRPC synchronization due to changes in ``pear-HTTP_Request2``
- I've created an upstream issue at https://github.com/pear/HTTP_Request2/issues/23
-
04:59 AM Regression #11910: IPsec status tunnel descriptions are incorrect
- Kris Phillips wrote:
> Saw this yesterday. Customer has the following:
>
> 3 P1s, 2 were IKEv1 and 1 was IKEv2
... -
04:34 AM Bug #11926 (Resolved): Advanced DHCP client configuration "Protocol timing" help text is in the wrong location
- Tested on:...
06/17/2021
-
10:47 PM Feature #12055: Option to disable XMLRPC Sync for Loopback Virtual IPs
- Forgot the doc link - here it is: https://docs.netgate.com/pfsense/en/latest/firewall/virtual-ip-addresses.html
-
10:46 PM Feature #12055 (Closed): Option to disable XMLRPC Sync for Loopback Virtual IPs
- According to this pfSense doc, Loopback IPs are synchronized via XMLRPC because they are only ever active on the loca...
-
08:53 PM pfSense Packages Bug #12054 (Resolved): "succesfully" misspelled
- When fetching a patch, the message "Patch fetched succesfully" is missing an S.
-
07:55 PM pfSense Plus Bug #12053: PRF Algorithm is Always Set to SHA256 on New Tunnel Creations
- Selection feature was introduced in changeset f5ddbec114b3b9ecce14761d173381556422061b
-
07:52 PM pfSense Plus Bug #12053: PRF Algorithm is Always Set to SHA256 on New Tunnel Creations
- Reference internal ticket INC-87329 for troubleshooting steps with customer that experienced this.
-
07:51 PM pfSense Plus Bug #12053 (Closed): PRF Algorithm is Always Set to SHA256 on New Tunnel Creations
- When creating new P1s regardless of what the hash algorithm is set to the variable in config.xml is always set to <pr...
-
07:28 PM Regression #12048 (New): Error during XMLRPC synchronization due to changes in ``pear-HTTP_Request2``
- Latest 2.5.2 build looks good with pear-HTTP_Request2 2.3.0,1.
Moving this ahead to 2.6.0 for (hopefully) a long t... -
04:29 PM Regression #12048 (Feedback): Error during XMLRPC synchronization due to changes in ``pear-HTTP_Request2``
- pear-HTTP_Request2 downgraded to 2.3.0,1
-
01:56 PM Regression #12048: Error during XMLRPC synchronization due to changes in ``pear-HTTP_Request2``
- Jim Pingle wrote:
> I have been able to narrow this down further to this change:
>
> [...]
>
> If I go back to... -
01:16 PM Regression #12048: Error during XMLRPC synchronization due to changes in ``pear-HTTP_Request2``
- I have been able to narrow this down further to this change:...
-
12:50 PM Regression #12048: Error during XMLRPC synchronization due to changes in ``pear-HTTP_Request2``
- After checking many, many different things (SSL, crypto settings, nginx settings, and more) I went back and tried old...
-
07:00 PM Revision 9455c6ef: XMLRPC sync improvements. Implements #12051
-
06:04 PM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- I can confirm that applying the PCRE_JIT patch fixed this problem for me on 21.05.
-
05:44 PM Revision f0e84135: Moves the help text to the appropriate place. Issue #11926
-
05:34 PM Revision 760d4d13: Build QEMU Guest Agent. Feature #9877
-
05:10 PM Revision cf11a8a5: Allow to swith to Persistent Maintenance Mode if CARP is disabled. Fixes #11727
-
05:08 PM Revision 97762ce9: Enable build of zabbix 5.4 packages
-
05:04 PM Revision 4e3ab7d2: Add Zabbix 5.4 config options. Feature #12042
- 04:06 PM Revision 1b910463: Fixed #12050 by adding new JumpToLine() function and calling as needed
-
03:02 PM Regression #12052 (Resolved): IPsec status IKE disconnect button drops all connections for the IKE ID, not a specific IKE SA ID
- *Plataform:*
Version 2.5.1-RELEASE (amd64) on VMWare
built on Mon Apr 12 07:50:14 EDT 2021
FreeBSD 12.2-STABLE
... -
02:10 PM Todo #12051 (Feedback): XMLRPC client improvements
- Applied in changeset commit:9455c6ef8fa512b9341885c2186f7a79ac59cf2b.
-
01:52 PM Todo #12051 (Resolved): XMLRPC client improvements
- There are a few changes that could be beneficial for the XMLRPC sync client:
* The same client can be reused for m... -
12:44 PM Bug #11926 (Feedback): Advanced DHCP client configuration "Protocol timing" help text is in the wrong location
- PR has been merged. Thanks!
-
12:35 PM Feature #9877 (Feedback): QEMU Guest Agent
- PR has been merged. Thanks!
-
12:20 PM Bug #11727: Cannot enter persistent CARP maintenance mode when CARP is disabled
- Applied in changeset commit:cf11a8a5b5752cdf3b4739b1ae1ed56e197705c3.
-
12:12 PM Bug #11727 (Feedback): Cannot enter persistent CARP maintenance mode when CARP is disabled
- PR has been merged. Thanks!
-
12:09 PM pfSense Packages Feature #12042 (Feedback): Add Zabbix 5.4 agent and proxy packages
- PRs merged. Thanks!
I also enabled the build on poudriere_bulk for CE 2.6.0 -
11:15 AM Bug #12050: "GoTo line #" function does not work on ``diag_edit.php``
- Applied in changeset commit:1b9104637f304697ec714d8b6ceb8f95466b52b1.
-
11:08 AM Bug #12050 (Feedback): "GoTo line #" function does not work on ``diag_edit.php``
- Functionality provided via new JS function jumpToLine() called when requesting GoTo line
-
11:05 AM Bug #12050 (Resolved): "GoTo line #" function does not work on ``diag_edit.php``
- When entering a value in the GoTo line # field, the requested line is highlighted, but the textarea does not scroll t...
-
10:59 AM Regression #11910: IPsec status tunnel descriptions are incorrect
- Saw this yesterday. Customer has the following:
3 P1s, 2 were IKEv1 and 1 was IKEv2
3 P2s, the 2 for the IKEv1 w... -
10:58 AM Revision dff043e9: Revert "Enable build of Telegraf on armv7"
- This reverts commit 99e7f9ec562cb3a0f614c60ae7813d8318cdff17.
-
10:29 AM Bug #12049: Input validation incorrectly rejects a second IPv4-only GRE tunnel
- This is not a regression. Too late for 2.5.2
-
04:20 AM Bug #12049 (Resolved): Input validation incorrectly rejects a second IPv4-only GRE tunnel
- More info:
-> This only occurs when creating A 2ND SUCH TUNNEL FOR THE SAME "Parent Interface"
-> The "GRE-tu... -
10:21 AM Revision 99e7f9ec: Enable build of Telegraf on armv7
-
08:02 AM Bug #11850: NTP authentication input validation rejects valid keys
- Thanks the effort made.
Just want to confirm: in *21.05-RELEASE* it works now as expected. -
06:32 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
- Charles Jackson wrote:
> I've managed to get two XBoX's and a gaming PC on my network and one Xbox and the PC to con...
06/16/2021
-
05:00 PM Revision b2a8595c: Fix filename
-
02:03 PM Revision 21fb5288: Correct pfctl syntax to kill by label. Fixes #12040
- (cherry picked from commit 2afcd4527d4b245c7968bf7ac6b6c505259fe6c9)
-
02:02 PM Revision 2afcd452: Correct pfctl syntax to kill by label. Fixes #12040
-
01:57 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
- Charles Jackson wrote:
> I've managed to get two XBoX's and a gaming PC on my network and one Xbox and the PC to con... -
01:46 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
- I've managed to get two XBoX's and a gaming PC on my network and one Xbox and the PC to connect to and play the same ...
-
12:04 PM pfSense Packages Feature #12042: Add Zabbix 5.4 agent and proxy packages
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/287
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-... -
09:58 AM Regression #12048 (Confirmed): Error during XMLRPC synchronization due to changes in ``pear-HTTP_Request2``
- At first I couldn't reproduce it, but now I can every time. Not sure what changed. It didn't show up in the logs or n...
-
07:20 AM Regression #12048 (Rejected): Error during XMLRPC synchronization due to changes in ``pear-HTTP_Request2``
- I cannot replicate the problem as stated and nothing changed between the previous builds which would have impacted XM...
-
03:08 AM Regression #12048 (Closed): Error during XMLRPC synchronization due to changes in ``pear-HTTP_Request2``
- I've just update the test PfSense cluster to release
2.5.2.r.20210615.1851
On the immediately preceding release ... -
09:11 AM Regression #12037 (Closed): Built-in SNMP daemon does not return values for BEGEMOT-PF-MIB::pfLabels on latest build
- SNMP daemon is returning correct responses now
-
09:10 AM Regression #12040 (Feedback): Scheduled firewall rules failing to load
- Applied in changeset commit:2afcd4527d4b245c7968bf7ac6b6c505259fe6c9.
-
09:00 AM Regression #12040 (In Progress): Scheduled firewall rules failing to load
- The scheduled rules are loading, but commit:765277ba6d873847c6c5b5657877e9fb0cec4357 needs another fix to correct the...
-
09:07 AM Regression #12045 (Resolved): High CPU usage and slowness with ``pfctl -ss``
- The latest build includes the fixes for this and it's working properly now. Dumping the states is fast no matter how ...
-
07:57 AM Bug #12034: Certificate Manager performs redundant escaping of special characters in certificate DN fields
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/286 -
07:17 AM Bug #12034: Certificate Manager performs redundant escaping of special characters in certificate DN fields
- it looks like `cert_escape_x509_chars()` is not needed - `openssl_csr_new()` automatically adds double quotes in case...
06/15/2021
-
06:38 PM pfSense Plus Bug #11942: Disconnecting WAN Interface Kills OpenVPN Servers on Other Interfaces
- I lied about the static. Still no dice.
-
06:37 PM pfSense Plus Bug #11942: Disconnecting WAN Interface Kills OpenVPN Servers on Other Interfaces
- UDP ipv4
It seems to work better if their is a static assigned to WAN, but not scientific test. Will test here so... -
05:21 PM Regression #12045 (Feedback): High CPU usage and slowness with ``pfctl -ss``
- I've cherry-picked commits from upstream/main to pfsense/RELENG_2_5_2 that should help this case:
b5d787d93b3d83f2... -
01:55 PM Regression #12045 (Resolved): High CPU usage and slowness with ``pfctl -ss``
- Some users have found that @pfctl -ss@ is taking consuming large amounts of CPU and taking much longer than it should...
-
05:20 PM Todo #12047 (Closed): Make sure libnv fixes are on devel-12 branch
- Following commits were cherry-picked directly from upstream/main to pfsense/RELENG_2_5_2 in order to fix #12045.
b... -
04:53 PM Bug #12034: Certificate Manager performs redundant escaping of special characters in certificate DN fields
- Here's some more details when examining certificates generated from different sources:
# Cert from third-party app... -
02:49 PM pfSense Docs Todo #12046 (Rejected): Feedback on Troubleshooting — Troubleshooting Duplicate IPsec SA Entries
- That's expected at the moment, but already being worked on.
I'm in the process of updating the other documentation... -
02:43 PM pfSense Docs Todo #12046 (Rejected): Feedback on Troubleshooting — Troubleshooting Duplicate IPsec SA Entries
- The confusion is around how to "disable". The way to disable seems to be conflicting?
*Page:* https://docs.netgate... -
01:52 PM Revision 474b0fed: Start IPv6 tunnel interfaces on boot and restart on dynamic IPv6 change. Fixes #6507
-
01:48 PM Revision 015a4824: Easyrule IPv6 fix. Issue #11439
- 01:00 PM Revision 27a8acbb: Use 'tos' rather than 'dscp' keyword for pf DSCP matching
- The 'dscp' keyword is pfSense-specific, but doesn't do anything more
than the FreeBSD 'tos' keyword.
Using 'tos' will... - 12:59 PM Revision 0b817201: Tell pf to keep counter values
- Pf can attempt to preserve (rule) counter values across rule updates.
We've reverted our home-grown implementation an... - 12:59 PM Revision 765277ba: schedule: Use the new multi-label support
- We've removed the pfsense specific 'schedule' keyword, and now use the new
multi-label support. That is, schedules ar... -
11:04 AM Bug #12041 (Pull Request Review): Certificate Manager shows incorrect DN for imported entries with UTF-8 encoding
-
10:52 AM Bug #12041: Certificate Manager shows incorrect DN for imported entries with UTF-8 encoding
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/285 -
09:28 AM Bug #12041 (Resolved): Certificate Manager shows incorrect DN for imported entries with UTF-8 encoding
- If you import a certificate containing UTF8 encoding into certificate manager,
it shows escaped unicode characters i... -
10:56 AM Todo #12044 (Resolved): Improve IPsec identifier settings
- We expose several IPsec identifier types in the GUI. strongSwan supports a few more, plus an automatic type. Addition...
-
09:37 AM pfSense Packages Feature #12042 (Resolved): Add Zabbix 5.4 agent and proxy packages
- New release from Zabbix, please add this new version : https://www.zabbix.com/rn/rn5.4.0
-
09:21 AM pfSense Packages Bug #11605: Suricata can trigger PHP crash on SG-3100
- Justin P wrote:
> Bill Meeks wrote:
> > Jim Pingle wrote:
> > > Bill Meeks wrote:
> > > > Does this function call... -
09:20 AM Bug #6507: GRE and GIF tunnels on dynamic IPv6 interface are not brought up during boot
- Applied in changeset commit:474b0fed67a9e2682526a230d410a4339ec7972d.
-
09:10 AM Bug #6507 (Feedback): GRE and GIF tunnels on dynamic IPv6 interface are not brought up during boot
- PR has been merged. Thanks!
-
08:49 AM Feature #11439 (Feedback): IPv6 support in ``easyrule`` CLI script
- PR has been merged. Thanks!
-
08:06 AM Regression #12040 (Feedback): Scheduled firewall rules failing to load
- There were some commits for the latest pf changes which were not included in the last 2.5.2 build, but will be in the...
-
08:03 AM Regression #12040 (Resolved): Scheduled firewall rules failing to load
- In 2.5.2-RC firewall rules with a schedule fail to load generating an error.
Tested using this config:... -
07:27 AM Regression #12037 (Feedback): Built-in SNMP daemon does not return values for BEGEMOT-PF-MIB::pfLabels on latest build
- Merged into devel-12 and cherry-picked to RELENG_2_5_2.
-
07:14 AM Regression #12037 (Pull Request Review): Built-in SNMP daemon does not return values for BEGEMOT-PF-MIB::pfLabels on latest build
-
07:06 AM Regression #12037 (Waiting on Merge): Built-in SNMP daemon does not return values for BEGEMOT-PF-MIB::pfLabels on latest build
- This was the result of an incorrect conversion to libpfctl (a DIOICGETRULE ioctl call was replaced by pfctl_add_rule(...
-
07:18 AM Bug #12038 (Pull Request Review): System attempts to start inactive services at boot
-
04:56 AM Bug #12038: System attempts to start inactive services at boot
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/284
-
03:43 AM Bug #12038 (Resolved): System attempts to start inactive services at boot
- ...
-
04:04 AM Bug #12039 (Resolved): Gateway alarm always triggers IPsec restart
- There are several issues:
1) '/etc/rc.gateway_alarm' trigger '/etc/rc.newipsecdns' which generate an invalid log m...
06/14/2021
-
08:08 PM Revision 3f39bbaf: Promote 2.5.2 to RC
-
08:06 PM Revision 26f8169b: Promote 2.5.2 to RC
- (cherry picked from commit eb1305d0736a1d71d1615ca6b19e3f4a917317a0)
-
08:06 PM Revision eb1305d0: Promote 2.5.2 to RC
-
07:14 PM Revision de248d0f: Do not show OpenVPN TUN interfaces on VLAN/QinQ edit pages. Fixes #11675
-
07:13 PM Revision 3f0e9812: Configure OpenVPN-parent QinQ interfaces on boot. Fixes #11662
-
06:34 PM Revision 23922057: Remove duplicate comconsole_port from loader.conf. Fixes #11653
-
06:16 PM Revision 789f8b22: Allow to enter /32 netmask and non-local gateway in the console menu. Issue #11581
-
06:10 PM Revision a17e9816: link_interface_to_tunnelif(): Make it consistent
- Change link_interface_to_tunnelif() to always return an array and
simplify logic used when it's used removing unneede... -
06:09 PM Revision 77e3e15a: Do not unset variables that will be set on next line
-
03:29 PM Regression #12037 (Closed): Built-in SNMP daemon does not return values for BEGEMOT-PF-MIB::pfLabels on latest build
- On the current RC builds of 2.5.2 with the new pf code, the bsnmp daemon no longer returns rule label data from the p...
-
02:20 PM Bug #11675: VLAN and QinQ edit pages allows selecting incompatible OpenVPN ``tun`` interfaces
- Applied in changeset commit:de248d0f6de7bcbca65aa94a37ac2a855b302580.
-
02:15 PM Bug #11675 (Feedback): VLAN and QinQ edit pages allows selecting incompatible OpenVPN ``tun`` interfaces
- PR has been merged. Thanks!
-
02:20 PM Bug #11662: QinQ using OpenVPN ``ovpn`` interface as a parent is not configured at boot time
- Applied in changeset commit:3f0e9812fea8672c2842d5f3f7a103518965af7f.
-
02:13 PM Bug #11662 (Feedback): QinQ using OpenVPN ``ovpn`` interface as a parent is not configured at boot time
- PR has been merged. Thanks!
-
01:40 PM Bug #11653: Duplicate ``comconsole_port`` lines in ``/boot/loader.conf``
- Applied in changeset commit:23922057504c253f1ddd0b6269e7ce85e94ac61e.
-
01:35 PM Bug #11653 (Feedback): Duplicate ``comconsole_port`` lines in ``/boot/loader.conf``
- PR has been merged. Thanks!
-
01:31 PM Bug #11581 (Feedback): Cannot configure WAN IP address with ``/32`` CIDR mask via console menu
- PR has been merged. Thanks!
-
01:17 PM pfSense Packages Bug #12036 (Pull Request Review): Certificate Manager page do not show Zabbix used certificates
-
11:39 AM pfSense Packages Bug #12036: Certificate Manager page do not show Zabbix used certificates
- fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/94 -
06:03 AM pfSense Packages Bug #12036 (Resolved): Certificate Manager page do not show Zabbix used certificates
- On the system_certmanager.php page, you can see the "In Use" column which reflects the certificates used by IPsec / O...
-
11:48 AM Bug #12034: Certificate Manager performs redundant escaping of special characters in certificate DN fields
- Interesting. Looks like the output varies by platform or OpenSSL version. Where I initially checked that was on an ol...
-
11:33 AM Bug #12034: Certificate Manager performs redundant escaping of special characters in certificate DN fields
- Jim Pingle wrote:
> I can't reproduce this here. The code is already doing the escaping so the user doesn't need to ... -
07:41 AM Bug #12034 (Feedback): Certificate Manager performs redundant escaping of special characters in certificate DN fields
- I can't reproduce this here. The code is already doing the escaping so the user doesn't need to worry about it. If I ...
-
05:03 AM Bug #12034: Certificate Manager performs redundant escaping of special characters in certificate DN fields
- according to https://datatracker.ietf.org/doc/html/rfc4514 "," (comma) must be escaped:...
-
04:53 AM Bug #12034 (Resolved): Certificate Manager performs redundant escaping of special characters in certificate DN fields
- We are facing issue while generating Cert/CSR form Cert. Manager whenever there is comma (,) in Organization same.
T... -
09:30 AM Regression #12021: NoIP.com incorrectly encodes Dynamic DNS update credentials
- Marcos Mendoza wrote:
> Maybe the username:password syntax can be avoided altogether and instead the @Authorization@... -
07:45 AM Regression #12028: SNMP daemon issues with pf nvlist changes
- I no longer get the original error on startup, and I am able to see data from the PF MIB:...
-
06:01 AM Regression #12028 (Resolved): SNMP daemon issues with pf nvlist changes
- libpfctl is now linked to libnv...
-
07:44 AM pfSense Docs Correction #12032 (Closed): TP-LINK M7350 modem works as an ethernet devices
- PR Merged.
-
05:38 AM pfSense Docs Correction #12032: TP-LINK M7350 modem works as an ethernet devices
- https://gitlab.netgate.com/docs/pfSense-docs/-/merge_requests/18
-
07:38 AM Bug #9277: MBT-4220/2220: pfSense hangs when running sysctl -a
- No. Those OIDs don't exist to be read if the i915 module is not loaded:...
-
07:33 AM Bug #9277: MBT-4220/2220: pfSense hangs when running sysctl -a
- Does it still crash if you don't load the i915 module?
-
07:35 AM Bug #12023 (Pull Request Review): Mobile IPsec NAT/BINAT entries missing from firewall rules
-
04:01 AM Bug #12023: Mobile IPsec NAT/BINAT entries missing from firewall rules
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/283 -
07:30 AM pfSense Packages Bug #12027 (Closed): FreeRADIUS 3.0.22 removed LEAP, package fails to start
- Works now
-
06:02 AM Regression #12017 (Resolved): FreeBSD-SA-21:12.libradius breaks mpd5 when using MS-CHAPv2
-
05:32 AM Feature #12035 (Resolved): Input validation to prevent unsupported UTF-8 characters from being used in certificate subject components
- If you try to use any UTF8 characters in State or Province/City/Organization/Organizational Unit fields, an error occ...
-
02:17 AM pfSense Packages Bug #12033 (New): maxmindb and _sqlite3 modules not found
- https://forum.netgate.com/topic/164305/py_error-log-errors-maxmindb-and-_sqlite3-modules-not-found
I am using pfbl...
06/13/2021
-
02:54 PM Regression #12021: NoIP.com incorrectly encodes Dynamic DNS update credentials
- Maybe the username:password syntax can be avoided altogether and instead the @Authorization@ header can be used as sp...
-
11:59 AM pfSense Packages Bug #11459: pfBlockerNG doesn't include WireGuard interface in outbound floating rules
- Tested on the latest RC release.
pfBlockerNG-devel 3.0.0_16
After enabling a Wireguard tunnel the interface stil... -
09:56 AM Regression #11910: IPsec status tunnel descriptions are incorrect
- I saw this behaviour when adding a VTI phase 2 to a system which already had a mobile IPSec tunnel defined.
Both con... -
06:47 AM Bug #9277: MBT-4220/2220: pfSense hangs when running sysctl -a
- There appear to be two specific sysctls that cause the system to stop responding:...
-
05:48 AM pfSense Docs Correction #12032 (Closed): TP-LINK M7350 modem works as an ethernet devices
- In the docs page entitled "Known Working 3G-4G Modems":https://docs.netgate.com/pfsense/en/latest/cellular/hardware.h...
06/12/2021
-
08:17 PM pfSense Packages Bug #12031 (Resolved): Wireguard Package Produces Crash in 2.5.2
- The Wireguard package produces a crash report in the dashboard in 2.5.2 after install. Here is the data:
Crash re... -
07:13 PM Bug #9277: MBT-4220/2220: pfSense hangs when running sysctl -a
- This was difficult to pin-down because it only stops responding if the HDMI console is not connected at the time the ...
-
05:54 PM Revision 20a9b988: This appears to be causing unintended fallout. Reverting for now.
- Revert "Delete static routes on gateway down. Fixes #11296"
This reverts commit 3fca57f8fae3733845c90338943c418bb77e... -
05:54 PM Revision 25b839d4: This appears to be causing unintended fallout. Reverting for now.
- Revert "Delete static routes on gateway down. Fixes #11296"
This reverts commit 3fca57f8fae3733845c90338943c418bb77e... -
05:54 PM pfSense Packages Bug #12030 (Resolved): Startup Errors for Avahi Package
- The avahi package is complaining about NSS support being missing and dependency errors on startup in 2.5.2.
WARN... -
03:16 PM pfSense Packages Feature #10858 (Resolved): OpenVPN Client silent install
- Tested OpenVPN Client Export 1.6_1 in 2.5.2.r.20210611.0300 and the silent installer option is getting saved as defau...
-
01:57 PM Bug #12022: Incorrect OpenVPN Client Export help link
- 2.6.0.a.20210612.0100 Client Export help is still pointing to https://docs.netgate.com/pfsense/en/latest/vpn/openvp...
-
01:13 PM Bug #11296 (New): Static route targets may still reachable via default route when the gateway they should route through is down
-
01:00 PM Bug #11296 (Feedback): Static route targets may still reachable via default route when the gateway they should route through is down
- Applied in changeset commit:25b839d4990bd5e3f55b2eccbdea74d1d2b92d5d.
-
12:56 PM Bug #11296 (New): Static route targets may still reachable via default route when the gateway they should route through is down
- Per Jim T, reverted this from 2.6.0 and 2.5.2. It appears to be causing some unintended side effects.
Can revisit ... -
08:37 AM pfSense Packages Bug #11605: Suricata can trigger PHP crash on SG-3100
- Bill Meeks wrote:
> Jim Pingle wrote:
> > Bill Meeks wrote:
> > > Does this function call work without restarting ... -
06:39 AM Regression #12028 (Feedback): SNMP daemon issues with pf nvlist changes
- Look to be fixed by Luiz's a8c3d8e344a7d7e015b78fa4935fcdbd4aec97df.
We were missing the libnv dependency in the l...
06/11/2021
-
07:07 PM pfSense Packages Bug #11950: Wireguard Package Errors and DNS problem
- No more DNS issue at boot after using MSS Clamp so disregard the DNS portion of this ticket
-
04:19 PM Feature #12029 (Duplicate): Please add MAC OUI lookup results (e.g. DHCP Leases table) to the ARP table
- It's already in the code, but had a bug recently: #11819
-
04:06 PM Feature #12029 (Duplicate): Please add MAC OUI lookup results (e.g. DHCP Leases table) to the ARP table
- In the DHCP Leases table, we see the assigned manufacturer displayed beside each MAC address.
This would be extremel... -
03:53 PM Revision 9569d863: OpenVPN Wizard: Set inactive_seconds = 300 by default.
- Follow up with fix for ticket #11699 and also enable it on server
tunnels created using wizard -
03:52 PM Revision 4aab19d4: Remove urlencode() for NoIP.com DDNS credentials. Fixes #12021.
-
12:36 PM Bug #12003: Pie and ``fq_pie`` are missing options and do not handle floating point number input correctly
- Patch version 3.
Added the ability to set the AQM & Scheduler parameters to zero.
Before php would interpet a zer... -
12:01 PM Regression #12017 (Feedback): FreeBSD-SA-21:12.libradius breaks mpd5 when using MS-CHAPv2
-
12:01 PM Regression #12017: FreeBSD-SA-21:12.libradius breaks mpd5 when using MS-CHAPv2
- Jim Pingle wrote:
> I do see the initial broken commit (@83280d17fccff2db7d79c7f38e80ec29078ef35e@) in 2.5.2 as well... -
10:36 AM Regression #12017: FreeBSD-SA-21:12.libradius breaks mpd5 when using MS-CHAPv2
- I do see the initial broken commit (@83280d17fccff2db7d79c7f38e80ec29078ef35e@) in 2.5.2 as well, so we need to bring...
-
10:18 AM Regression #12017: FreeBSD-SA-21:12.libradius breaks mpd5 when using MS-CHAPv2
- After several attempts I confirm that the bug is on libradius.so.4
I've replaced the library with the patched versio... -
11:28 AM Regression #12028 (Resolved): SNMP daemon issues with pf nvlist changes
- On @2.5.2.r.20210611.0300@ and @2.6.0.a.20210611.0100@, the built-in SNMP (bsnmp) logs the following at startup:
<... -
11:00 AM pfSense Packages Bug #12027 (Feedback): FreeRADIUS 3.0.22 removed LEAP, package fails to start
- Fix pushed as pkg version 0.15.7_31
-
10:59 AM pfSense Packages Bug #12027 (Closed): FreeRADIUS 3.0.22 removed LEAP, package fails to start
- Systems which pick up FreeRADIUS 3.0.22 (e.g. 2.5.2, 2.6.0 after latest ports merge) won't start because the package ...
-
11:00 AM Regression #12021: NoIP.com incorrectly encodes Dynamic DNS update credentials
- Applied in changeset commit:4aab19d4ade5d164c22bd63b2833d54bab740d59.
-
10:53 AM Regression #12021 (Feedback): NoIP.com incorrectly encodes Dynamic DNS update credentials
- PR has been merged. Thanks!
-
10:51 AM Bug #12022 (Feedback): Incorrect OpenVPN Client Export help link
- Merged
-
12:17 AM Bug #12022: Incorrect OpenVPN Client Export help link
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/282 -
10:05 AM Todo #12025: Add 1:1 Validation to Notify Someone They are 1:1 NAT'ing an Interface Address
- We used to prevent that in the past and had numerous complaints. There are many ways someone can shoot themselves in ...
-
09:57 AM Regression #12024 (Closed): State table data in GUI does not show the expected interface after latest pf merge
- This looks good on @2.5.2.r.20210611.0300@ and @2.6.0.a.20210611.0100@, both with @php74-pfSense-module-0.71@
* St... -
05:17 AM Revision fda3e52d: OpenVPN Client Export help link fix. Issue #12022
-
05:06 AM Regression #11910: IPsec status tunnel descriptions are incorrect
- I can replicate the active tunnel count being incorrect, as well as incorrect status, by using P1s with the option "G...
-
12:43 AM Bug #12026: Applying IPsec settings for many tunnels is slow or times out
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/279
-
12:42 AM Bug #12026 (Resolved): Applying IPsec settings for many tunnels is slow or times out
- This is an additional optimization for #11795:
1. `ipsec_get_phase1_src()` - always executes `get_interface_ip/ipv...
06/10/2021
-
09:43 PM Bug #11934: IPSEC stops working on 2.5.1 running on Watchguard XTM 5
- Tried altering and saving then applying but no IPSEC status, still unable to stop or start service...
- 08:29 PM Revision e2bb3424: Revise firewall schedule delete for MVC
-
05:34 PM Todo #12025 (New): Add 1:1 Validation to Notify Someone They are 1:1 NAT'ing an Interface Address
- Although it is VERY rarely necessary, we should add a banner to the top of the 1:1 NAT page notifying end users that ...
-
04:54 PM Revision 99b3a5cb: Change pkg install variable references. Fixes #11290
- * For whatever reason, PHP was failing to copy certain values into
$pkg_data which was a reference to the pkg configu... -
03:04 PM Bug #12023: Mobile IPsec NAT/BINAT entries missing from firewall rules
- Documenting a possible workaround:
If you have the following Mobile IPsec configuration:
Mobile Virtual Address... -
11:25 AM Bug #12023: Mobile IPsec NAT/BINAT entries missing from firewall rules
- Noting here what I mentioned on Slack:
* This is likely due to the fact that the "remote" network on mobile P2s is... -
11:18 AM Bug #12023 (Resolved): Mobile IPsec NAT/BINAT entries missing from firewall rules
- Adding a NAT or BINAT to a mobile IPsec configuration does not work.
The nat rules are not added to the pf configu... -
02:42 PM Revision 42c0b296: Fix state table content sorting. Fixes #11852
- (cherry picked from commit 5d48880b48039967f3b2b5acfb1432ee30953140)
-
02:26 PM Revision 5d48880b: Fix state table content sorting. Fixes #11852
-
01:25 PM Revision 02a923c1: Add devel/git back to list of packages
- (cherry picked from commit 9713b8ee2a61b3e68ccae0c898adff69ed111948)
-
01:11 PM Bug #11852: State table content on ``diag_dump_states.php`` does not sort properly
- Typo
-
12:54 PM Bug #11852: State table content on ``diag_dump_states.php`` does not sort properly
- Updating subject for release notes.
-
12:29 PM Bug #11852 (Resolved): State table content on ``diag_dump_states.php`` does not sort properly
- Confirmed fix
-
09:44 AM Bug #11852: State table content on ``diag_dump_states.php`` does not sort properly
- Picked back to RELENG_2_5_2 as well.
-
09:35 AM Bug #11852 (Feedback): State table content on ``diag_dump_states.php`` does not sort properly
- Applied in changeset commit:5d48880b48039967f3b2b5acfb1432ee30953140.
-
09:29 AM Bug #11852: State table content on ``diag_dump_states.php`` does not sort properly
- Simple fix, commit pending.
-
12:55 PM Regression #12005: ``Recover config.xml`` installer option does not work after default ZFS pool name change
- Excluding from release notes since it was a regression which happened after the last release.
-
09:41 AM Regression #12005 (Closed): ``Recover config.xml`` installer option does not work after default ZFS pool name change
- I've tried this a few times now with RC iso installs and it works fine with the new pool name and old pool name for m...
-
12:35 PM Regression #12024 (In Progress): State table data in GUI does not show the expected interface after latest pf merge
-
12:35 PM Regression #12024 (Closed): State table data in GUI does not show the expected interface after latest pf merge
- Adding for tracking purposes, it's a known issue but I don't see it in Redmine.
After the latest pf merge, the int... -
12:27 PM Todo #11684 (Resolved): Set ``explicit-exit-notify`` option by default for new OpenVPN server instances
- Confirmed fix on wizard
-
12:05 PM Bug #11290 (Feedback): Package ``<plugins>`` and ``<tabs>`` content missing from configuration in some cases
- Applied in changeset commit:99b3a5cb0ef4586222a331045df3cee17bb25d31.
-
12:02 PM Bug #11290: Package ``<plugins>`` and ``<tabs>`` content missing from configuration in some cases
- For whatever reason, PHP was failing to copy certain values into @$pkg_data@ which was a reference to the pkg configu...
-
09:56 AM Bug #11290 (New): Package ``<plugins>`` and ``<tabs>`` content missing from configuration in some cases
- There is still a bug here somewhere. Installing FRR on a complete fresh installation still doesn't get the proper @<p...
-
11:01 AM Bug #11453: ``wpa_supplicant`` uses 100% of a CPU core at boot
- Renato Botelho wrote:
> Hayden Hill wrote:
> > rom racer wrote:
> > > I don't know what interfaces.inc is but if y... -
06:17 AM Bug #11453: ``wpa_supplicant`` uses 100% of a CPU core at boot
- Hayden Hill wrote:
> rom racer wrote:
> > I don't know what interfaces.inc is but if you read the original descript... -
10:17 AM Regression #11981 (Closed): Duplicating Outbound NAT rule does not carry over contents of the source rule
- Works with the latest RELENG_2_5_2 code in place.
-
10:16 AM Bug #11946 (Closed): Custom value for AutoConfigBackup schedule Hours is not shown when loading the settings page
- Works with the latest RELENG_2_5_2 code in place.
-
10:12 AM Bug #11967 (Closed): Mobile IPsec advanced RADIUS parameters do not allow numeric values with a decimal point
- Works on 2.5.2 RC image 2.5.2.r.20210609.0300 -- the *Retransmit Base* and *Retransmit Timeout* fields allowed values...
-
10:04 AM Regression #11994 (Closed): Firewall rule usage counters showing 0/0 after latest pf merge
- All good now on 2.5.2 and 2.6.0
-
09:57 AM Bug #12022 (Resolved): Incorrect OpenVPN Client Export help link
- The help icon on the vpn_openvpn_export.php page points to
https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/i... -
07:36 AM Regression #11805 (Resolved): Port forward rules only function through the default gateway interface, ``reply-to`` does not work for Multi-WAN (CE Only)
- Bouke Henstra wrote:
> Jim Pingle wrote:
> > Adam Kuklycz wrote:
> > > Question, does this affect virtual IP's tha... -
07:33 AM Regression #11982 (Resolved): Outbound NAT does not create automatic equivalent rules when switching from Automatic to Manual mode
- Confirmed fix. It will reach 21.09 on next round of merges.
-
07:24 AM Regression #12021 (Pull Request Review): NoIP.com incorrectly encodes Dynamic DNS update credentials
-
05:07 AM Regression #12021: NoIP.com incorrectly encodes Dynamic DNS update credentials
- fix:
https://redmine.pfsense.org/issues/12021 -
05:04 AM Regression #12021 (Resolved): NoIP.com incorrectly encodes Dynamic DNS update credentials
- There is no need to `urlencode` user credentials (CURLOPT_USERPWD already encode them):...
-
07:21 AM Bug #12020 (Pull Request Review): OpenVPN RADIUS-based firewall rules use incorrect port ranges
-
03:47 AM Bug #12020: OpenVPN RADIUS-based firewall rules use incorrect port ranges
- https://github.com/pfsense/pfsense/pull/4522
-
03:47 AM Bug #12020 (Resolved): OpenVPN RADIUS-based firewall rules use incorrect port ranges
- Previous operator ( `><` ) prevented inserting port range with min/max port.
Ex.... -
04:23 AM pfSense Packages Bug #11575: OpenVPN clients cannot pass traffic when reconnecting using the same source port
- I had the same problem.
To replicate I connect a client, then kill the openvpn.exe process.
On the pfsense the user... -
04:17 AM Bug #11699: OpenVPN does not clean up parsed ``Cisco-AVPair`` rules on non-graceful disconnect
- This is not enabled for new servers created by the Remote Access Wizard.
fix:
https://gitlab.netgate.com/pfSense/... -
04:07 AM Regression #11795: Applying IPsec settings for more than ~30 tunnels times out PHP
- extra improvements:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/279
06/09/2021
-
08:57 PM Revision 3032e3b7: OpenVPN Wizard: Enable exit_notify by default
- Follow up with fix for ticket #11684 and also enable it on server
tunnels created using wizard
(cherry picked from c... -
07:23 PM Revision e6389f63: OpenVPN Wizard: Enable exit_notify by default
- Follow up with fix for ticket #11684 and also enable it on server
tunnels created using wizard -
04:48 PM Bug #12003: Pie and ``fq_pie`` are missing options and do not handle floating point number input correctly
- Patch version 2.
Fixed a spelling problem with the derand setting. -
03:58 PM Todo #11684: Set ``explicit-exit-notify`` option by default for new OpenVPN server instances
- Chris Linstruth wrote:
> This is _not_ enabled for new servers created by the Remote Access Wizard.
>
> Reconnect... -
12:19 PM Todo #11684: Set ``explicit-exit-notify`` option by default for new OpenVPN server instances
- This is _not_ enabled for new servers created by the Remote Access Wizard.
Reconnect to this server / Retry once i... -
02:34 PM Revision 609a2127: Simplify logic: no functional changes
- (cherry picked from commit a314c6c846406115c426ed20b102daf6e206b420)
-
02:34 PM Revision 372453f5: Outbound NAT: Fix rule duplication - #11981
- - firewall_nat_out.inc: Declare $after as a global variable otherwise
duplicate rule will always end up at the bott... -
02:22 PM Revision a314c6c8: Simplify logic: no functional changes
-
02:15 PM Revision 9fedbb13: Outbound NAT: Fix rule duplication - #11981
- - firewall_nat_out.inc: Declare $after as a global variable otherwise
duplicate rule will always end up at the bott... -
01:45 PM Bug #11453: ``wpa_supplicant`` uses 100% of a CPU core at boot
- rom racer wrote:
> I don't know what interfaces.inc is but if you read the original description of this bug, this wa... -
01:25 PM Bug #11453: ``wpa_supplicant`` uses 100% of a CPU core at boot
- I don't know what interfaces.inc is but if you read the original description of this bug, this was encountered in an ...
-
12:49 PM Bug #11453: ``wpa_supplicant`` uses 100% of a CPU core at boot
- rom racer wrote:
> @Renato please re-open this bug.
>
> There's two versions of wpa_supplicant included in pfSesn... -
12:44 PM Bug #11453: ``wpa_supplicant`` uses 100% of a CPU core at boot
- rom racer wrote:
> @Renato please re-open this bug.
>
> There's two versions of wpa_supplicant included in pfSesn... -
08:23 AM Bug #11453: ``wpa_supplicant`` uses 100% of a CPU core at boot
- @Renato please re-open this bug.
There's two versions of wpa_supplicant included in pfSesnse. Both the version in... -
07:49 AM Bug #11453 (Resolved): ``wpa_supplicant`` uses 100% of a CPU core at boot
- This fix was committed on ports on wpa_supplicant version 2.9_3. We are now using 2.9_10.
-
01:32 PM Revision bf1f1428: AutoConfigBackup schedule custom hour value fix. Issue #11946
- (cherry picked from commit 806d5c497497476e92568e168c302275e576e25c)
-
12:46 PM Regression #12017: FreeBSD-SA-21:12.libradius breaks mpd5 when using MS-CHAPv2
- I am unable to reproduce this on 2.6.0.a.20210609.0100 or 2.5.2.r.20210609.0300
In either case, the authentication... -
02:18 AM Regression #12017 (Resolved): FreeBSD-SA-21:12.libradius breaks mpd5 when using MS-CHAPv2
- [[https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=256283]] Bug 256283
l2tp authentication using radius is broken a... -
10:15 AM Regression #11805: Port forward rules only function through the default gateway interface, ``reply-to`` does not work for Multi-WAN (CE Only)
- Jim Pingle wrote:
> Adam Kuklycz wrote:
> > Question, does this affect virtual IP's that are setup on the same inte... -
10:09 AM pfSense Docs Todo #12018 (Pull Request Review): Feedback on Firewall — Configuring firewall rules
-
03:14 AM pfSense Docs Todo #12018: Feedback on Firewall — Configuring firewall rules
- from https://www.freebsd.org/cgi/man.cgi?query=pf.conf&apropos=0&sektion=0&manpath=FreeBSD+13.0-RELEASE+and+Ports&arc...
-
03:04 AM pfSense Docs Todo #12018 (Closed): Feedback on Firewall — Configuring firewall rules
- *Page:* https://docs.netgate.com/pfsense/en/latest/firewall/configure.html
*Feedback:*
There is no description ... -
09:49 AM Regression #11981 (Feedback): Duplicating Outbound NAT rule does not carry over contents of the source rule
- Fix pushed to 2.6.0 and 2.5.2
-
09:04 AM Regression #11981: Duplicating Outbound NAT rule does not carry over contents of the source rule
- Renato Botelho wrote:
> It actually broke duplication and is now acting like rule is being edited instead of creatin... -
08:43 AM Regression #11981 (In Progress): Duplicating Outbound NAT rule does not carry over contents of the source rule
- It actually broke duplication and is now acting like rule is being edited instead of creating a new one
-
09:36 AM pfSense Docs Todo #12016 (Closed): Feedback on Cellular Wireless — Known Working 3G-4G Modems
- Merged. I fixed the formatting (Should be @::@ not @:::@) but it was wrong on multiple entries so I fixed them all in...
-
12:36 AM pfSense Docs Todo #12016: Feedback on Cellular Wireless — Known Working 3G-4G Modems
- https://gitlab.netgate.com/docs/pfSense-docs/-/merge_requests/16
-
12:26 AM pfSense Docs Todo #12016 (Closed): Feedback on Cellular Wireless — Known Working 3G-4G Modems
- *Page:* https://docs.netgate.com/pfsense/en/latest/cellular/hardware.html
*Feedback:*
Add Huawei E5573 to the... -
08:36 AM Todo #11943 (Resolved): Add FRR package documentation links
- Confirmed fix
-
08:33 AM Bug #11946: Custom value for AutoConfigBackup schedule Hours is not shown when loading the settings page
- Cherry-picked to 2.5.2-RC
-
07:56 AM pfSense Packages Bug #11605: Suricata can trigger PHP crash on SG-3100
- Jim Pingle wrote:
> Bill Meeks wrote:
> > Does this function call work without restarting PHP? I don't have hardwar... -
07:47 AM pfSense Packages Bug #12019 (Not a Bug): Right Axis always shows `None -`
- That's not what it's indicating. You can graph two separate items, in the settings they are labeled to match (Left Ax...
-
07:34 AM pfSense Packages Bug #12019 (Not a Bug): Right Axis always shows `None -`
- It should show something like "Right Axis: Time"
-
07:45 AM Bug #11966 (Resolved): Incorrect RADVD log message on HA event
- Confirmed fix
-
07:42 AM Bug #3132: Gateway events for IPv6 affect IPv4 services and vice versa
- see #11864#note-3
-
07:41 AM Bug #11864: OpenVPN stays bound to previous IP address after interface changes
- We have to create a function `restart_interface_services($interface, $ipproto)` to restart all interface and IPv4/IPv...
06/08/2021
-
10:10 PM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- I don't use either Snort or Suricata in operation but I do use pfBLockerNG-devel and the patch has solved the stabili...
-
09:15 PM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- Jim Pingle wrote:
> Each package maintainer would need to handle changes to their own code, should they choose to ta... -
09:28 AM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- Darin May wrote:
> How is the cat-herding addressed so that the work-around isn't duplicated across packages?
It ... -
09:24 AM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- How is the cat-herding addressed so that the work-around isn't duplicated across packages? I've noticed chit-chat in...
-
08:35 AM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- Darin May wrote:
> I'm not familiar with the criteria for bugs to be listed in the target fix list of open issues, b... -
02:24 AM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- Kris Phillips wrote:
> Tested in 21.09 Jun 5th build. This patch is present and no longer needs to be applied manual... -
09:52 PM Bug #12015 (Not a Bug): When using VMware Fusion/Workstation NAT, with pfsense IPSEC, no routes are going thru the tunnel
- No evidence that this is a bug and not a config/environment issue. Post on the forum to discuss it in more detail.
-
07:53 PM Bug #12015 (Not a Bug): When using VMware Fusion/Workstation NAT, with pfsense IPSEC, no routes are going thru the tunnel
- So I have a virtualized lab setup that has to connect to a corporate development lab. I have a layered setup where I ...
-
09:51 PM pfSense Packages Bug #11605: Suricata can trigger PHP crash on SG-3100
- Bill Meeks wrote:
> Does this function call work without restarting PHP? I don't have hardware at the moment to test... -
09:20 PM pfSense Packages Bug #11605: Suricata can trigger PHP crash on SG-3100
- Jim Pingle wrote:
> The patch should fix the behavior, but the package could also implement the fix on its own using... -
02:52 PM Bug #12014 (Duplicate): Invalid arguments passed in services_dhcpv6_relay.php on line 116
- This appears to be a duplicate of #11969
-
02:25 PM Bug #12014 (Duplicate): Invalid arguments passed in services_dhcpv6_relay.php on line 116
- Just got this error while saving DHCPv6 relay settings on the 2.5.2-BETA.
pfSense asked me to upload the log. -
09:23 AM Bug #12008 (Not a Bug): IPsec - mutual certificate - can't find priv key
- The identifiers must match and be present in the certificate. As you see, it's not always exactly the same in each ca...
-
05:27 AM Bug #12008: IPsec - mutual certificate - can't find priv key
- it seems working setting my identifer as asn.1, but using as DN the output of the command:
ipsec listcerts
that o... -
12:42 AM Bug #12008 (Not a Bug): IPsec - mutual certificate - can't find priv key
- IPsec with mutual certificate
Jun 8 07:35:28 charon 95058 16[IKE] <con400000|35> IKE_SA con400000[35] state chang... -
07:35 AM Bug #12013 (New): Reading log data is inefficient in certain cases
- When reading log files, the functions are set to fetch a specific number of lines (e.g. 50, 250, 500) but to get thos...
-
07:29 AM Bug #11934: IPSEC stops working on 2.5.1 running on Watchguard XTM 5
- I cannot tell if the same issue but with 2.5.1 I am experiencing a similar problem with VPN and not with the watchgua...
-
07:24 AM Todo #12012 (Resolved): Improve log settings help text for file size, compression, and retention count
- The fields in log settings for file size and compression lack information that users need to make properly informed d...
-
07:14 AM Feature #12011 (Closed): Disable log compression on new installations when ``/var/log`` is a ZFS dataset with compression enabled
- The default setting for log compression is currently bzip2 for all cases, which isn't ideal for every case. If /var/l...
-
06:40 AM Bug #12010 (Closed): System default gateway doesn't automatically switch from an inactive gateway if a specific gateway is selected
- from https://forum.netgate.com/topic/161065/%D0%B2%D0%BE%D0%BF%D1%80%D0%BE%D1%81%D1%8B-%D0%BF%D0%BE-pfsense-2-5-plus/...
-
05:26 AM Regression #11982: Outbound NAT does not create automatic equivalent rules when switching from Automatic to Manual mode
- Max Leighton wrote:
> Tested in 2.6 it is working.
>
> It doesn't seem to have made it to 21.09 current build b... -
01:35 AM pfSense Packages Bug #12009 (New): Zabbix Agent starts twice by /etc/rc.start_packages
- ...
-
12:46 AM Regression #11994 (Feedback): Firewall rule usage counters showing 0/0 after latest pf merge
- Fixed in 2.6.0 and 2.5.2.
The tracker ID wasn't being saved rendering the counters useless.
06/07/2021
-
03:30 PM Bug #12007 (Resolved): Dynamic DNS cache expiration time check calculation method may cause update to happen on the wrong day
- Dynamic DNS update is executed if a) no update has been done for the provider yet, b) the IP address has changed afte...
-
03:09 PM Regression #12005 (Feedback): ``Recover config.xml`` installer option does not work after default ZFS pool name change
-
09:19 AM Regression #12005 (Closed): ``Recover config.xml`` installer option does not work after default ZFS pool name change
- On current 2.5.2, 2.6.0, and 21.09 snapshots the default ZFS pool name changed from "zroot" to "pfSense" and there is...
-
02:20 PM Revision 188e82ff: Update config recovery to use new zpool name. Issue #12005
- (cherry picked from commit d440bb6ae65f6ddb8ae310683cdac9ce64b01487)
-
02:20 PM Revision d440bb6a: Update config recovery to use new zpool name. Issue #12005
-
12:50 PM Bug #11967: Mobile IPsec advanced RADIUS parameters do not allow numeric values with a decimal point
- Tested on:...
-
09:46 AM Feature #9297 (Pull Request Review): Graph for hardware temperature readings
-
05:16 AM Feature #9297: Graph for hardware temperature readings
- rrd update:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/278
Status Monitoring pkg update:
https:... -
09:41 AM pfSense Packages Bug #11993 (Pull Request Review): PHP error after disabling HAProxy
-
04:01 AM pfSense Packages Bug #11993: PHP error after disabling HAProxy
- fix:
https://github.com/pfsense/FreeBSD-ports/pull/1072 -
09:40 AM Bug #12002 (Pull Request Review): Boot messages contain entries about configuring LAGG/VLAN/QinQ interfaces even when no entries of those types are configured
-
02:10 AM Bug #12002: Boot messages contain entries about configuring LAGG/VLAN/QinQ interfaces even when no entries of those types are configured
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/277 -
01:46 AM Bug #12002 (Resolved): Boot messages contain entries about configuring LAGG/VLAN/QinQ interfaces even when no entries of those types are configured
- ...
-
09:40 AM Bug #12006 (Duplicate): CARP IP sometimes doesn't apply to CARP member
- I noticed this when a CARP member had no CARP status. I was told that this can happen if the VIP address isn't appli...
-
09:37 AM Bug #12001 (Pull Request Review): System attempts to stop inactive services at shutdown
-
01:27 AM Bug #12001: System attempts to stop inactive services at shutdown
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/276 -
01:09 AM Bug #12001 (Resolved): System attempts to stop inactive services at shutdown
- /etc/rc.stop_packages tries to stop disabled services:...
-
09:34 AM Bug #12000 (Pull Request Review): Remote log server input validation allows invalid values
-
01:01 AM Bug #12000: Remote log server input validation allows invalid values
- OS interprets numeric-only value as decimal IP address:...
-
08:14 AM pfSense Packages Bug #11551: SG-3100 with pfBlockerNG doesn't pass traffic
- See also: #12004
-
07:34 AM pfSense Packages Bug #11551: SG-3100 with pfBlockerNG doesn't pass traffic
- The patch should fix the behavior, but the package could also implement the fix on its own using @ini_set("pcre.jit",...
-
08:14 AM pfSense Packages Bug #11605: Suricata can trigger PHP crash on SG-3100
- See also: #12004
-
07:19 AM pfSense Packages Bug #11605: Suricata can trigger PHP crash on SG-3100
- The patch should fix the behavior, but the package could also implement the fix on its own using @ini_set("pcre.jit",...
-
08:14 AM pfSense Plus Todo #12004: Disable PCRE JIT to work around PHP PCRE crashes on multi-core 32-bit ARM systems
- Packages and other scripts could use @ini_set("pcre.jit", "0");@ to disable PCRE JIT on systems without the patch to ...
-
08:08 AM pfSense Plus Todo #12004 (Resolved): Disable PCRE JIT to work around PHP PCRE crashes on multi-core 32-bit ARM systems
- Currently, PHP crashes on multi-core 32-bit ARM systems (SG-3100) with certain PCRE calls, as documented on #11466, #...
-
08:12 AM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- I created #12004 for the temporary workaround via disabling PCRE JIT. This issue can remain open while we investigate...
-
07:50 AM Bug #12003 (Resolved): Pie and ``fq_pie`` are missing options and do not handle floating point number input correctly
- Example:
"alpha" => array("name" => "alpha", "type" => "number", "default" => get_single_sysctl("net.inet.ip.dummyne... -
07:41 AM Regression #11805: Port forward rules only function through the default gateway interface, ``reply-to`` does not work for Multi-WAN (CE Only)
- Adam Kuklycz wrote:
> Question, does this affect virtual IP's that are setup on the same interface as the default ga... -
07:33 AM Todo #11983: Hide "Reboot and run a filesystem check" for ZFS systems
- Darin May wrote:
> I'm running 21.05 on an sg-3100 and I don't have the fsck option on my reboot menu; should I?
... -
06:59 AM Feature #8794: NTP authentication support
- The ntp client auth is yet to be implemented.
-
12:20 AM pfSense Packages Bug #11711: New Squid Status Page Non-Functional
- Kris Phillips wrote:
> Can someone provide the patch once this is merged so we can test?
See the attachment
-
12:05 AM pfSense Packages Feature #11349 (Resolved): Allow to set minimum TLS version
06/06/2021
-
11:24 PM pfSense Packages Bug #11551: SG-3100 with pfBlockerNG doesn't pass traffic
- The patch contained at https://redmine.pfsense.org/issues/11466#note-32 has stopped the PHP crashes. So this bug coul...
-
11:10 PM Regression #11805: Port forward rules only function through the default gateway interface, ``reply-to`` does not work for Multi-WAN (CE Only)
- Question, does this affect virtual IP's that are setup on the same interface as the default gateway IP, or does the I...
-
09:41 AM Bug #12000 (Resolved): Remote log server input validation allows invalid values
- When configuring remote syslog servers in status_logs_settings.php each server is entered as IP[:port]. Port 514 is a...
-
08:07 AM pfSense Packages Bug #11605: Suricata can trigger PHP crash on SG-3100
- Does the PHP temp workaround patch fix this one too?
https://redmine.pfsense.org/issues/11466#note-32
06/05/2021
-
03:42 PM Bug #11999 (Resolved): OpenVPN IPv6 tunnel network is not validated properly
- If you enter an IPv6 address without a subnet mask, the configuration will be accepted, but the OpenVPN service will ...
-
03:41 PM Regression #11316: Unbound crashes with signal 11 when reloading
- The DHCP service doesn't appear to be reliably updating the DNS server either. Tested on 21.09 Jun 5th build, I did ...
-
03:27 PM pfSense Plus Feature #11772: Layer 2 Tunnel Bonding Capability
- I understand your concern about the requirement for an "upstream device on a big pipe," however this is exactly the s...
-
01:57 PM pfSense Plus Feature #11772: Layer 2 Tunnel Bonding Capability
- Not certain how this would be possible. Fundamentally internet connectivity doesn't work this way. You would need ...
-
03:20 PM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- Tested in 21.09 Jun 5th build. This patch is present and no longer needs to be applied manually in the development ch...
-
03:13 PM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- Reporting that the patch in #32 solved my 21.02.2 --> 21.05 upgrade w/pfBLockerNG-devel causing the firewall service ...
-
01:37 PM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- Decided to go through some performance testing and stress testing. I loaded the CPU to maximum with iPerf3 traffic a...
-
03:04 PM Todo #11983: Hide "Reboot and run a filesystem check" for ZFS systems
- I'm running 21.05 on an sg-3100 and I don't have the fsck option on my reboot menu; should I?
-
03:01 PM Regression #11982: Outbound NAT does not create automatic equivalent rules when switching from Automatic to Manual mode
- Verified problem exists on Jun 5th build of 21.09.
Build Info:
21.09-DEVELOPMENT (arm)
built on Sat Jun 05 01:... -
01:26 PM Regression #11982: Outbound NAT does not create automatic equivalent rules when switching from Automatic to Manual mode
- Tested in 2.6 it is working.
It doesn't seem to have made it to 21.09 current build because when I test in
21... -
02:07 PM pfSense Packages Feature #11349: Allow to set minimum TLS version
- Minimum TLS version option are: 1.0/1.1/1.2
2.5.1-RELEASE (amd64)
built on Mon Apr 12 07:50:14 EDT 2021 -
01:49 PM pfSense Packages Bug #11711: New Squid Status Page Non-Functional
- Can someone provide the patch once this is merged so we can test?
-
01:43 PM Bug #11946: Custom value for AutoConfigBackup schedule Hours is not shown when loading the settings page
- Tested in 2.6.0. The specified hour will now stay on the page when after navigating away and navigating back.
Howe... -
09:45 AM pfSense Docs Correction #11998 (Closed): Feedback on Hardware — Hardware Tuning and Troubleshooting
- *Page:* https://docs.netgate.com/pfsense/en/latest/hardware/tune.html
*Feedback:*
Section "VMware vmx(4) Interfac...
06/04/2021
-
07:04 PM Revision 502973c8: Duplicating Outbound NAT rule fix. Issue #11981
- (cherry picked from commit 68be10e63195d399089092149e119de30ae6a639)
-
07:04 PM Revision e191b65c: Create Outbound NAT automatic equivalent rules when switching from Automatic to Manual mode. Fixes #11982
- (cherry picked from commit ec8adb56d59a293516d1a0a3fb4eb45aad299f5b)
-
05:30 PM pfSense Packages Feature #11997 (New): IPsec Profile Wizard: Add Support for exporting Android strongSwan Profiles
- We currently have Apple and Windows IPSec profile export. However, we're missing this option for Android which has a...
-
04:39 PM Bug #9277: MBT-4220/2220: pfSense hangs when running sysctl -a
- We've received additional reports of issues related to this bug report. The behavior may be related to running sysctl...
- 02:58 PM Revision e691303d: Adjust validation for MVC
-
02:05 PM Regression #11981: Duplicating Outbound NAT rule does not carry over contents of the source rule
- Fix was not picked back to 2.5.2, but is now. Will be in future builds.
-
02:04 PM Regression #11982: Outbound NAT does not create automatic equivalent rules when switching from Automatic to Manual mode
- Fix was not picked back to 2.5.2, but is now. Will be in future builds.
- 01:00 PM Revision 34b44340: Revise top/bottom outbound rule addition
-
11:15 AM Revision 1f0abbad: Use stable host for pkg repo
-
11:10 AM Revision d7ee51c5: Welcome pfSense CE 2.5.2-RC
-
08:35 AM Regression #11910: IPsec status tunnel descriptions are incorrect
- Also seeing strangeness in the IPsec dashboard widget. Customer also reporting the active tunnel counts are incorrect...
-
08:23 AM pfSense Plus Regression #11995 (Closed): UPnP/NAT-PMP not functioning on 32-bit ARM
- UPnP is not functional on 32-bit ARM systems (SG-3100, SG-1000) running pfSense Plus 21.05. When a client attempts to...
-
07:48 AM Regression #11994 (Closed): Firewall rule usage counters showing 0/0 after latest pf merge
- On 2.6.0.a.20210604.0100 the state counters on the firewall rule tabs are showing 0/0 again. We had a similar issue i...
-
05:41 AM Regression #11545: Primary interface address is not always used when VIPs are present
- I believe I am seeing this now after upgrading 2.4.5-p1 -> 2.5.1-CE with FRR BGP where FRR is told to use the WAN IPv...
-
04:12 AM Regression #11775: State counters not updating and always show 0/0 since last few updates
- Issue reappeared for me in 2.6.0.a.20210603.0625 and 2.6.0.a.20210604.0100
-
01:35 AM pfSense Packages Bug #11993 (Resolved): PHP error after disabling HAProxy
- After unchecking the "Enable HAProxy" checkbox and clicking 'Save' on the haproxy_global.php page, an error occurs:
... -
01:16 AM Bug #11992 (Confirmed): GRE Tunnel - Does not work with a virtual IP as endpoint
- I can confirm this issue on 2.6.0.a.20210603.0100/2.5.2.b.20210603.0300 (Proxmox VM) -
I see high packet loss when...
06/03/2021
- 07:29 PM Revision bfd55119: Simplify getting automated rules
-
06:34 PM Bug #11992 (Confirmed): GRE Tunnel - Does not work with a virtual IP as endpoint
- Hello,
I saw that normally this problem is solved since 6 years but I meet a problem, I did not manage to solve it... -
04:49 PM Revision 806d5c49: AutoConfigBackup schedule custom hour value fix. Issue #11946
-
04:49 PM Revision ebb3c7a6: FRR help links. Fixes #11943
- (cherry picked from commit be659aff5a3a52c1e08481a00eb697ecd86a9899)
-
04:48 PM Revision be659aff: FRR help links. Fixes #11943
-
04:47 PM Revision a7ea1293: Correct RADVD log message on HA event. Fixes #11966
- (cherry picked from commit d4b4c1805419cacad886094cf11dacbb4f43a0e6)
-
04:45 PM Revision d4b4c180: Correct RADVD log message on HA event. Fixes #11966
-
04:44 PM Revision 8bbc34a2: Allow to use numeric with decimal point for RADIUS Advanced Parameters. Feature #11211
- (cherry picked from commit f5ab9736059e616e4a037591ef6f89d1c14e23ed)
-
04:43 PM Revision f5ab9736: Allow to use numeric with decimal point for RADIUS Advanced Parameters. Feature #11211
-
12:55 PM Regression #11805: Port forward rules only function through the default gateway interface, ``reply-to`` does not work for Multi-WAN (CE Only)
- Updating subject for release notes.
-
12:51 PM Todo #11684: Set ``explicit-exit-notify`` option by default for new OpenVPN server instances
- Updating subject for release notes.
-
11:48 AM Todo #11684 (Feedback): Set ``explicit-exit-notify`` option by default for new OpenVPN server instances
- PR has been merged 3 weeks ago and is already present on 2.5.2
-
12:51 PM Bug #11967: Mobile IPsec advanced RADIUS parameters do not allow numeric values with a decimal point
- Updating subject for release notes.
-
11:45 AM Bug #11967 (Feedback): Mobile IPsec advanced RADIUS parameters do not allow numeric values with a decimal point
- PR has been merged. Thanks!
-
12:01 PM Bug #11453 (Feedback): ``wpa_supplicant`` uses 100% of a CPU core at boot
-
11:55 AM Todo #11943: Add FRR package documentation links
- Applied in changeset commit:be659aff5a3a52c1e08481a00eb697ecd86a9899.
-
11:49 AM Todo #11943 (Feedback): Add FRR package documentation links
-
11:49 AM Todo #11943: Add FRR package documentation links
- PR has been merged. Thanks!
-
11:55 AM Bug #11966: Incorrect RADVD log message on HA event
- Applied in changeset commit:d4b4c1805419cacad886094cf11dacbb4f43a0e6.
-
11:45 AM Bug #11966 (Feedback): Incorrect RADVD log message on HA event
- PR has been merged. Thanks!
-
11:49 AM Bug #11946 (Feedback): Custom value for AutoConfigBackup schedule Hours is not shown when loading the settings page
- PR has been merged. Thanks!
-
11:48 AM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- We do not use @pcre_jit_stack@ anywhere directly, so there is nothing to change/adjust in that regard. Also reading t...
-
11:35 AM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- Given that this issue seems to only affect 32-bit systems, perhaps this is a case of needing to substitute @pcre_@ fu...
-
10:48 AM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- The PCRE JIT patch has resolved the issue on two problematic SG-3100 configs that I had sitting here.
Thanks Jim. -
10:01 AM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- A couple others here have also confirmed that the JIT disable patch has worked around the crash on 3100. I committed ...
-
09:34 AM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- Using the sample code from Note 15 I can still crash it with a low recursion limit, and I also tried lowering pcre.ba...
-
09:16 AM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- If someone who can readily reproduce the PHP crash wants to try resizing the pcre.recursion_limit automatically based...
-
11:30 AM pfSense Plus Bug #11942: Disconnecting WAN Interface Kills OpenVPN Servers on Other Interfaces
- Web Dawg wrote:
> Well,
>
> I have 19 other netgate routers configured the same, and they do not do this. Same c... -
10:19 AM pfSense Plus Bug #11942: Disconnecting WAN Interface Kills OpenVPN Servers on Other Interfaces
- Well,
I have 19 other netgate routers configured the same, and they do not do this. Same config.
Only this mod... -
03:19 AM Regression #11986: Static routes may not be in routing table when expected
- workaround: Disable Gateway Monitoring or Disable Gateway Monitoring Action
06/02/2021
-
11:00 PM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- A cursory search seems to suggest that the default pcre recursion limit is too high ootb (higher than what can fit in...
-
06:47 PM Feature #9297: Graph for hardware temperature readings
- Signed up just to do this. +1.
Current CPU temperature at 0% load isn't the same as temperature 2 hours ago when t... - 05:40 PM Revision 14ee85bb: Minot MVC improvements
- 02:21 PM Revision 3d259e5e: Use 'tos' rather than 'dscp' keyword for pf DSCP matching
- The 'dscp' keyword is pfSense-specific, but doesn't do anything more
than the FreeBSD 'tos' keyword.
Using 'tos' will... - 02:21 PM Revision 4715251f: schedule: Use the new multi-label support
- We've removed the pfsense specific 'schedule' keyword, and now use the new
multi-label support. That is, schedules ar... - 02:21 PM Revision 78b98b41: Tell pf to keep counter values
- Pf can attempt to preserve (rule) counter values across rule updates.
We've reverted our home-grown implementation an... -
01:26 PM Regression #11945 (Closed): Incorrect VTI interface creation
-
01:26 PM Bug #11913 (Closed): RADVD breaks on SIGHUP
-
01:26 PM Feature #11911 (Closed): Shortcut buttons for service control and logs on RADVD configuration
-
01:26 PM Bug #11904 (Closed): IGMP Proxy restarts unnecessarily after IPv6 gateway events
-
01:26 PM Bug #11883 (Closed): ``dhcp6withoutra_script.sh`` does not get executed when advanced options are set
-
01:26 PM Bug #11880 (Closed): Missing ``/0`` subnet when cloning repeatable CIDR mask controls
-
01:26 PM Bug #11850 (Closed): NTP authentication input validation rejects valid keys
-
01:26 PM Bug #11842 (Closed): Captive Portal post-auth redirect is not properly respected
-
01:26 PM Bug #11832 (Closed): ``ipsec_vti()`` does not skip disabled VTI entries
-
01:26 PM Bug #11830 (Closed): Certificate validation with OCSP always fails in ``openvpn.tls-verify.php``
-
01:26 PM Regression #11806 (Closed): IPv4 link-local (``169.254.x.x``) gateway does not function
-
01:26 PM Regression #11794 (Closed): IPsec VTI interface names are not properly formed for more than 32 interfaces
-
01:26 PM Bug #11793 (Closed): OpenVPN client starts when CARP VIP is in BACKUP status when bound to Virtual IP aliased to CARP VIP
-
01:26 PM Regression #11751 (Closed): Input validation prevents creating 1:1 NAT rules on IPsec
-
01:26 PM Bug #11725 (Closed): Error when setting queue limit on CODELQ limiter
-
01:26 PM Regression #11702 (Closed): RAM Disk Settings shows Kernel Memory at ``0`` Kb and does not allow the user to create RAM disks
-
01:26 PM Bug #11700 (Closed): OpenVPN does not kill IPv6 client states on disconnect
-
01:26 PM Bug #11699 (Closed): OpenVPN does not clean up parsed ``Cisco-AVPair`` rules on non-graceful disconnect
-
01:26 PM Bug #11698 (Closed): Incomplete PPPoE custom reset values lead to invalid cron entry
-
01:26 PM Bug #11685 (Closed): PHP error if ``PHP_error.log`` file is too large
-
01:26 PM Bug #11651 (Closed): Error when adding both IPv4 and IPv6 P2 under an IPv4 or IPv6 only IKEv1 P1
-
01:26 PM Bug #11609 (Closed): CLI interface configuration without IPv6 leaves RA enabled
-
01:26 PM Feature #11596 (Closed): Support for Cisco AVPair ``{clientipv6}`` template in firewall rules returns by RADIUS
-
01:26 PM Feature #11576 (Closed): IPsec GUI option to control Child SA ``start_action``
-
01:26 PM Regression #11564 (Closed): strongSwan configuration always contains user EAP/PSK values
-
01:26 PM Regression #11495 (Closed): NTP widget displays incorrect status
-
01:26 PM Feature #11402 (Closed): Xen console support
-
01:26 PM Feature #11395 (Closed): Option to switch IPsec filtering modes to choose between ``enc`` and ``if_ipsec`` filtering
-
01:26 PM Feature #11264 (Closed): Redirect Captive Portal users to login page after they logout
-
01:26 PM Bug #11229 (Closed): Harmless error when enabling traffic shaper
-
01:26 PM Feature #11211 (Closed): GUI option to set RADIUS Timeout for EAP-RADIUS
-
01:25 PM Feature #11140 (Closed): Allow the firewall to use DNS servers provided to an OpenVPN client instance
-
01:25 PM Bug #11082 (Closed): XMLRPC synchronization restarts all OpenVPN instances on the secondary node when making any change on the primary node
-
01:25 PM Feature #6626 (Closed): Support for IPv6 firewall entries with dynamic delegated prefix and static host address
-
01:25 PM Bug #5135 (Closed): DHCP interfaces are always treated as having a gateway, even if one is not assigned by the upstream DHCP server
-
01:25 PM Feature #2400 (Closed): GUI options for WPA Enterprise with identity/password
-
10:42 AM Todo #11985 (Pull Request Review): Ensure ``/usr/local/sbin/`` scripts use full path to executable files
-
05:06 AM Todo #11985: Ensure ``/usr/local/sbin/`` scripts use full path to executable files
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/274 -
04:18 AM Todo #11985 (Resolved): Ensure ``/usr/local/sbin/`` scripts use full path to executable files
- ...
-
10:31 AM Regression #11986 (Resolved): Static routes may not be in routing table when expected
- Static routes that I had established via VTI tunnels are not showing up in the routing table.
related to #11296 -
... -
10:15 AM Bug #11955 (Rejected): Cannot disable startup beep without configuring e-mail notifications
- Same here. Unable to reproduce on a fresh install.
Perhaps there is a browser extension or other feature which is ... -
03:03 AM Bug #11955: Cannot disable startup beep without configuring e-mail notifications
- unable to reproduce it on 2.4.5-p1/2.5.1/2.6.0.a.20210528.0100/2.5.2.b.20210601.0300 -
I can successfully set "Disa... -
10:11 AM Regression #11524 (Closed): Using SHA1 or SHA256 with AES-NI may fail if AES-NI attempts to accelerate hashing
-
09:16 AM pfSense Packages Bug #10436: softflowd no longer sends flow data after upgrade (v0.9.9_1 -> v1.0.0)
- same crash on pfSense 21.02-p2 (SG-3100):...
-
08:26 AM Bug #7779: Traffic crossing a site-to-site OpenVPN tunnel fails to fragment.
- see also #7801
-
05:37 AM Bug #11869 (Resolved): OpenVPN client startup error if IPv6 Tunnel Network is defined in TAP mode
- Tested on the:...
-
05:13 AM Bug #11926 (Pull Request Review): Advanced DHCP client configuration "Protocol timing" help text is in the wrong location
-
05:13 AM Feature #9341 (Pull Request Review): Support DNS Made Easy authentication without a username
-
04:07 AM Bug #11456 (Resolved): Unbound Python Integration repeatedly mounts ``dev`` without unmounting
- works as expected on 2.5.2.b.20210602.0300 -
I only see one mount point after multiple restarts of pfBlockerNG(Pytho... -
01:47 AM Bug #11629: PPPoE WAN IP address different than expected when set static by ISP
- workaround:
You could use VIPs from your /29 for all the VPNs/services. If clients are using an FQDN you could jus... -
01:01 AM Regression #11981 (Feedback): Duplicating Outbound NAT rule does not carry over contents of the source rule
-
12:59 AM Regression #11545: Primary interface address is not always used when VIPs are present
- might be `ifconfig` bug, like #11594 and #11964
-
12:47 AM Bug #11984 (Resolved): Automatic Outbound NAT mode can create incorrect rules in some cases
- In some cases it uses incorrect IPv6 link-local address specification:...
06/01/2021
-
08:56 PM Regression #11524: Using SHA1 or SHA256 with AES-NI may fail if AES-NI attempts to accelerate hashing
- Tested with SHA256 on IPsec P1 and SHA1 on P2 on @21.05-RC built on Wed May 26 18:11:31 EDT 2021@ with AES-NI selecte...
-
04:11 PM Revision 68be10e6: Duplicating Outbound NAT rule fix. Issue #11981
-
04:06 PM Bug #11843 (Resolved): Potential XSS vulnerability in Captive Portal ``redirurl`` handling
- Tested this against 21.05.r.20210526.1807.
Whilst logged in:... -
03:58 PM Revision ec8adb56: Create Outbound NAT automatic equivalent rules when switching from Automatic to Manual mode. Fixes #11982
-
01:12 PM Todo #11983 (Pull Request Review): Hide "Reboot and run a filesystem check" for ZFS systems
-
11:14 AM Todo #11983: Hide "Reboot and run a filesystem check" for ZFS systems
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/273
-
10:56 AM Todo #11983 (Resolved): Hide "Reboot and run a filesystem check" for ZFS systems
- ZFS does not have a fsck utility, so the option to reboot and run a filesystem check does not make sense to offer to ...
-
11:20 AM Regression #11982 (Feedback): Outbound NAT does not create automatic equivalent rules when switching from Automatic to Manual mode
- Applied in changeset commit:ec8adb56d59a293516d1a0a3fb4eb45aad299f5b.
-
10:59 AM Regression #11982: Outbound NAT does not create automatic equivalent rules when switching from Automatic to Manual mode
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/272 -
08:47 AM Regression #11982 (Resolved): Outbound NAT does not create automatic equivalent rules when switching from Automatic to Manual mode
- When a user switches from Automatic Outbound NAT to Manual Outbound NAT, the GUI is supposed to create a set of stati...
-
11:03 AM Regression #11550 (Resolved): Segmentation fault when loading ALTQ traffic shaping rules using FAIRQ
- pfSense 2.5.1 test:...
-
10:54 AM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- That might explain why my example config triggers the problem. As preg_match is being used by the PHP code for urltab...
-
10:20 AM Regression #11805: Port forward rules only function through the default gateway interface, ``reply-to`` does not work for Multi-WAN (CE Only)
- Testing on 2.5.2-BETA snapshot build 2.5.2.b.20210601.0300 confirms it is fixed there on a system which could reprodu...
-
10:15 AM Regression #11316: Unbound crashes with signal 11 when reloading
- Jim Pingle wrote:
> The unbound112 build is available in the pkg repository but we're still working on a good set of... -
09:58 AM Regression #11981 (Pull Request Review): Duplicating Outbound NAT rule does not carry over contents of the source rule
-
09:17 AM Regression #11981: Duplicating Outbound NAT rule does not carry over contents of the source rule
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/271 -
08:22 AM Regression #11981 (Closed): Duplicating Outbound NAT rule does not carry over contents of the source rule
- When using the copy button on an Outbound NAT rule on firewall_nat_out.php, the contents of the source rule are not c...
-
09:03 AM pfSense Packages Feature #11972 (Pull Request Review): Arpwatch - Add support for Telegram notifications
-
03:54 AM pfSense Packages Feature #11972: Arpwatch - Add support for Telegram notifications
- https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/92
-
09:02 AM Feature #11978 (Pull Request Review): New Dynamic DNS Provider: Strato
- Too late for 2.5.2.
-
08:55 AM Todo #11976 (Pull Request Review): Compliance with pfSense style guide in Dynamic DNS service code
-
08:42 AM Bug #11979 (Rejected): GUI Cannot reassign Interface on LAGG port
- I can't replicate the behavior as stated, and this site is not for support or diagnostic discussion.
For assistanc... -
08:40 AM Feature #11975 (Duplicate): Simplify NAT logging to conforme more easily with local/regional laws
- Duplicate of #7800
We're limited at the moment by what pf offers as data for logging, and last I saw, it doesn't s... -
08:37 AM Bug #11973 (Not a Bug): High Latency every 10 second on TCP OVPN
- There isn't enough information here to definitively classify this as a bug in pfSense. This site is not for support o...
-
07:39 AM pfSense Packages Bug #11366: Arpwatch Cron Notification every 15 minutes
- Just checking on the status of this. I updated to the latest version of pfSense, 2.5.1-RELEASE (amd64), and it rever...
-
03:51 AM pfSense Packages Bug #11977 (Duplicate): Any mail from the pfsense appliance has "Arpwatch Notification" in the subject line, no matter which package the mail comes from
- Duplicate of #8454
see also #11366 -
03:06 AM pfSense Packages Bug #11980: EAP does not work with SQL backend
- Please provide more info - "radiusd `-X`" output during EAP+SQL authentication and changes in the `inner-tunnel-*` fi...
05/31/2021
-
07:56 PM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- I have confirmed this PHP segmentation fault issue is an issue only on 32-bit ARM hardware such as that in the SG-310...
-
06:26 PM Revision 9713b8ee: Add devel/git back to list of packages
-
01:31 PM Bug #11629: PPPoE WAN IP address different than expected when set static by ISP
- Jim Pingle wrote:
> We will need a lot more information here since it isn't happening to others that we're aware of ...
05/30/2021
-
09:01 PM Bug #11636 (Resolved): Unused Limiter entries with schedules create unnecessary cron jobs
- Tested and working on 21.05/2.5.2. Cron job was not added until a rule contained the limiter, and the cron job was re...
-
08:43 PM Bug #11718 (Resolved): XMLRPC Client does not honor its default timeout value
- This fix has resolved a couple of different setups where the 60s timeout was being hit. Afterwards, the xmlrpc calls ...
-
07:19 PM pfSense Packages Bug #11980 (Feedback): EAP does not work with SQL backend
- The problem is that the sql module references in /usr/local/etc/sites-enabled/inner-*-tunnel remain commented out or ...
-
07:10 PM Bug #11979 (Rejected): GUI Cannot reassign Interface on LAGG port
- I was trying to reassign the HA sync interface from lagg0.4000 to igb3 through the GIU. Saving the setting however wo...
-
07:07 PM Regression #11795 (Resolved): Applying IPsec settings for more than ~30 tunnels times out PHP
- Tested 51 entries and working on 21.05/2.5.2 - marking as resolved.
-
04:47 PM Bug #11704 (Resolved): Stale hostname registration data for OpenVPN clients is not deleted from the DNS Resolver configuration at boot
- Tested and working - marking as resolved.
-
04:15 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
>
> I gave up 2 years ago and moved to Untangle Firewall. Worked instantly for all the xboxes in our house. All m...-
04:08 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
- Polar Nerd wrote:
> Marc 05 wrote:
> > Likely not as miniupnp hasn't changed afaik.
>
> FYI here is a link to wh... -
12:36 PM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
- Marc 05 wrote:
> Likely not as miniupnp hasn't changed afaik.
FYI here is a link to where they are discussing thi... -
09:12 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
- Likely not as miniupnp hasn't changed afaik.
If you have time, find a copy of 2.4.0 and test it. It may help narro... -
04:16 AM Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port
- Will this work on 2.5.1, as still having the same issue.
would love to test on 2.5.1 as i have 3 pcs all with COD ... -
01:37 PM Bug #11821 (Rejected): Upgrade libcurl to version 7.76.0
- There are CVEs present in 7.76.0 hence it will not be included on 21.05/2.5.2. New libcurl versions are included in t...
-
09:47 AM Feature #11978: New Dynamic DNS Provider: Strato
- PR: https://github.com/pfsense/pfsense/pull/4525
-
09:41 AM Feature #11978 (Closed): New Dynamic DNS Provider: Strato
- add the german "strato.de" to the dyndns providers
-
03:45 AM pfSense Packages Bug #11977 (Duplicate): Any mail from the pfsense appliance has "Arpwatch Notification" in the subject line, no matter which package the mail comes from
- Most mail from the pfsense appliance has "Arpwatch Notification" in the subject line, even when it is from a complete...
05/29/2021
-
10:42 PM Revision 79b9e082: Add some leeway to DynDNS cache expiration time check
- This leeway is needed to ensure that the cache is invalidated after N days and
not N+1 days. The latter could happen,... -
09:18 PM Revision 22949106: Merge identical code of DynDNS providers
-
09:13 PM Revision f56efb0d: Sort DynDNS providers inside switch statements
- Not all of the code is sorted in this commit, but comments
were added to the code to instruct future contributors to
... -
09:13 PM Revision f6f1d1c6: Remove whitespace at end of line
-
06:17 PM pfSense Packages Bug #11822 (Resolved): Upgrade ClamAV to 0.103.2
- Verified that the version is upgraded in 21.05/2.5.2. Version in repos confirmed as 0.103.2_1.
-
06:09 PM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- Tested on the 21.05 RC from May 26th on the SG-3100. This issue is still present.
-
04:47 PM Todo #11976 (Resolved): Compliance with pfSense style guide in Dynamic DNS service code
- Files for the dynamic DNS include white space in the end of lines.
Additionally, many switch statements list provi... -
04:09 PM Feature #11975 (Duplicate): Simplify NAT logging to conforme more easily with local/regional laws
- The French law requires from ISPs to log "who used this IP address at this timestamp?" informations for a year.
Fo... -
03:58 PM Feature #11974 (New): XMLRPC synchronization for igmmproxy settings
- Configuration synchronization (XMLRPC) does not replicate the configuration of IGMP Proxy.
Related to #11957. -
01:06 PM Feature #11968 (Resolved): VLAN list sorting
- Tested in
2.6.0-DEVELOPMENT (amd64)
built on Fri May 28 01:04:03 EDT 2021
FreeBSD 12.2-STABLE
It works as expe... -
10:47 AM Bug #11973 (Not a Bug): High Latency every 10 second on TCP OVPN
- Hello,
We have an PFSensePLUS on AWS with 2 OVPN server: 1 TCP and 1 UDP. After the update to 21.02.2 we noticed tha... -
08:54 AM pfSense Packages Feature #11972 (Resolved): Arpwatch - Add support for Telegram notifications
- Arpwatch does not have an option to send notifications to a Telegram backend, even when the Telegram configuration is...
05/28/2021
-
10:12 PM Feature #11968: VLAN list sorting
- the "VLANS" headers are clickable .
2.6.0.a.20210528.0100 -
11:11 AM Feature #11968: VLAN list sorting
- On RELENG_2_5_2 when branched
- 07:51 PM Revision b5c9be99: Cisco-AVPair ACL rule: port range operator change
- Previous operator ( `><` ) prevented inserting port range with min/max port.
Ex.
`ip:inacl#1=permit tcp host {clienti... -
05:06 PM Revision 23f7fa0b: Add 2.5.2-BETA repo
- (cherry picked from commit 8997bf4703ab41fe7d36c098c1e0d29d69e26194)
-
05:03 PM Revision 34ca228a: Add 2.5.2-BETA repo
- (cherry picked from commit 8997bf4703ab41fe7d36c098c1e0d29d69e26194)
-
05:03 PM Revision 8997bf47: Add 2.5.2-BETA repo
-
03:51 PM Bug #11453: ``wpa_supplicant`` uses 100% of a CPU core at boot
- This is in 2.6 snapshots and now 2.5.2. Also in 21.09 snapshots if testing on arm.
-
01:58 PM Regression #11723 (Closed): Virtual IP addresses are only added to interfaces after reboot
- Works correctly now.
-
01:56 PM Bug #11867 (Closed): Unquoted variable in ``dot.tcshrc`` can cause proxy password to be printed
- Works correctly now.
-
01:52 PM Bug #11765 (Closed): Invalid HTML encoding in modal Notices window
- Since the bug causing the original notice was random and hard to reproduce, and also has been fixed, it's not viable ...
-
01:42 PM Feature #11293 (Closed): New Dynamic DNS Provider: one.com
- Closing for lack of feedback. No way for us to test this here.
-
01:42 PM Feature #11294 (Closed): New Dynamic DNS Provider: Yandex PDD
- Closing for lack of feedback. No way for us to test this here.
-
01:42 PM Feature #11358 (Closed): New Dynamic DNS Provider: NIC.RU
- Closing for lack of feedback. No way for us to test this here.
-
01:42 PM Feature #11420 (Closed): New Dynamic DNS Provider: Gandi LiveDNS IPv6
- Closing for lack of feedback. No way for us to test this here.
-
01:42 PM Bug #11667 (Closed): Automatic 25-day forced Dynamic DNS update removes wildcard domain
- Closing for lack of feedback.
-
01:41 PM Bug #11815 (Closed): NoIP.com Dynamic DNS update failure is not detected properly
- Closing for lack of feedback. No way for us to test this here.
-
01:40 PM Bug #11754 (Closed): Digital Ocean Dynamic DNS help text is incorrect
- New text is in place.
-
01:28 PM Bug #11767 (Closed): Sanitize OpenVPN Client Export certificate password in status output
- Works. Password is sanitized in the output....
-
12:22 PM Bug #11748 (Resolved): Automated corruption recovery from cached ``config.xml`` backup files should check multiple backups
- On a fresh VM I made a few changes, booted to single user mode and truncated the last few configs to 0 bytes, and the...
-
11:37 AM Revision bb5f626f: devel repo should use PKG_REPO_SERVER_DEVEL
-
11:12 AM Bug #11290: Package ``<plugins>`` and ``<tabs>`` content missing from configuration in some cases
- On RELENG_2_5_2 when branched
-
07:15 AM pfSense Packages Bug #11964 (Pull Request Review): pfBlocker XMLRPC sync CARP interface advskew
-
07:12 AM Bug #11678: Certificate Manager does not report Unbound as using a certificate
- Slipped by me, too. And spell check, since it's technically a valid word.
Thanks! -
01:07 AM Bug #11678: Certificate Manager does not report Unbound as using a certificate
- Jim Pingle wrote:
> Updating subject for release notes.
BTW, all this time the subject has a typo: Manger -> Mana... -
07:12 AM pfSense Plus Bug #11971 (Not a Bug): pfSense Plus 21.02.2 Crashes while reboot
- Something is wrong with your filesystem or disk, not a bug. You should wipe and reload from a recovery installation i...
-
06:31 AM pfSense Plus Bug #11971 (Not a Bug): pfSense Plus 21.02.2 Crashes while reboot
- Our Netgate, updated from pfSense 2.4.5-RELEASE-p1 to pfSense Plus 21.02.2 had the issue that the Traffic Graphs on t...
05/27/2021
-
11:29 PM pfSense Packages Bug #11892: WireGuard: dpinger does not start correctly on a WireGuard gateway at boot
- [2.6.0-DEVELOPMENT][admin@pfSense.home.arpa]/root: ifconfig tun_wg0
tun_wg0: flags=80c1<UP,RUNNING,NOARP,MULTICAST... -
07:10 PM Revision 3845c6eb: Fix PKG_REPO_BRANCH_DEVEL s/devel/master/
-
07:02 PM Revision cac3f71a: Welcome pfSense CE 2.5.2-BETA
- 05:37 PM Revision ef4f9a8b: Observe 'after' value when creating a new rule
-
05:28 PM pfSense Packages Bug #11964: pfBlocker XMLRPC sync CARP interface advskew
- from https://forum.netgate.com/topic/163709/dns-resolver-not-listening-on-lan-carp-vip-after-update-to-2-5-1/7:
> I ... -
04:20 PM Revision 7dbe76cd: Init pkg plugin array before use. Fixes #11290
-
03:05 PM Revision cf8a0761: Make VLAN table sortable. Implements #11968
- 01:16 PM Revision 49674e1f: Move globals to include file
- 01:13 PM Revision 2ca19797: Move globals to include file
-
01:05 PM pfSense Packages Bug #11970 (Confirmed): Netgate Firmware Upgrade Doesn't Work on XG-2758 (ADI/coreboot)
- Any version of pfSense after 2.4.4p3 breaks the flashing functionality for coreboot in the Netgate Firmware Upgrade p...
- 01:00 PM Revision a5d3732b: Validate input depends on flag
-
12:35 PM Bug #11290: Package ``<plugins>`` and ``<tabs>`` content missing from configuration in some cases
- Jim Pingle wrote:
> Applied in changeset commit:7dbe76cd5756082cbd67db1b93acb606ad84996e.
Can confirm this fixes ... -
11:30 AM Bug #11290 (Feedback): Package ``<plugins>`` and ``<tabs>`` content missing from configuration in some cases
- Applied in changeset commit:7dbe76cd5756082cbd67db1b93acb606ad84996e.
-
11:28 AM Bug #11290: Package ``<plugins>`` and ``<tabs>`` content missing from configuration in some cases
- Jim Pingle wrote:
> This is actually a problem in the base system not specific to a package. I have a fix, will comm... -
11:19 AM Bug #11290 (In Progress): Package ``<plugins>`` and ``<tabs>`` content missing from configuration in some cases
- This is actually a problem in the base system not specific to a package. I have a fix, will commit shortly.
-
10:15 AM Bug #11290: Package ``<plugins>`` and ``<tabs>`` content missing from configuration in some cases
- Marcos Mendoza wrote:
> Do those have the @<type>plugin_carp</type>@ line in the /conf/config.xml file? If not, does... -
10:44 AM Bug #11969 (Pull Request Review): PHP error if no DHCPv6 Relay interfaces are selected
-
10:23 AM Bug #11969: PHP error if no DHCPv6 Relay interfaces are selected
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/270 -
10:19 AM Bug #11969 (Resolved): PHP error if no DHCPv6 Relay interfaces are selected
- How to reproduce:
Unselect all interfaces on the services_dhcpv6_relay.php and uncheck "Enable"
Result:... -
10:15 AM Feature #11968 (Feedback): VLAN list sorting
- Applied in changeset commit:cf8a0761c5c2ae80b62743d6d476e0fae6f2495e.
-
10:05 AM Feature #11968 (Resolved): VLAN list sorting
- Add sorting for the table of VLAN tags, so the headers are clickable to sort by each column.
See also: #8558
-
09:17 AM Bug #11793: OpenVPN client starts when CARP VIP is in BACKUP status when bound to Virtual IP aliased to CARP VIP
- Fixing up subject
-
08:54 AM Bug #11967 (Pull Request Review): Mobile IPsec advanced RADIUS parameters do not allow numeric values with a decimal point
-
08:41 AM Bug #11967: Mobile IPsec advanced RADIUS parameters do not allow numeric values with a decimal point
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/269 -
08:40 AM Bug #11967 (Closed): Mobile IPsec advanced RADIUS parameters do not allow numeric values with a decimal point
- "RADIUS Advanced parameters" doesn't allow to enter numeric with a decimal point in the "Retransmit Base" and "Retran...
-
08:52 AM pfSense Packages Bug #11965 (Pull Request Review): Avahi service started twice by /etc/rc.start_package
-
03:41 AM pfSense Packages Bug #11965: Avahi service started twice by /etc/rc.start_package
- fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/91 -
08:51 AM Bug #11966 (Pull Request Review): Incorrect RADVD log message on HA event
-
03:00 AM Bug #11966: Incorrect RADVD log message on HA event
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/268 -
01:24 AM Bug #11966 (Resolved): Incorrect RADVD log message on HA event
- After transition to the CARP BACKUP state, an incorrect message appears in the log:
"Stopping radvd instance on LAN ... -
08:50 AM Feature #11957 (Pull Request Review): XMLRPC synchronization for DHCP relay settings
-
02:57 AM Feature #11957: XMLRPC synchronization for DHCP relay settings
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/267
-
08:08 AM Todo #11943 (Pull Request Review): Add FRR package documentation links
-
08:04 AM Feature #11211: GUI option to set RADIUS Timeout for EAP-RADIUS
- Open a fresh issue for that input validation concern, we can work on that for the next release separate from this.
-
07:41 AM Feature #11211: GUI option to set RADIUS Timeout for EAP-RADIUS
- works as expected on 21.05.r.20210526.1807 -
I can see advanced parameter in the `/var/etc/ipsec/strongswan.conf`:
... -
07:48 AM Regression #11952 (Closed): Traffic matching rules with limiters is not handled by DUMMYNET
- Confirmed working here as well on latest 21.05 build. I see traffic in limiter info now, and my bufferbloat score is ...
-
12:31 AM Feature #11103 (Resolved): Use virtual link local IP address as RA source address for HA environments
- works as expected on 21.05.r.20210526.1807
`AdvRASrcAddress` in `/var/etc/radvd.conf`:...
Also available in: Atom