Activity
From 09/09/2021 to 10/08/2021
10/08/2021
-
07:30 PM Feature #12416: Support OpenVPN ``client-kill`` to terminate remote clients instead of clearing their session
- Customer in internal ticket 96721 tested this. Their results seem to be that this patch breaks the OpenVPN client ki...
-
05:44 PM Bug #12440 (Resolved): Zero-value prefix IPv6 addresses are mishandled
- Zero-value prefix IPv6 addresses on the type ::/96 are mishandled when used in pfSense firewall or NAT rules.
For ... -
04:56 PM Revision 9a18668d: Display default Reflection Timeout value. Feature #12318
-
03:51 PM Revision 44a4215f: 1:1 NAT destination entries description fix. Issue #12410
-
03:50 PM Revision e33311fe: DNS check optimization. Fixes #11512
-
03:49 PM Revision 1ab2ec0a: IPv6 Port Forwarding Proxy+NAT input validation. Fixes #12319
-
03:48 PM Revision ff90368d: fix #11734 NAT overlap validation does not check special networks
-
03:44 PM Revision 42259176: deleteVIP() IPsec PH1 input validation. Fixes #12356
-
03:42 PM Revision 3e968849: Correct input validation on deleting a CARP VIP which is referenced by an IP Alias. Fixes #12362
-
03:36 PM Revision b5332117: Improve XMLRPC Sync for dhcpd. Fixes #10955
-
03:36 PM Revision 83afa41a: Reload syslogd on log Rotation Size / Retention Count change. Fixes #12366
-
03:35 PM Revision 08ef78ac: Allow to halt OpenVPN client on status page. Issue #12416
-
03:34 PM Revision ed1ff340: Do not show Configuring IPsec VTI interfaces message at boot if no VTIs are configured. Fixes #12419.
-
03:34 PM Revision 14e080ab: Swap Captive Portal Redirection URL and Blocked MAC redirect URL input validation messages. Fixes #12388
-
03:33 PM Revision d9793efc: Update help text for RAM disk settings. Fixes #12389
-
03:30 PM Revision 79b8b049: Remove unused function from pfsense-utils.inc. Todo #12406
-
03:26 PM Revision b8cfee9d: 6RD Prefix input validation. Fixes #12435
-
12:22 PM Revision 7cf69c98: Default preferred lifetime input validation. Fixes #12439
-
12:09 PM pfSense Docs Todo #12418 (Feedback): AutoConfigBackup Menu Structure Documentation
- Fixed (plus a few other changes):
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/160898325eff3f21fa77b9fc67... -
10:59 AM pfSense Docs Todo #12418 (In Progress): AutoConfigBackup Menu Structure Documentation
-
11:11 AM pfSense Docs Todo #11812 (Feedback): Feedback on pfSense Configuration Recipes — Configuring IPv6 Through A Tunnel Broker Service
- Updated the doc and added the reboot advice.
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/465c63a97708665... -
11:00 AM Regression #11512 (Feedback): DHCP Leases page and ARP table page fail to load if DNS is not available
- Applied in changeset commit:e33311fefd11f5b30c6822c298cf9d12adbb164e.
-
11:00 AM Bug #12319 (Feedback): NAT reflection does not work for IPv6 port forwarding rules when configured for NAT+Proxy mode
- Applied in changeset commit:1ab2ec0a269f03dd7e865d21787331a7a2cb6f3f.
-
10:50 AM Bug #12356 (Feedback): Validation when deleting a VIP does not check if the VIP is used by IPsec phase 1 entries
- Applied in changeset commit:42259176d0c0a4ca49099ef5cdbcbfdacdd64589.
-
10:50 AM Bug #12362 (Feedback): Validation when deleting a VIP does not prevent deleting a CARP VIP used as a parent for an IP Aliases VIP
- Applied in changeset commit:3e968849be516d138cad7f021ee2d8df11bea202.
-
10:50 AM Bug #10955 (Feedback): XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
- Applied in changeset commit:b5332117fd5b675d9d7f81b9c2895ab452f3d610.
-
10:45 AM Bug #12366 (Feedback): Rotation settings for individual log files do not take effect after saving
- Applied in changeset commit:83afa41acfafdfd90fb71d8cdd5542a826bef315.
-
10:35 AM Regression #12288: GRE and GIF tunnel inside addresses are missing at the OS level after applying changes on assigned interfaces
- This also applies to GIF interfaces. Additionally, it doesn't happen on assignment but any time changes are applied.
-
10:35 AM Bug #12419 (Feedback): Console boot output includes ``Configuring IPsec VTI interfaces`` when no VTI interfaces are configured
- Applied in changeset commit:ed1ff34051aa52395e91c84b7e4d2beb0f2e9b91.
-
10:35 AM Bug #12388 (Feedback): Captive Portal input validation for "After authentication Redirection URL" and "Blocked MAC address redirect URL" is swapped
- Applied in changeset commit:14e080ab41419b4006130432c1e128deaaffdee0.
-
10:35 AM Bug #12389 (Feedback): Help text for RAM disk settings does not mention Captive Portal data
- Applied in changeset commit:d9793efc0cb9d13aa812141ab509d288455f1f62.
-
10:35 AM Bug #12435 (Feedback): "6RD Prefix" field does not have input validation
- Applied in changeset commit:b8cfee9dbaec99fc20ed0d816bb3cbe79943b150.
-
07:41 AM Bug #12435 (Pull Request Review): "6RD Prefix" field does not have input validation
-
12:49 AM Bug #12435: "6RD Prefix" field does not have input validation
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/411 -
12:42 AM Bug #12435 (Resolved): "6RD Prefix" field does not have input validation
- ```6RD Prefix``` field on the interfaces.php page has no input validation and allows any value to be entered
-
10:35 AM Bug #12439 (Feedback): "Default preferred lifetime" field for IPv6 RA does not have input validation
- Applied in changeset commit:7cf69c985d73a2a3a418832bf9e6314a05f8efbe.
-
07:42 AM Bug #12439 (Pull Request Review): "Default preferred lifetime" field for IPv6 RA does not have input validation
-
07:23 AM Bug #12439: "Default preferred lifetime" field for IPv6 RA does not have input validation
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/412 -
07:13 AM Bug #12439 (Resolved): "Default preferred lifetime" field for IPv6 RA does not have input validation
- The "Default preferred lifetime" field allows to enter any value, including non-numeric
-
07:40 AM Bug #12371 (Pull Request Review): Remove subnet overlap check on LAN interfaces when using 6rd
-
12:36 AM Bug #12371: Remove subnet overlap check on LAN interfaces when using 6rd
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/410 -
07:36 AM Feature #9827 (Duplicate): Add default route indicator to gateways dashboard widget to indicate which interface is currently selected as default in a gateways group scenario
- duplicate of #11057
-
07:24 AM Bug #12437 (Rejected): Firewall logs block item from appearing in logs creates an alias such as EasyRuleBlockHostsOPT10. OPT10 was renamed to e.g. “wirelessly when interface was created there is no way to find original OPTX from gui
- Given the free-form nature of interface descriptions that isn't viable, and they would also not update if an interfac...
-
03:19 AM Bug #12437 (Rejected): Firewall logs block item from appearing in logs creates an alias such as EasyRuleBlockHostsOPT10. OPT10 was renamed to e.g. “wirelessly when interface was created there is no way to find original OPTX from gui
- Once interfaces have been renamed there does not seem to be an easy way to identify which OPTX interface it used to b...
-
07:21 AM Bug #12436 (Not a Bug): Pppoe server config gui does not allow setting of chap authentication, and sets the network start address for allocation to 0
- An IP address ending in @.0@ is only invalid when used as a part of an actual subnet. In point-to-point interfaces li...
-
03:55 AM Bug #12436: Pppoe server config gui does not allow setting of chap authentication, and sets the network start address for allocation to 0
- Hi Victor,
This behaviour causes assigned client ip address to be 0 thus invalid.
E.g. 192.168.1.0 is not a valid ... -
03:43 AM Bug #12436: Pppoe server config gui does not allow setting of chap authentication, and sets the network start address for allocation to 0
- And Ritchie wrote:
> It is not possible to enable chap authentication via the gui. The service config file is genera... -
03:08 AM Bug #12436 (New): Pppoe server config gui does not allow setting of chap authentication, and sets the network start address for allocation to 0
- It is not possible to enable chap authentication via the gui. The service config file is generated with pap authentic...
-
07:13 AM Bug #12159 (Resolved): "Default preferred lifetime" router advertisement validation check uses incorrect variable
- The original issue from the PR is resolved in 21.09.r.20210923.2242
but the "Default preferred lifetime" field all... -
06:47 AM Regression #11938 (Resolved): DNS Resolver does not add PTR record for OpenVPN clients
- Tested on the:...
-
05:27 AM Regression #12233 (Resolved): VIP network addresses are not expanded on Port Forward rules
- Tested on the:...
-
03:40 AM Feature #12438 (Resolved): Option to select PPPoE Server authentication protocol
- It is not possible to enable chap authentication via the gui. The service config file is generated with pap authentic...
10/07/2021
-
11:28 PM Feature #12094 (Resolved): Suppress kernel messages for ``lo0`` configuration during boot
there is no kernel messages for ``lo0``
Starting Secure Shell Services...done.
Setting up interfaces microco...-
06:17 PM Bug #12434 (Resolved): Multiple cURL Vulnerabilities
- Vulnerabilities outlined here:
https://www.tenable.com/plugins/nessus/153812
CVEs Here:
https://cve.mitre.org/c... -
04:38 PM Feature #12433 (Resolved): Icon for traffic direction on floating rules tab
- It’d be helpful to see the configured direction(s) for rules on the floating rule page without having to click on the...
-
03:13 PM pfSense Docs Todo #11743 (Feedback): Feedback on Virtual Private Networks — VPN Scaling
- Done:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/54c876ea107be13ffe3fcdfad3e8e27990c1f86c -
02:56 PM pfSense Docs Todo #11743 (In Progress): Feedback on Virtual Private Networks — VPN Scaling
- https://docs.netgate.com/pfsense/en/latest/hardware/cryptographic-accelerators.html covers it in much more detail but...
-
12:01 PM Bug #11481 (Pull Request Review): NAT Reflection does not work when "NAT Reflection mode for port forwards" is set to "pure nat"
-
11:44 AM Bug #11481: NAT Reflection does not work when "NAT Reflection mode for port forwards" is set to "pure nat"
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/409
-
10:34 AM pfSense Docs New Content #12432 (Feedback): Add documentation for DNS Resolver Status page
- Added:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/b82cfce672ea111e49044889d08af69f47f52f86
https://git... -
10:10 AM pfSense Docs New Content #12432 (Closed): Add documentation for DNS Resolver Status page
- The DNS Resolver status page ( *Status > DNS Resolver* , @status_unbound.php@) is not currently documented or referen...
-
09:42 AM pfSense Packages Bug #12423: Dashboard shows "SQLite database missing, Force Reload DNSBL to recover!"
- Viktor, thanks for improving the error message. Two comments:
1. putting the full path might be even better. I assu... -
12:41 AM pfSense Packages Bug #12423: Dashboard shows "SQLite database missing, Force Reload DNSBL to recover!"
- fix:
https://github.com/pfsense/FreeBSD-ports/pull/1112 -
08:18 AM Regression #12382: Certificate Depth checking creates OpenVPN micro-outages every time a user authenticates after 2.5.2 upgrade
- So this bug is affecting us too. We need to route all our VPN clients traffic through the VPN and this bug is causing...
-
08:16 AM pfSense Docs Todo #12428 (Feedback): Feedback on Services — DNS Resolver — Host Overrides
- Fixed:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/86556c7171b5d22b3e2ce34cca2d9d98d98072b2
-
12:28 AM pfSense Docs Todo #12428 (Closed): Feedback on Services — DNS Resolver — Host Overrides
- *Page:* https://docs.netgate.com/pfsense/en/latest/services/dns/resolver-host-overrides.html
*Feedback:*
"IP Ad... -
08:16 AM pfSense Docs Todo #12429 (Feedback): Feedback on Bridging
- Fixed:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/1c0e9ed82c951f12336c502ed9be7eabde30cab9
-
03:10 AM pfSense Docs Todo #12429 (Closed): Feedback on Bridging
- *Page:* https://docs.netgate.com/pfsense/en/latest/bridges/index.html
*Feedback:*... -
07:40 AM Todo #12431: GUI pages should use ``POST`` for AJAX calls, not ``GET``
- True. May as well fix them all. Updated subject/category.
-
07:36 AM Todo #12431: GUI pages should use ``POST`` for AJAX calls, not ``GET``
- also:
pkg.php
services_captiveportal_vouchers.php
vendorstatus_graph.php
vpn_ipsec_phase1.php
status_graph.php... -
07:24 AM Todo #12431 (Resolved): GUI pages should use ``POST`` for AJAX calls, not ``GET``
- The AJAX buttons on the OpenVPN status page submit values using @GET@ when they should use @POST@. The variables used...
-
07:37 AM Todo #12430 (Pull Request Review): Add IPsec phase 2 BINAT subnet size input validation
-
06:06 AM Todo #12430: Add IPsec phase 2 BINAT subnet size input validation
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/408
-
04:36 AM Todo #12430 (Resolved): Add IPsec phase 2 BINAT subnet size input validation
- from https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/phase-2-nat.html#nat-types:
"NAT+IPsec cannot be configure... -
07:29 AM pfSense Packages Todo #12354 (Pull Request Review): Update haproxy-devel to mitigate CVE-2021-40346
-
02:40 AM pfSense Packages Todo #12354: Update haproxy-devel to mitigate CVE-2021-40346
- https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/136
-
07:18 AM pfSense Packages Bug #12420 (Pull Request Review): rc file is not deleted
-
01:41 AM pfSense Packages Bug #12420: rc file is not deleted
- fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/135 -
04:19 AM pfSense Packages Bug #1620: Can't use transparent proxy when using bridge.
- transparent mode on bridge works fine on pfSense 2.6.0.a.20211006.2213 with net.link.bridge.pfil_bridge=1 and net.lin...
-
12:25 AM pfSense Docs Correction #11121 (Resolved): Feedback on Services — DNS Resolver
- OpenVPN Clients info added
10/06/2021
-
03:38 PM pfSense Docs Todo #12261 (Closed): Feedback on pfSense Configuration Recipes — WireGuard VPN Client Configuration Example
-
03:38 PM pfSense Docs New Content #12417 (Closed): Add section to IPsec troubleshooting for VTI tunnels not reconnecting
-
03:36 PM pfSense Docs Correction #11176 (Feedback): Feedback on Services — DNS Resolver
- DNS Resolver docs have been updated and now include the requested content.
https://gitlab.netgate.com/docs/pfSense... -
03:36 PM pfSense Docs Todo #11417 (Feedback): Feedback on Services — DNS Resolver — DNS Resolver Advanced Options
- DNS Resolver docs have been updated and now include the requested content.
https://gitlab.netgate.com/docs/pfSense... -
03:35 PM pfSense Docs Correction #11121 (Feedback): Feedback on Services — DNS Resolver
- DNS Resolver docs have been updated and now include the requested content.
https://gitlab.netgate.com/docs/pfSense... -
03:35 PM pfSense Docs Correction #9373 (Feedback): Feedback on Services — DNS — Configuring the DNS Resolver
- DNS Resolver docs have been updated and now include the requested content.
https://gitlab.netgate.com/docs/pfSense... -
07:17 AM Bug #12426 (Rejected): Captive portal not working with 5 vlan interface in version 2.5
- There is not enough information here to classify this as a bug, and this site is not for support or diagnostic discus...
-
03:27 AM Bug #12426: Captive portal not working with 5 vlan interface in version 2.5
- The same configuration on 2.4.5-RELEASE-p1 works without issue.
the issue on 2.5.x -
03:14 AM Bug #12426 (Rejected): Captive portal not working with 5 vlan interface in version 2.5
- I use captive portal with 4 vlan interface, it works flawlessly. The problem is that when I activate the captive port...
-
07:14 AM pfSense Packages Bug #12365 (Not a Bug): PFBlockerNG - Unbound fails to start 3.1.0
- No worries, thanks for following up and letting us know. Those kinds of problems can be quite frustrating to track down.
-
04:54 AM pfSense Packages Bug #12365: PFBlockerNG - Unbound fails to start 3.1.0
- Seems this was down to a hard to find memory problem that gave random errors.
Apologies -
07:02 AM pfSense Packages Todo #12427 (New): ha-proxy: action order in the GUI is not keeped in the resulting ha-proxy configuration
- If there are (for example) 'Use Backend' and 'http-request redirect' actions are defined in the GUI in a specific ord...
10/05/2021
-
12:23 PM pfSense Docs Correction #9394 (Feedback): Feedback on Services — DNS — Configuring the DNS Resolver
- Additional updates:
1. Added a new section to the DNS Lookup page which describes how it selects servers to test.
... -
08:23 AM Regression #12069: Panic in ``pfctl`` with large numbers of states
- So can we close it now?
-
07:33 AM Feature #12425 (Rejected): Remove DHCP Leases automatically
- That is not a typical requirement for DHCP as it will automatically recycle expired leases with the appropriate setti...
-
05:25 AM Feature #12425 (Rejected): Remove DHCP Leases automatically
- Hello,
We use Pfsense's DHCP server to assign IP addresses on a WIFI network used with lots of users and BYOD. We ...
10/04/2021
-
03:33 PM pfSense Docs Correction #9394 (In Progress): Feedback on Services — DNS — Configuring the DNS Resolver
- There are multiple items here that aren't directly related:
1. The DNS test page reports times for configured serv... -
01:53 PM pfSense Packages Bug #12424 (Pull Request Review): OpenVPN silent install uses incorrect parameters
-
01:37 PM pfSense Packages Bug #12424: OpenVPN silent install uses incorrect parameters
- https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/133
-
01:07 PM pfSense Packages Bug #12424 (Resolved): OpenVPN silent install uses incorrect parameters
- The @.exe@ and @.msi@ installers require different parameters for a silent install. Currently, the same parameter is ...
-
07:20 AM Bug #12419 (Pull Request Review): Console boot output includes ``Configuring IPsec VTI interfaces`` when no VTI interfaces are configured
10/03/2021
-
08:47 PM Bug #11432: status_dhcp_leases.php doesn't load
- This is likely a duplicate of https://redmine.pfsense.org/issues/11512.
-
06:54 PM pfSense Packages Bug #12423 (Resolved): Dashboard shows "SQLite database missing, Force Reload DNSBL to recover!"
- See screenshot. The message tells to 'force reload' which I did, yet the error persists.
There's one post on the ... -
03:53 PM pfSense Packages Feature #10739: Update HAproxy-devel package to 2.2 and HAproxy to 2.0
- Hi, here many points are still undone.
-
03:34 PM pfSense Packages Todo #12354: Update haproxy-devel to mitigate CVE-2021-40346
- Hi, this is serious CVE, and still no updates? Even it possible to workaround issue by adding own check, I sure most ...
10/02/2021
-
05:58 PM pfSense Packages Bug #12188: client export breaks multi remote configurations
- Based on reviewing the bug report with OpenVPN there doesn't appear to be anything that needs to be done here. They'...
-
05:52 PM pfSense Packages Bug #12365 (Feedback): PFBlockerNG - Unbound fails to start 3.1.0
- Completed the following tests:
1. Installed pfBlockerNG-dev
2. Ran a force update and reload
3. Monitored loggin... -
05:41 PM pfSense Packages Bug #12030: Startup Errors for Avahi Package
- Jim Pingle wrote in #note-11:
> It's a package, not a part of the base system, so updates are not tied to any releas... -
03:37 PM pfSense Packages Bug #11768 (Resolved): FRR OSPF - Comment field within the ospf interfaces gets longer and longer
- Tested with FRR 1.1.0_15
Looks to be fixed. The description only matches the interface that it is actually set on... -
01:30 PM Bug #12168 (Resolved): 1:1 NAT rule with internal IP address of "Any" results in an invalid firewall rule
- Tested on the:...
-
11:45 AM Regression #12398 (Resolved): "Expiration and Replacement" section is shown twice when editing a mobile IPsec phase 2 entry
- I checked and saw it in 21.09. The fix works. The Expiration and Replacement section only appears once in 22.01:
2... -
08:44 AM Bug #12421 (New): IPV6 limiter bug
- I attempted to set a IPV6 limiter along with an IPV4 limiter. I had previously had a QOS setup which was deleted, and...
-
08:27 AM pfSense Packages Bug #11465: Input validation does not prevent multiple conflicting WireGuard peers on a single tunnel from attempting to act as default route
- Submitted PR 19 (https://github.com/theonemcdonald/pfSense-pkg-WireGuard/pull/149).
Few queries on the PR regardin... -
01:07 AM pfSense Packages Bug #12420 (Resolved): rc file is not deleted
- /usr/local/etc/rc.d/pimd.sh file is not deleted after disabling the service
-
12:38 AM Bug #12419: Console boot output includes ``Configuring IPsec VTI interfaces`` when no VTI interfaces are configured
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/407 -
12:21 AM Bug #12419 (Resolved): Console boot output includes ``Configuring IPsec VTI interfaces`` when no VTI interfaces are configured
- I am seeing VTI interface while I do not have any IPsec configuration:...
-
12:22 AM Bug #12002 (Resolved): Boot messages contain entries about configuring LAGG/VLAN/QinQ interfaces even when no entries of those types are configured
- Alhusein Zawi wrote in #note-6:
> I am seeing VTI interface while I do not have any IPsec configuration in tested vm...
10/01/2021
-
11:32 PM Bug #12002: Boot messages contain entries about configuring LAGG/VLAN/QinQ interfaces even when no entries of those types are configured
I am seeing VTI interface while I do not have any IPsec configuration in tested vm
Configuring loopback interf...-
09:13 PM Bug #12039 (Resolved): Gateway alarm always triggers IPsec restart
/etc/rc.ipsec is created
/etc/rc.gateway_alarm:
/usr/local/sbin/pfSctl \
-c "service reload dyndns ${GW...-
07:14 PM pfSense Docs Todo #12418 (Closed): AutoConfigBackup Menu Structure Documentation
- Documentation here states to use Diagnostics --> AutoConfigBackup to reach the service's configuration. It's actuall...
-
11:53 AM pfSense Packages Bug #12058: pfBlockerNG / "Cannot allocate memory" from Geo blocking IP list
- Indeed increasing that has eliminated the "Cannot allocate memory" messages.
Could the error message be improved t... -
10:45 AM pfSense Docs New Content #12417 (Feedback): Add section to IPsec troubleshooting for VTI tunnels not reconnecting
- Done:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/0a4089d8298e230db7ef3c9ab146bca409521a7e
http://sta... -
10:37 AM pfSense Docs New Content #12417 (Closed): Add section to IPsec troubleshooting for VTI tunnels not reconnecting
- Add section to IPsec troubleshooting for VTI tunnels not reconnecting. The new periodic check keep alive option in P2...
-
08:05 AM Feature #12416 (Pull Request Review): Support OpenVPN ``client-kill`` to terminate remote clients instead of clearing their session
-
03:44 AM Feature #12416: Support OpenVPN ``client-kill`` to terminate remote clients instead of clearing their session
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/406 -
01:25 AM Feature #12416 (Resolved): Support OpenVPN ``client-kill`` to terminate remote clients instead of clearing their session
- Killing a user remote access vpn session from the firewall through the pfsense GUI only works temporarily.
Less the... -
06:05 AM Feature #4881: Allow NPt to use dynamic IPv6 networks
- Hi,
So the CARP fixing is broken as of yet: the script founds the old CARP address as interface address and fixes ... -
04:42 AM pfSense Packages Bug #12033: maxmindb and _sqlite3 modules not found
- How to resolve:...
-
04:26 AM pfSense Packages Bug #12033: maxmindb and _sqlite3 modules not found
- see the same error on SG-3100 with pfSense-21.09.r.20210923.2242 and pfBlockerNG-3.1.0:...
-
12:23 AM pfSense Packages Bug #12414: DNSBL SafeSearch page displays input validation error if DoH / DoT blocking is not enabled
- fix:
https://github.com/pfsense/FreeBSD-ports/pull/1111 -
12:12 AM pfSense Packages Bug #12414 (Resolved): DNSBL SafeSearch page displays input validation error if DoH / DoT blocking is not enabled
- You need to enable DoH/DoT Blocking and select entries in the DoH/DoT Blocking List, otherwise you'll see:...
-
12:16 AM pfSense Docs Todo #12415 (Rejected): Feedback on pfSense Configuration Recipes
- *Page:* https://docs.netgate.com/pfsense/en/latest/recipes/index.html
*Feedback:*
https://forum.netgate.com/top...
09/30/2021
-
03:16 PM pfSense Docs Todo #12412 (Closed): Feedback on Virtual Private Networks — IPsec — Routed IPsec (VTI)
- Fixed (plus a bunch more that were out of date):
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/d7496cc5e09... -
11:41 AM pfSense Docs Todo #12412 (Closed): Feedback on Virtual Private Networks — IPsec — Routed IPsec (VTI)
- *Page:* https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/routed-vti.html
*Feedback:*
"The Hangouts Archive ... -
03:16 PM pfSense Docs Todo #12413 (Closed): Feedback on Services — SNMP
- Fixed (plus a bunch more that were out of date):
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/d7496cc5e09... -
11:43 AM pfSense Docs Todo #12413 (Closed): Feedback on Services — SNMP
- *Page:* https://docs.netgate.com/pfsense/en/latest/services/snmp.html
*Feedback:*
"The Hangouts Archive contain... -
07:30 AM Regression #12398: "Expiration and Replacement" section is shown twice when editing a mobile IPsec phase 2 entry
- It won't show on 2.5.2, only on recent builds of 2.6.0 (after I introduced the bug and before I fixed it) and on curr...
-
03:21 AM Regression #12398: "Expiration and Replacement" section is shown twice when editing a mobile IPsec phase 2 entry
- I tested on the 2.5.2-RELEASE (amd64). With all defaults settings under Phase 2, I couldn't replicate it.
Is there... -
04:37 AM pfSense Plus Bug #12341 (Resolved): Gateway Monitoring Percentage Not Decreasing After Gateway Packet Loss Event
- I tested on XG-7100 latest RC.
I can confirm it works as expected. I am resolving this ticket. -
04:03 AM Regression #12377 (Resolved): NAT Rule Reorder
- I couldn't replicate it on the latest pfSense plus RC nor the latest CE version. It may be closed.
09/29/2021
-
10:39 AM pfSense Docs Todo #12411 (Resolved): Feedback on High Availability — pfSense XML-RPC Config Sync Overview
- *Page:* https://docs.netgate.com/pfsense/en/latest/highavailability/xmlrpc-sync.html
*Feedback:*
A description ... -
09:19 AM Todo #12235 (Resolved): ``pfSense-upgrade`` should reinstall all packages on new version upgrades
- Fixed now
-
07:30 AM Todo #12406 (Pull Request Review): Remove unused functions
-
03:06 AM Todo #12406: Remove unused functions
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/405
-
07:22 AM Bug #12410 (Pull Request Review): 1:1 NAT edit page lists incorrect entries in the Destination field
-
02:56 AM Bug #12410: 1:1 NAT edit page lists incorrect entries in the Destination field
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/404 -
01:36 AM Bug #12410 (Resolved): 1:1 NAT edit page lists incorrect entries in the Destination field
- Destination type doesn't have "net" suffix:...
-
07:19 AM Bug #12408 (Pull Request Review): Input validation prevents creating 1:1 NAT rules on OpenVPN
-
12:56 AM Bug #12408: Input validation prevents creating 1:1 NAT rules on OpenVPN
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/403 -
12:02 AM pfSense Packages Feature #12297 (Resolved): Suricata: show actual GID:SID rule on click
09/28/2021
-
10:13 AM Todo #12235 (Feedback): ``pfSense-upgrade`` should reinstall all packages on new version upgrades
- Fixed by pfSense-upgrade 1.0_6
-
09:45 AM Todo #12235 (In Progress): ``pfSense-upgrade`` should reinstall all packages on new version upgrades
- There were some reports of crash logs showing up after upgrade and also PHP complaining about libpfctl missing during...
-
09:27 AM pfSense Docs Correction #12405 (Closed): Wireguard Docs Spelling Error
- Merged & Deployed.
09/27/2021
-
07:15 PM Feature #12267: OpenVPN option to limit concurrent connections per user
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/402
-
03:33 PM pfSense Docs Correction #12405 (Waiting on Merge): Wireguard Docs Spelling Error
- MR: https://gitlab.netgate.com/docs/pfSense-docs/-/merge_requests/24
-
03:04 PM pfSense Docs Todo #12182 (Feedback): Update IPsec to match recent changes
- Additional updates:
* https://gitlab.netgate.com/docs/pfSense-docs/-/commit/9f424c44b6c9f95f8728e3699db4f9b47fb6e699... -
02:30 PM pfSense Docs New Content #11862 (Closed): Document High Availability IPSec
- I suspect mostly you were hitting bugs in IPsec that are fixed in 2.6.0/21.09. HA IPsec was covered already, at https...
-
10:24 AM Bug #12409: Automatic-default-gateway-mode selects OpenVPN-Server interfaces
- What is this mode made for? As long as there are only valid internet gateways it is safe to use. But as soon as there...
-
09:47 AM Bug #12409 (Not a Bug): Automatic-default-gateway-mode selects OpenVPN-Server interfaces
- That's the nature of the default "automatic" mode -- when left to select it will select whatever gateway is the first...
-
09:39 AM Bug #12409 (Not a Bug): Automatic-default-gateway-mode selects OpenVPN-Server interfaces
- If the gateway selection is in automatic mode, the default gateway is switched from the monitored WAN gateway to an O...
-
08:57 AM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- We are having the same problem on SG-3100, XG-7100, SG-5100. It occours on 21.* up to 21.05.1. On 2.4.5 everything wa...
-
08:45 AM Bug #12408: Input validation prevents creating 1:1 NAT rules on OpenVPN
- I worked around the issue temporarily by adding opt-interfaces to the array,
$vpn_and_ppp_ifs = array("l2tp", "p... -
07:30 AM Bug #12408: Input validation prevents creating 1:1 NAT rules on OpenVPN
- The problem seems to be that the array value of 'openvpn' does not reflect the actual value sent by firewall_nat_1to1...
-
04:33 AM Bug #12408: Input validation prevents creating 1:1 NAT rules on OpenVPN
- Tested on Netgate pfSense Plus 21.05.1-RELEASE (amd64)
-
04:31 AM Bug #12408 (Resolved): Input validation prevents creating 1:1 NAT rules on OpenVPN
- Maybe related to https://redmine.pfsense.org/issues/11751 but for 1:1 NAT rules with OpenVPN interface selected
Wh... -
08:10 AM pfSense Packages Bug #12030: Startup Errors for Avahi Package
- It's a package, not a part of the base system, so updates are not tied to any release.
It could be updated any tim... -
06:39 AM pfSense Packages Bug #12365: PFBlockerNG - Unbound fails to start 3.1.0
- php-fpm 52285 /status_services.php: The command '/usr/local/sbin/unbound -c /var/unbound/unbound.conf' returned exi...
09/26/2021
-
05:44 PM Bug #12332: OpenVPN does not clear old Cisco-AVPair anchor rules in some cases
- I've submitted a new merge request which solves this issue. The solution is dependent on #12407
https://gitlab.netg... -
05:42 PM Feature #12407: Use deferred client connections in OpenVPN
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/402
-
05:16 PM Feature #12407 (Resolved): Use deferred client connections in OpenVPN
- New in OpenVPN 2.5 is the ability to use deferred client-connect. See @Deferred client-connect@:
https://github.com/...
09/25/2021
-
09:05 PM pfSense Packages Bug #12030: Startup Errors for Avahi Package
- Tested on RC3 of 21.09. Still present. Is this going to make it into 21.09 before it's pushed public?
-
03:15 PM pfSense Packages Feature #12297: Suricata: show actual GID:SID rule on click
- GID:SID is clickable using suricata 6.0.3_2 on 21.09.r.20210923.1842
-
11:07 AM Feature #4881: Allow NPt to use dynamic IPv6 networks
- Hi,
I made a sort of workaround: I created two php scripts (checknpt and fixnpt) which checks all NPT settings and... -
09:39 AM Regression #11512: DHCP Leases page and ARP table page fail to load if DNS is not available
- the MR/patch works as expected - https://forum.netgate.com/topic/161424/dhcp-lease-screen-not-loading/86:...
-
04:44 AM Todo #12406 (Resolved): Remove unused functions
- from https://github.com/pfsense/pfsense/blob/df945787c7b7784444381eabeeaf519361cbc2ec/src/etc/inc/pfsense-utils.inc:
... -
04:36 AM Bug #12227 (Resolved): Changing VHID on CARP VIP does not update VHID of related IP Alias VIPs
- Tested on the:...
-
01:28 AM Feature #12086 (Resolved): New Dynamic DNS Provider: deSEC
-
01:28 AM Feature #12086: New Dynamic DNS Provider: deSEC
- Tested on the :...
-
12:00 AM pfSense Packages Feature #11320 (Resolved): Update NAS client type
09/24/2021
-
11:58 PM Regression #12396: PHP Warning: Use of undefined constant ip - /etc/inc/services.inc on line 2465
- Many thanks. Do you want me to close this?
-
10:18 PM pfSense Packages Feature #11320: Update NAS client type
clients are added to clients type list
2.5.2
-
08:36 PM pfSense Packages Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
- Christian McDonald wrote in #note-9:
> Thanks.
>
> We might need to hook the gateway alarm and trigger WireGuard se... -
06:46 PM pfSense Packages Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
- Thanks.
We might need to hook the gateway alarm and trigger WireGuard service to be restarted when gateway status... -
05:35 PM pfSense Packages Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
- Christian McDonald wrote in #note-7:
> Interesting... I can replicate this if my WAN is using DHCP, but as soon as I... -
05:26 PM pfSense Packages Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
- Interesting... I can replicate this if my WAN is using DHCP, but as soon as I switch to a static address I can unplug...
-
05:13 PM pfSense Packages Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
- Christian McDonald wrote in #note-5:
> Ryan, out of curiosity, are you using DHCP are static addressing on your WAN?... -
05:09 PM pfSense Packages Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
- Ryan, out of curiosity, are you using DHCP are static addressing on your WAN?
-
05:03 PM pfSense Packages Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
- Just tested this on my 2100. I will test more next week.
I have a WireGuard tunnel to Mullvad.
# Started a persiste... -
04:26 PM pfSense Docs Correction #12405 (Closed): Wireguard Docs Spelling Error
- Warning bubble here uses "were" instead of "where". Super minor.
https://docs.netgate.com/pfsense/en/latest/recip... -
03:33 PM pfSense Docs Todo #12404 (Closed): LaTeX Error: Too deeply nested.
- Fixed:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/50d8b58a6e5c79cb10b8ee400f02d3f4ccc3be39
https://g... -
02:50 PM pfSense Docs Todo #12404 (Closed): LaTeX Error: Too deeply nested.
- PDF builds are failing with an error:...
-
12:38 PM pfSense Docs Todo #12182: Update IPsec to match recent changes
Updated EAP-TLS document and the Windows IKEv2 client doc. There was quite a bit of overlap that is now greatly sim...-
12:36 PM pfSense Docs Todo #12261 (Feedback): Feedback on pfSense Configuration Recipes — WireGuard VPN Client Configuration Example
- PR merged and deployed.
-
12:25 PM pfSense Docs Todo #12261 (Pull Request Review): Feedback on pfSense Configuration Recipes — WireGuard VPN Client Configuration Example
-
12:02 PM Bug #11863 (Resolved): Unable to create nested URL aliases
-
10:59 AM Bug #11863: Unable to create nested URL aliases
- Working as expected on:...
-
10:36 AM Regression #11512 (Pull Request Review): DHCP Leases page and ARP table page fail to load if DNS is not available
-
09:09 AM Regression #11512: DHCP Leases page and ARP table page fail to load if DNS is not available
- We don't yet know if this issue affects Plus. No reports originating from that version have been observed.
-
08:34 AM Regression #11512: DHCP Leases page and ARP table page fail to load if DNS is not available
- optimization:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/401 -
08:13 AM pfSense Packages Bug #12205 (Pull Request Review): Certificate Manager page doesn't show Squid used certificates
-
05:07 AM pfSense Packages Bug #12205: Certificate Manager page doesn't show Squid used certificates
- https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/130
-
07:37 AM pfSense Packages Bug #12403 (Resolved): WireGuard tunnel and peer edit pages do not prevent browser auto-fill
- The WireGuard tunnel (@vpn_wg_tunnels_edit.php@) and peer (@vpn_wg_peers_edit.php@) edit pages do not prevent the bro...
-
03:58 AM Feature #4881: Allow NPt to use dynamic IPv6 networks
- I found this issue two days ago while I tried to provide internet access via IPv6 to my OpenVPN clients.
Right now... -
02:50 AM Bug #11337 (Resolved): Interface column empty in list of GIF tunnels when using IP Alias on CARP VIP as Interface
- Tested on the:...
-
12:46 AM pfSense Docs New Content #12402 (Rejected): Add recipe for configuring Telegram to receive notifications from pfSense software
- *Page:* https://docs.netgate.com/pfsense/en/latest/config/advanced-notifications.html
*Feedback:*
How to config...
09/23/2021
-
10:57 PM pfSense Packages Feature #11972: Arpwatch - Add support for Telegram notifications
there is no option to add Telegram in Arpwatch page.
Tested :
2.6.0.a.20210923.0100
&
21.05.1-
09:18 PM Bug #12401 (New): Traffic graphs with untagged and tagged VLAN on same interface
- My setup is a single interface with multiple VLANs. Still using VLAN 1 as the LAN VLAN but got a couple others.
Sa... -
04:01 PM pfSense Docs Todo #12182: Update IPsec to match recent changes
- Additional updates for mobile IPsec:
* https://gitlab.netgate.com/docs/pfSense-docs/-/commit/a19ea35d7b35b0617bd40... -
02:36 PM pfSense Packages Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
- In rebooting my ISP modem many times and tracking the behavior of pfSense and WireGuard, I observed that when the mod...
-
10:55 AM pfSense Packages Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
- Christian McDonald wrote in #note-1:
> Thanks for the tag, I will investigate this and circle back.
Awesome! Grea... -
10:35 AM pfSense Packages Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
- Thanks for the tag, I will investigate this and circle back.
-
09:26 AM pfSense Packages Bug #12399 (Resolved): WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
- Hi Christian,
Really appreciate your work on the Wireguard package for pfSense :)
Sadly, there seems to be a show... -
02:03 PM Regression #12382: Certificate Depth checking creates OpenVPN micro-outages every time a user authenticates after 2.5.2 upgrade
- The solution here should be to implement async auth plugin. It's already being done with @/usr/local/sbin/ovpn_auth_v...
-
03:20 AM Regression #12382: Certificate Depth checking creates OpenVPN micro-outages every time a user authenticates after 2.5.2 upgrade
- Just want to thank you Brett for the debug of the problem that unfortunately affects us as well.
Doesn't change an... -
01:33 PM Revision 863ab7d4: Fix IPsec P2 Keep Alive mobile check. Issue #12398
-
01:29 PM pfSense Docs Correction #12400: NAT 1:1 documentation - multi-wan information
- Dear Jim thank you for the quick reply.
I do agree on the concept of NAT not controlling outgoing traffic and how th... -
01:24 PM pfSense Docs Correction #12400: NAT 1:1 documentation - multi-wan information
- NAT never controls where traffic exits the firewall in any context (1:1, outbound, port forwards). NAT only manipulat...
-
01:10 PM pfSense Docs Correction #12400 (Resolved): NAT 1:1 documentation - multi-wan information
- Dear pfSense team,
I would like to submit a suggestion to the NAT 1:1 page. This suggestion comes from an issue I ... -
12:12 PM Feature #4881: Allow NPt to use dynamic IPv6 networks
- I'm going to chime in to the usefulness of this. My use case is a little different, but the same principle. I have ...
-
08:52 AM Regression #12398 (Feedback): "Expiration and Replacement" section is shown twice when editing a mobile IPsec phase 2 entry
- Fixed in commit:863ab7d4
-
08:30 AM Regression #12398: "Expiration and Replacement" section is shown twice when editing a mobile IPsec phase 2 entry
- The type bit wasn't the case, it was the remoteid type which was lost but that isn't necessary from what I can tell. ...
-
08:16 AM Regression #12398 (Resolved): "Expiration and Replacement" section is shown twice when editing a mobile IPsec phase 2 entry
- When editing a phase 2 entry for a mobile IPsec tunnel the "Expiration and Replacement" section is shown twice.
Th... -
07:43 AM Feature #12342 (Pull Request Review): Dynamic DNS client proxy support
-
05:01 AM Feature #12342: Dynamic DNS client proxy support
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/399
-
07:38 AM Bug #12385 (Pull Request Review): deleteVIP() does not check 1:1 NAT and Outbound NAT rules
-
07:23 AM Bug #12389 (Pull Request Review): Help text for RAM disk settings does not mention Captive Portal data
-
12:43 AM Bug #12389: Help text for RAM disk settings does not mention Captive Portal data
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/398
-
01:51 AM Bug #10955: XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
- Joachim Tingvold wrote in #note-20:
> So, while going through the configuration to sanitize them, I noticed the foll...
09/22/2021
-
10:22 PM Bug #11923: Input validation not working for 1:1 NAT entries using an alias as a destination
- Confirmed that bug is still present in 2.5.2. Running most recent version and I cannot create 1:1 NAT mappings with a...
-
02:56 PM pfSense Docs Todo #12182: Update IPsec to match recent changes
- Additional Updates:
* https://gitlab.netgate.com/docs/pfSense-docs/-/commit/091b27f589e2ca992b4fb40aeebaef31c65131... -
12:39 PM Revision 0512975e: Fixes redmine #12396
-
09:09 AM Feature #12397 (Resolved): Distinguish between policy-based and route-based entries on IPsec status SPD tab
- The IPsec Status SPD tab at @status_ipsec_spd.php@ prints information from the security policy database and it curren...
-
08:50 AM Regression #12396: PHP Warning: Use of undefined constant ip - /etc/inc/services.inc on line 2465
- Jim Pingle wrote in #note-1:
> Most likely the latest version of PHP in use now is being more strict about such thin... -
08:49 AM Regression #12396 (Feedback): PHP Warning: Use of undefined constant ip - /etc/inc/services.inc on line 2465
-
07:56 AM Regression #12396 (Pull Request Review): PHP Warning: Use of undefined constant ip - /etc/inc/services.inc on line 2465
- Odd that it would just start giving an error now since that line, as obviously wrong as it is, hasn't changed in 7 ye...
-
12:59 AM Regression #12396 (Resolved): PHP Warning: Use of undefined constant ip - /etc/inc/services.inc on line 2465
- Hi Team,
Could you please confirm. Many thanks.
Issue identified following the first reboot, after fully complet... -
03:29 AM pfSense Packages Feature #9833: ACME: add ability to use custom ACME server
- +1 Would be nice to have this. Invalid certs are just not cool anymore with ACME available. Should be possible to sel...
09/21/2021
-
04:32 PM pfSense Docs New Content #12395 (New): FRR: Add information about the private use AS reservation from RFC 6996
- *Page:* https://docs.netgate.com/pfsense/en/latest/packages/frr/bgp/required-info.html
*Feedback:*
Would be hel... -
03:19 PM pfSense Docs Todo #12182: Update IPsec to match recent changes
- Additional updates:
* https://gitlab.netgate.com/docs/pfSense-docs/-/commit/5f6977cf1b44daa49656c2ba2f050f4cccb387... -
03:06 PM pfSense Docs Todo #12394 (Closed): Broken link on Redmine home page
- Fixed, thanks!
-
02:54 PM pfSense Docs Todo #12394 (Closed): Broken link on Redmine home page
- https://redmine.pfsense.org home page has a link:
Read the [Reporting Issues with pfSense Software] article comple... -
02:48 PM Bug #12393 (New): Priority of qOthersLow higher than default queues
- I posted in the forum (https://forum.netgate.com/post/1002109) but received no response so far.
In the wizard for ... -
09:58 AM Bug #12368 (Closed): Disk widget alignment issue when only two items are in the list
- Looks good here on both ZFS and UFS systems on RC2.
09/20/2021
-
04:17 PM Revision b9885720: Bump up the config version to match a change in plus.
-
03:46 PM Feature #12392 (Resolved): Allow the selection of "any" interface in floating rules
- Currently, a floating rule can be created without specifying an interface which allows for filtering on interfaces no...
-
03:37 PM pfSense Docs Todo #12182: Update IPsec to match recent changes
- Additional WIP updates:
* https://gitlab.netgate.com/docs/pfSense-docs/-/commit/f5a285f648d86f4d4c2115537cf7cbae6f... -
12:06 PM pfSense Docs Todo #12309 (Closed): Add Light Pattern/Light Meaning for 6100 to Documentation Similar to Other Hardware
- LED settings have been added to https://docs.netgate.com/pfsense/en/latest/solutions/netgate-6100/io-ports.html#front...
-
09:32 AM pfSense Docs Todo #12309 (In Progress): Add Light Pattern/Light Meaning for 6100 to Documentation Similar to Other Hardware
-
10:24 AM Bug #12391 (Pull Request Review): Uninitialized config variable in ```interface_assign.php```
-
10:21 AM Bug #12391: Uninitialized config variable in ```interface_assign.php```
- plus: https://gitlab.netgate.com/pfSense/factory/-/merge_requests/29
ce: https://gitlab.netgate.com/pfSense/pfSense/... -
10:13 AM Bug #12391 (Resolved): Uninitialized config variable in ```interface_assign.php```
- ...
-
07:39 AM Bug #12390 (Duplicate): i18n zh-hant-TW translate error, incomplete HTML "a" tag
- Duplicate of #9344
-
06:31 AM Bug #12390 (Duplicate): i18n zh-hant-TW translate error, incomplete HTML "a" tag
- Page path: /vpn_openvpn_server.php?act=edit
Source Code: https://github.com/pfsense/pfsense/blob/master/src/usr/loca... -
07:38 AM Bug #12274 (Resolved): Unbound fails to start if its configuration references a python script which does not exist
-
07:37 AM Bug #12389: Help text for RAM disk settings does not mention Captive Portal data
- This can wait, it's not critical for it to be in this release.
-
07:13 AM pfSense Packages Bug #11888 (Resolved): FreeRADIUS starts twice by /etc/rc.start_packages
-
06:50 AM Bug #11437 (Closed): WireGuard group is not printed in the interface column of the NAT rule list
- Not an issue with package.
-
06:49 AM Bug #11587 (Closed): WireGuard interfaces do not have data on traffic graphs
- WireGuard package and latest kmod correctly reports traffic.
-
06:48 AM Bug #11538 (Closed): WireGuard Panic
- Unable to hit this panic on wireguard package
-
06:47 AM Bug #11691 (Closed): WireGuard MSS Clamping and TCP traffic issues after reboot.
- Doesn't seem to be an issue with latest WireGuard package.
-
06:46 AM Feature #11374 (Closed): WireGuard Status in GUI
-
01:36 AM Feature #11374: WireGuard Status in GUI
- I believe between the status page and the dashboard widget this request is now satisfied.
-
12:29 AM Revision 8e2de557: Keep 'enableserial_force' in /conf when a factory reset is performed.
- Ticket: #6880
09/19/2021
-
10:16 AM Feature #11588: Automatically suggest next IP address in Wireguard interface subnet when creating a peer
- Opened PR 145 (https://github.com/theonemcdonald/pfSense-pkg-WireGuard/pull/145) to resolve this feature request.
Cu...
09/18/2021
-
09:50 PM Bug #12274: Unbound fails to start if its configuration references a python script which does not exist
- Tested in RC builds of pfSense Plus. Confirmed no longer an issue.
-
09:46 PM Regression #12377: NAT Rule Reorder
- Tested and confirmed fixed with patch. Tested on RC1 and recreated the bug. Applied the patch and bug went away. A...
-
09:28 PM pfSense Plus Bug #12341: Gateway Monitoring Percentage Not Decreasing After Gateway Packet Loss Event
- Odd. Not sure why I'm the only one that can't reproduce this one, but this can be closed out. Clearly my testing is...
-
04:01 PM Bug #12389 (Resolved): Help text for RAM disk settings does not mention Captive Portal data
- Under System>Advanced>Miscellaneous -> RAM Disk Settings > Help text doesn't list captive portal data.
The current... -
01:38 PM pfSense Packages Bug #11695 (Resolved): PHP error in the last step of the wizard
- Tested in:
21.09-RC (amd64)
built on Wed Sep 15 09:10:53 EDT 2021
FreeBSD 12.2-STABLE
The wizard completes su... -
12:31 PM Bug #11846 (Resolved): Logging configuration added by a package is not removed on uninstall
- Tested with haproxy-devel 0.62_4
/var/etc/syslog.d/haproxy.log.conf is removed on deinstall and no errors are pres... -
11:10 AM pfSense Packages Todo #12351: Remove non-functional feeds
- I checked with pfBlockerNG-devel 3.1.0. Some of the feeds listed above are removed, but some are still there.
http... -
07:07 AM Bug #12388: Captive Portal input validation for "After authentication Redirection URL" and "Blocked MAC address redirect URL" is swapped
- hello, how can i solve this problem with this page showing? eyeg
09/17/2021
-
11:38 PM pfSense Packages Bug #11888: FreeRADIUS starts twice by /etc/rc.start_packages
seems fixed
[2.5.2-RELEASE][root@pfSense.home.arpa]/root: /etc/rc.start_packages
Starting package FRR...done.
...-
01:28 PM pfSense Docs Todo #12182: Update IPsec to match recent changes
- Additional updates:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/de91716aacbf5581c366dea884c2543ebae3c769... -
10:08 AM Bug #12368: Disk widget alignment issue when only two items are in the list
- This looks better on the latest CE snapshot. Will need to wait for a new Plus build to test it there.
09/16/2021
-
10:25 PM pfSense Packages Bug #11961: FRR OSPF add unwanted area 0 authentication to router ospf
adding Authentication Type in area tab works (peering)
!
interface em0
ip ospf authentication
ip ospf au...-
04:20 PM Bug #11863: Unable to create nested URL aliases
- Verified working as expected on:...
-
03:40 PM Revision 3bab20ed: Some small cleanups with disk widget and library code.
-
03:34 PM Regression #12382: Certificate Depth checking creates OpenVPN micro-outages every time a user authenticates after 2.5.2 upgrade
- Well, obviously you know your userbase better than I do, so if more people would be negatively impacted by reverting ...
-
07:13 AM Regression #12382: Certificate Depth checking creates OpenVPN micro-outages every time a user authenticates after 2.5.2 upgrade
- If it works for you to revert that change, by all means do so, but more people were negatively impacted by the other ...
-
07:07 AM Regression #12382: Certificate Depth checking creates OpenVPN micro-outages every time a user authenticates after 2.5.2 upgrade
- Should be improved in #11829
-
03:33 PM pfSense Docs Todo #12182 (In Progress): Update IPsec to match recent changes
- Work in progress update:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/dfa09be3d35387aa3d3b5665591067f5d2b... -
02:44 PM Regression #12384 (Resolved): Segmentation fault when loading ALTQ traffic shaping rules using FAIRQ
- Thanks for testing and following up!
I'm going to close this out for now, but if you happen to be able to replicat... -
02:32 PM Regression #12384: Segmentation fault when loading ALTQ traffic shaping rules using FAIRQ
- I just tested this on the 2.6.0.a.20210916.0100 snapshot, and I can no longer reproduce the problem there, so this do...
-
07:16 AM Regression #12384 (Feedback): Segmentation fault when loading ALTQ traffic shaping rules using FAIRQ
- Can you replicate this on a CE 2.6.0 or Plus 21.09 snapshot? It may already be corrected there.
-
02:26 PM pfSense Docs Todo #12273: Feedback on pfSense Configuration Recipes — Configuring DNS over TLS
- Thanks for catching that! I've pushed a fix. If it's not up yet, it will be momentarily when the build finishes.
h... -
01:56 PM pfSense Docs Todo #12273: Feedback on pfSense Configuration Recipes — Configuring DNS over TLS
- Jim Pingle wrote in #note-2:
> Done.
>
> https://gitlab.netgate.com/docs/pfSense-docs/-/commit/489cafdc46a02979926e0... -
08:39 AM pfSense Docs Todo #12273 (Resolved): Feedback on pfSense Configuration Recipes — Configuring DNS over TLS
- Done.
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/489cafdc46a02979926e0d36409a6cd01bebe957
-
08:20 AM pfSense Docs Todo #12273 (In Progress): Feedback on pfSense Configuration Recipes — Configuring DNS over TLS
-
12:03 PM Bug #12388 (Pull Request Review): Captive Portal input validation for "After authentication Redirection URL" and "Blocked MAC address redirect URL" is swapped
-
11:45 AM Bug #12388: Captive Portal input validation for "After authentication Redirection URL" and "Blocked MAC address redirect URL" is swapped
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/395 -
07:53 AM Bug #12388 (Resolved): Captive Portal input validation for "After authentication Redirection URL" and "Blocked MAC address redirect URL" is swapped
- On @services_captiveportal.php@ the input validation for "After authentication Redirection URL" and "Blocked MAC addr...
-
11:30 AM Bug #12368 (Feedback): Disk widget alignment issue when only two items are in the list
- Fixed
-
09:38 AM pfSense Packages Bug #12167: BGP TCP setkey not set if neighbor is in peer group
- Testing this I notice the following:
There is no way to inherit the MD5 settings from the peer group. It must be s... -
09:25 AM pfSense Packages Bug #12167: BGP TCP setkey not set if neighbor is in peer group
- Target package version: v1.1.0_14
-
08:56 AM Bug #12202 (Resolved): When a CARP VIP VHID change is synchronized to a secondary node, the CARP VIP is removed from the interface and the old VHIDs remain active
- This specific case works now. Thank you.
Tested on:
2.6.0-DEVELOPMENT (amd64)
built on Thu Sep 16 01:10:58 EDT 2... -
08:20 AM Feature #2668 (Feedback): Support aliases in OpenVPN local/remote/tunnel network fields
- Picked back to @plus-RELENG_21_09@.
-
08:19 AM Regression #12377 (Feedback): NAT Rule Reorder
- Picked back to @plus-RELENG_21_09@.
-
07:31 AM Bug #12385: deleteVIP() does not check 1:1 NAT and Outbound NAT rules
- This should not be enforced strictly. Not all NAT rules need a VIP. It's possible someone may be removing an unnecess...
-
01:14 AM Bug #12385: deleteVIP() does not check 1:1 NAT and Outbound NAT rules
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/394
-
12:22 AM Bug #12385 (Rejected): deleteVIP() does not check 1:1 NAT and Outbound NAT rules
- It is possible to delete the Virtual IP that is used in 1:1 NAT rules (destination) and Outbound NAT rules (Translati...
-
07:26 AM pfSense Packages Bug #12386 (Pull Request Review): ```bgp as-path``` and ```bgp community-list``` are present in configuration even when BGP daemon is not enabled
-
12:51 AM pfSense Packages Bug #12386: ```bgp as-path``` and ```bgp community-list``` are present in configuration even when BGP daemon is not enabled
- fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/127 -
12:34 AM pfSense Packages Bug #12386 (Resolved): ```bgp as-path``` and ```bgp community-list``` are present in configuration even when BGP daemon is not enabled
- This breaks config loading:...
-
07:15 AM Bug #12387 (Not a Bug): Problem sending logs without hostname
- That isn't possible on 2.4.x as it's a limitation of the syslog format used there. It is possible to change the syslo...
-
02:40 AM Bug #12387 (Not a Bug): Problem sending logs without hostname
- I have three pfsense with version 2.4.5-RELEASE-p1 and they send logs to graylog 4.1, all the sending works correctly...
09/15/2021
-
10:06 PM Regression #12384 (Resolved): Segmentation fault when loading ALTQ traffic shaping rules using FAIRQ
- This is the return of Bug #11550 in pfSense 2.5.2.
I originally filed my report as a reply to that bug, but I real... -
09:52 PM Bug #12383: Typos in interfaces_assign.php configuration change description strings
- PR https://github.com/pfsense/pfsense/pull/4538
-
09:52 PM Bug #12383 (Resolved): Typos in interfaces_assign.php configuration change description strings
- 3 instances of "assignment" are misspelled as "assignement"
Lines 233, 351, 406. -
08:57 PM Revision b146b9b3: Fix Disks widget UI on UFS systems
- ```
PHP 7.4.22 | 10 parallel jobs
............................................................ 60/279 (21 %)
.......... -
08:22 PM Regression #12382 (New): Certificate Depth checking creates OpenVPN micro-outages every time a user authenticates after 2.5.2 upgrade
- We're running several OpenVPN servers on a single pfSense box at our office, and ever since upgrading from 2.4.5p1 to...
-
06:23 PM Bug #11481 (Confirmed): NAT Reflection does not work when "NAT Reflection mode for port forwards" is set to "pure nat"
- I ran into this issue and was able to get more details. I tested this on both 2.4.5p1 and 21.05 with the following se...
-
03:09 PM pfSense Docs Correction #11151 (Closed): avahi_settings.php is missing an entry in help.php
- Redirect added using new method. Help link works now on 21.09.
-
02:51 PM pfSense Docs Todo #12375 (Closed): Feedback on pfSense Configuration Recipes — Accessing the Firewall Filesystem with SCP
- Given that any version released in the past year should support this, if the user isn't updating it, that's on them.
... -
12:12 AM pfSense Docs Todo #12375 (Closed): Feedback on pfSense Configuration Recipes — Accessing the Firewall Filesystem with SCP
- *Page:* https://docs.netgate.com/pfsense/en/latest/recipes/scp-access.html
*Feedback:*
At least WinSCP 5.18 bet... -
02:33 PM pfSense Docs Todo #12360 (Closed): Remove ALTQ Note on XG-7100 SFP+ Modules
- Merged and deployed.
-
10:32 AM pfSense Docs Todo #12360: Remove ALTQ Note on XG-7100 SFP+ Modules
- https://gitlab.netgate.com/docs/pfsense-platforms/-/merge_requests/11
-
01:17 PM Revision 4bd90d66: Fix PHP error on firewall_aliases_edit.php page. Issue #2668
-
01:10 PM pfSense Docs Correction #9228 (Resolved): Feedback on Hardware — Hardware Sizing Guidance
- No additional feedback, so closing.
-
01:10 PM pfSense Docs New Content #9753 (New): Feedback on Installing and Upgrading — Writing Disk Images
-
01:10 PM pfSense Docs New Content #10225 (Resolved): Add cryptographic hardware info to the SG-3100 manual
- No additional feedback, so closing.
-
01:10 PM pfSense Docs Correction #11162 (Resolved): Feedback on Backup and Recovery — Making Backups in the GUI
- No additional feedback, so closing.
-
01:09 PM pfSense Docs Todo #11716 (Resolved): Feedback on Network Address Translation — Port Forwards
- No additional feedback, so closing.
-
01:09 PM pfSense Docs New Content #11796 (Resolved): Document the FRR Package
- No additional feedback, so closing.
-
01:08 PM pfSense Docs Todo #11962 (Resolved): Feedback on Firewall — Aliases
- No additional feedback, so closing.
-
01:07 PM pfSense Docs Todo #12372 (Resolved): Update "Download" documentation
-
10:53 AM Feature #2668 (Waiting on Merge): Support aliases in OpenVPN local/remote/tunnel network fields
- Needs picked back to the @plus-RELENG_21_09@ branch after additional approval.
-
08:48 AM Feature #2668 (Feedback): Support aliases in OpenVPN local/remote/tunnel network fields
- Merged
-
07:07 AM Feature #2668 (Pull Request Review): Support aliases in OpenVPN local/remote/tunnel network fields
-
02:25 AM Feature #2668: Support aliases in OpenVPN local/remote/tunnel network fields
- PHP error on firewall_aliases_edit.php page if OpenVPN server description field is empty...
-
10:52 AM Regression #12377 (Waiting on Merge): NAT Rule Reorder
- Needs picked back to the @plus-RELENG_21_09@ branch after additional approval.
-
08:25 AM Regression #12377 (Feedback): NAT Rule Reorder
- Applied in changeset commit:fa7563991540f98166e2ca5e537229a7f73615d4.
-
07:06 AM Regression #12377 (Pull Request Review): NAT Rule Reorder
-
04:54 AM Regression #12377: NAT Rule Reorder
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/392 -
04:15 AM Regression #12377 (Resolved): NAT Rule Reorder
- Fatal error: Uncaught Error: Call to undefined function reorderoutNATrules() in /usr/local/www/firewall_nat_out.php:5...
-
09:58 AM pfSense Packages Bug #12381: mOTP with RADIUS drops the VPN connection after 60 minutes
- I don't think that's FreeRADIUS, but OpenVPN. IIRC OpenVPN defaults to reconnecting every 60 minutes, but can be chan...
-
09:46 AM pfSense Packages Bug #12381 (Rejected): mOTP with RADIUS drops the VPN connection after 60 minutes
- from https://forum.netgate.com/topic/165967/2fa-mfa-with-radius-drops-the-vpn-connection-after-60-minutes:...
-
09:53 AM Revision fa756399: Rename incorrect reorder function name in firewall_nat_out.php. Fixes #12377
-
07:05 AM pfSense Docs Todo #12376 (Duplicate): Feedback on pfSense Configuration Recipes
- Duplicate of #9370
-
12:23 AM pfSense Docs Todo #12376 (Duplicate): Feedback on pfSense Configuration Recipes
- *Page:* https://docs.netgate.com/pfsense/en/latest/recipes/index.html
*Feedback:*
Outdated screenshots (pfSense... -
01:00 AM Bug #12020 (Resolved): OpenVPN RADIUS-based firewall rules use incorrect port ranges
- RADIUS ACL:...
09/14/2021
-
07:15 PM Revision afb0fdd9: Remove unused net/realtek-re-kmod from package repo
-
04:02 PM Bug #10955: XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
- Thank you for the info. With the proposed fix, this scenario should not be an issue.
-
03:26 PM Bug #10955: XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
- So, while going through the configuration to sanitize them, I noticed the following;
* node1 and node2 had VLAN int... -
01:32 PM Bug #11818: Mixed use of aliases in a port range produces unloadable ruleset
- Also confirming the attempted combination use of aliases and ports on 2.6 Development:...
-
01:22 PM Bug #11818 (Resolved): Mixed use of aliases in a port range produces unloadable ruleset
-
01:16 PM Bug #11818: Mixed use of aliases in a port range produces unloadable ruleset
- This is fixed in 21.09.
Trying to use a combination of aliases and ports is rejected:... -
11:57 AM Bug #12374 (Resolved): Update python to address vulnerabilities < 3.8.12
- Details here:
https://vuxml.freebsd.org/freebsd/145ce848-1165-11ec-ac7e-08002789875b.html
Latest 21.09 uses pytho... -
11:11 AM Bug #12373 (Resolved): Update mpd5 to address vulnerabilities in < 5.9_2
- https://vuxml.freebsd.org/freebsd/f55921aa-10c9-11ec-8647-00e0670f2660.html:
Version 5.9_2 contains security fix f... -
11:02 AM pfSense Docs Todo #12372 (Feedback): Update "Download" documentation
- Done:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/cd42f582f93cb7ee4e6e2833d5d95eb67bf53233
https://do... -
10:11 AM pfSense Docs Todo #12372 (Resolved): Update "Download" documentation
- There are a few problems with the download documentation at @/install/download-installer-image.html@, including:
*... -
09:51 AM pfSense Packages Bug #12058: pfBlockerNG / "Cannot allocate memory" from Geo blocking IP list
- Viktor, thanks for suggesting the duplicate. I'll see if the config change there also fixes my issue and report back...
-
09:44 AM pfSense Packages Bug #12058 (Duplicate): pfBlockerNG / "Cannot allocate memory" from Geo blocking IP list
- Duplicate of #6814
-
09:37 AM pfSense Packages Bug #11590 (Closed): pfBlocker Issue when IPv6 is disabled
-
08:36 AM Bug #12371 (Resolved): Remove subnet overlap check on LAN interfaces when using 6rd
- Hello,
Can the subnet overlapping check on the lan interfaces be removed if using 6rd? (See attached screenshot)
... -
07:40 AM Bug #12366 (Pull Request Review): Rotation settings for individual log files do not take effect after saving
-
05:09 AM Bug #12366: Rotation settings for individual log files do not take effect after saving
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/390 -
07:37 AM Feature #12370: Add limiters to Queue column on firewall rule list
- There are already a lot of columns on that page. While I don't see Limiters being added as a separate column, they co...
-
07:30 AM Feature #12370 (New): Add limiters to Queue column on firewall rule list
- could you add limiters column to firewall rules page for each interface to
show which firewall rules contain limiter... -
06:40 AM pfSense Packages Feature #12369 (New): Skip If No Content issue
- Even if *Skip If No Content* is ticked if running a command will always result in an email being sent as the command ...
09/13/2021
- 03:01 PM Revision 9962b011: Move hwcrypto call to sysinfo widget
-
02:25 PM Bug #10955 (Pull Request Review): XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
-
01:15 PM Bug #10955: XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
I've submitted the following to fix the reported issue:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_request...-
09:12 AM Bug #10955: XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
- I expect my two 2.5.2 HA nodes to come online within a day or two, and I'll provide sanitized config.xml from them bo...
-
09:05 AM Bug #10955: XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
- Bridges wouldn't be valid with HA, so that isn't a supported configuration. If the interfaces mismatch, that also wou...
-
12:13 PM Regression #12340 (Closed): Factory Reset Menu Broken in webConfigurator
-
08:24 AM Bug #12362 (Pull Request Review): Validation when deleting a VIP does not prevent deleting a CARP VIP used as a parent for an IP Aliases VIP
-
08:16 AM Feature #12349 (Closed): Disks dashboard widget to replace Disk Usage section of System Information widget
- Upgraded and tested on a variety of different filesystem type installs (old and newer ZFS with different dataset layo...
-
08:15 AM Bug #12368 (Closed): Disk widget alignment issue when only two items are in the list
- A simple UFS install only has @/@ and @/var/run@ in the filesystem list and by default the new Disks widget doesn't p...
-
07:52 AM Bug #12346: Deny SSH access for ``admin`` and ``root`` users when the ``admin`` GUI account is disabled
- Updating subject for release notes
-
07:47 AM Bug #12346 (Closed): Deny SSH access for ``admin`` and ``root`` users when the ``admin`` GUI account is disabled
-
07:43 AM Bug #12211 (Closed): Email Notifications not working with Special Characters in Password
- I suspect you are correct. There is a forum thread about this as well and it's come to a similar conclusion. There ar...
-
07:37 AM Todo #12367 (New): ZFS: Do not show memstick disk on target list
- As we did for UFS in the past, do not present memstick device used to boot install as an option of target disk for us...
-
07:29 AM Bug #12323 (Resolved): IPsec Phase 2 entry incorrectly orders proposals in AH mode
09/12/2021
-
10:22 PM Bug #10955: XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
- I was able to reliably reproduce this. I believe the issue is within @find_interface_ip()@. If the interface does not...
-
12:02 PM Bug #10955: XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface
- I can confirm that I see this on a freshly installed 2.5.2 HA setup.
I have not yet found a way to actually be abl... -
04:42 PM Bug #12366 (Resolved): Rotation settings for individual log files do not take effect after saving
- Clicking @Save@ for the settings on any of the specific log categories in "Status / System Logs" does not immediately...
-
11:49 AM Bug #9263: Incorrect ICMP reply when using limiters
- Same on 2.5 and 2.6
09/11/2021
-
10:03 PM Bug #12095: Memory leak in pcscd
- Philip Cook wrote in #note-14:
> This memory leak is rather problematic.
> 2.5.2-RELEASE (amd64)
> Uptime 64 Da... -
02:30 AM Bug #12095: Memory leak in pcscd
- This memory leak is rather problematic.
2.5.2-RELEASE (amd64)
Uptime 64 Days 22 Hours 02 Minutes 06 Seconds
<... -
12:37 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
same issue on 2.5.2-RELEASE - date 20211109
3 years...-
12:19 PM Bug #12346: Deny SSH access for ``admin`` and ``root`` users when the ``admin`` GUI account is disabled
- tested on XG-7100 running 21.09.b.20210911.0100
was unable to ssh as admin following disabling admin from GUI user... -
12:01 PM pfSense Packages Bug #12263 (Resolved): Snort package unable to save a new or edited Pass List when Language is set for anything other than English
- Tested with Snort 4.1.4_3. I was able to save pass lists without issues with languages other than English selected. M...
-
11:11 AM Bug #12211: Email Notifications not working with Special Characters in Password
- I tested this with a Gmail account using special characters in the password and was able to send SMTP alerts in 2.5.2...
-
11:08 AM pfSense Plus Bug #12341: Gateway Monitoring Percentage Not Decreasing After Gateway Packet Loss Event
- tested on XG-7100 running 21.09.b.20210911.0100
ensured gateway monitoring was enabled, then created icmp block on... -
08:43 AM Bug #11922 (Resolved): Certificate manager reports CA as in use by an LDAP server when LDAP is not configured for TLS
- Tested on the:...
-
08:25 AM Bug #12253 (Resolved): IPv6 gateway for an interface is not shown on ``status_interfaces.php`` if the interface does not also have an IPv4 gateway
- Tested on the:...
-
07:55 AM Bug #12196 (Resolved): IPsec settings fail to apply when a remote gateway is set to an FQDN and there are no DNS servers available
- Tested on the:...
-
06:45 AM Bug #12362: Validation when deleting a VIP does not prevent deleting a CARP VIP used as a parent for an IP Aliases VIP
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/387 -
01:13 AM Bug #12362 (Resolved): Validation when deleting a VIP does not prevent deleting a CARP VIP used as a parent for an IP Aliases VIP
- It is possible to delete a CARP that is used by an IP aliases as the parent
@deleteVIP()@ needs checking
see al... -
05:55 AM pfSense Packages Bug #12365 (Not a Bug): PFBlockerNG - Unbound fails to start 3.1.0
- Hi;
Unbound fails to start after reloading pfBlockerNG. Seems to have only started with PfBlockerNG - 3.1.0
I h... -
01:40 AM Regression #12324 (Resolved): Hash algorithm GUI options are disabled after switching a phase 2 entry to AH mode
- Tested on the:...
09/10/2021
-
10:09 PM Bug #12323: IPsec Phase 2 entry incorrectly orders proposals in AH mode
order seems ok
ah_proposals = sha512-modp2048,sha384-modp2048,sha256-modp2048,sha1-modp2048,md5-modp2048,aesxcbc...-
01:04 PM Bug #12323: IPsec Phase 2 entry incorrectly orders proposals in AH mode
- Updating subject for release notes.
-
10:03 PM pfSense Plus Bug #12341: Gateway Monitoring Percentage Not Decreasing After Gateway Packet Loss Event
- This was tested in Firefox 91, per the original post. It's possible it's caching, but it's odd the rest of the field...
-
09:58 PM pfSense Packages Bug #12030: Startup Errors for Avahi Package
- Is this patched into the latest build? I'm seeing this still present in the September 10th builds.
-
03:57 PM Revision 8558539a: Do not restart IPsec on every gateway alarm. Fixes #12039
-
03:50 PM Revision dbe51a34: additional fix #7801 Include IPsec P2 address type in vpn_networks
-
02:12 PM Revision 454cfb43: Fix disk widget upgrade script assuming widgets always have an index
-
01:06 PM pfSense Plus Bug #11466: PHP exits with signal 11 on SG-3100 when calling PCRE functions
- Updating subject for release notes.
-
10:44 AM pfSense Plus Bug #11466 (Closed): PHP exits with signal 11 on SG-3100 when calling PCRE functions
- Cannot crash PHP with the test code on a current 21.09 snapshot.
Since disabling JIT is the best solution in this ... -
01:05 PM Feature #2668: Support aliases in OpenVPN local/remote/tunnel network fields
- Updating subject for release notes.
-
01:03 PM Bug #12039: Gateway alarm always triggers IPsec restart
- Updating subject for release notes.
-
11:05 AM Bug #12039: Gateway alarm always triggers IPsec restart
- Applied in changeset commit:8558539a8547befd3a9f218286766e76a1c0f03f.
-
11:04 AM Bug #12039 (Feedback): Gateway alarm always triggers IPsec restart
- PRs merged
-
01:03 PM Bug #12282: Default IPv4 gateway may be set to IPv6 gateway value in certain cases
- Updating subject for release notes.
-
01:02 PM Bug #12331: Yandex Dynamic DNS client does not set the ``PddToken`` value
- Updating subject for release notes.
-
01:01 PM Regression #12337: IPsec widget generates errors if no tunnels are defined
- Updating subject for release notes.
-
12:40 PM pfSense Packages Todo #12354: Update haproxy-devel to mitigate CVE-2021-40346
- Sorry for typo
-
11:51 AM pfSense Packages Bug #11135: HAproxy OCSP reponse crontab bug
- Thank you!
-
11:47 AM pfSense Packages Bug #11135: HAproxy OCSP reponse crontab bug
- PR has been merged. Thanks!
-
11:43 AM pfSense Packages Todo #12317 (Feedback): Suricata UI improvements
- PR has been merged. Thanks!
-
11:42 AM pfSense Packages Bug #12322 (Feedback): Suricata creates invalid HOME_NET entries
- PR has been merged. Thanks!
-
11:40 AM pfSense Packages Bug #12330 (Feedback): pfBlockerNG devel creating invalid NAT rules on boot
- PR has been merged. Thanks!
-
11:38 AM pfSense Packages Todo #12351 (Feedback): Remove non-functional feeds
- PR has been merged. Thanks!
-
11:33 AM pfSense Packages Feature #11295 (Feedback): DNSBL IDN support
- PR has been merged. Thanks!
-
11:31 AM pfSense Packages Bug #11964 (Feedback): pfBlocker XMLRPC sync CARP interface advskew
- PR has been merged. Thanks!
-
11:06 AM Bug #12352 (Pull Request Review): Update Dynamic DNS code for one.com to use their new login process
-
10:55 AM Bug #12352: Update Dynamic DNS code for one.com to use their new login process
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/386
-
10:57 AM Bug #11734 (Resolved): NAT rule overlap detection is inconsistent
- Marking resolved since the original part was already tested. I moved the special networks issue over to #12361 as it ...
-
10:56 AM Bug #12361 (Resolved): NAT rule overlap detection does not check special networks
- Split from #11734, NAT rule overlap detection does not consider special networks when testing.
There is already a ... -
10:50 AM Bug #7801 (Feedback): UDP fragments received over IPsec tunnel are not properly reassembled and forwarded
- PR merged.
-
10:10 AM pfSense Docs Todo #12360 (Closed): Remove ALTQ Note on XG-7100 SFP+ Modules
- The XG-7100 now supports ALTQ on the SFP+ ports. There is an old note in the documentation stating that they do not,...
-
10:07 AM Bug #12144: Bug in ``df -t`` filtering if two filesystems use the same mountpoint
- The new Disks widget in #12349 uses @df@ in a different way and doesn't hit this problem, thus it is no longer a curr...
-
09:25 AM Feature #12349: Disks dashboard widget to replace Disk Usage section of System Information widget
- Upgrade looks good with that change applied, I rolled back the config and triggered the upgrade code again and this t...
-
09:14 AM Feature #12349 (Feedback): Disks dashboard widget to replace Disk Usage section of System Information widget
-
09:13 AM Feature #12349: Disks dashboard widget to replace Disk Usage section of System Information widget
- Fixed: https://gitlab.netgate.com/pfSense/pfSense/-/commit/454cfb433a7496d1e33a9ea856612974f5718243
-
08:36 AM Feature #12349: Disks dashboard widget to replace Disk Usage section of System Information widget
- ah good catch. Bad assumption on my part. Easy to fix.
-
07:44 AM Feature #12349 (New): Disks dashboard widget to replace Disk Usage section of System Information widget
- PR was merged yesterday, it's in snapshots today.
Looks like there is a bug in the upgrade code. The dashboard widge...
09/09/2021
-
11:08 PM Revision 2de8b1f5: * Removes disk usage from system information widget
- * Adds Pfsense\Services\Filesystem\ library
* Adds new disk widget -
08:26 PM Feature #12226 (Resolved): Copy button for group entries in the User Manager
- added and fixed
2.6.0.a.20210909.0100 - 03:08 PM Revision 9dac41af: captiveportal: fix ipfw rules
- When we authorise a client we add it to the *_auth_(up|down) tables.
This means traffic will pass and not be forwarde... -
03:01 PM Revision 7e0da288: Initial commit of useful dependencies provided by Composer
-
03:00 PM Todo #12314 (Resolved): Convert help shortcut links to server-side redirects
- New behavior seems solid. Requests are being routed properly, first to the expected target URL and then redirected to...
-
02:58 PM Todo #11507 (Resolved): Update font formats to WOFF2
- Browser debug panel show WOFF2 format being used, no sign of font issues that I can see.
-
02:54 PM Regression #12340 (Resolved): Factory Reset Menu Broken in webConfigurator
- Works fine now.
-
02:52 PM Feature #9297 (Resolved): Graph for hardware temperature readings
- Seems to be working nicely
-
02:50 PM Regression #12287 (Resolved): State table entry rule ID does not contain the expected value
- This has been solid since the fix made it into snapshots.
-
02:48 PM Regression #12111 (Resolved): Crash report message displayed on dashboard. flock() expects parameter 1 to be resource, null given in /etc/inc/util.inc on line 166
-
02:41 PM Bug #11701 (Resolved): Missing global ``$g`` declaration in ``config.lib.inc`` function ``pfSense_clear_globals()``
- Variable is present now.
-
02:36 PM Todo #12012 (Resolved): Improve log settings help text for file size, compression, and retention count
- Text looks good now.
-
02:34 PM Bug #9058 (Resolved): Kernel panic during L2TP retransmit
- Marking resolved based on current issue feedback. For what it's worth, I have not seen a crash on the system where I ...
-
02:32 PM Bug #12173 (Resolved): IPv6 RA DNSSL lifetime is too short, not compliant with RFC 8106
- This all looks correct now on current snapshots.
-
02:32 PM Bug #12280 (Resolved): Default IPv6 router advertisement intervals and lifetime are too low
- This all looks correct now on current snapshots.
-
02:28 PM Bug #12026 (Resolved): Applying IPsec settings for many tunnels is slow or times out
- This is all working correctly now on current IPsec code, in my local tests and based on reports from our internal Net...
-
02:28 PM Bug #12155 (Resolved): Tunnels with conflicting REQID values can lead to multiple identical Child SA entries
- This is all working correctly now on current IPsec code.
-
02:28 PM Regression #11910 (Resolved): IPsec status tunnel descriptions are incorrect
- This is all working correctly now on current IPsec code.
-
02:27 PM Todo #11933 (Resolved): PC/SC Smart Card Daemon ``pcscd`` running on all devices at all times, should be optional
- Service is no longer running by default, service is not in the list when disabled.
-
02:26 PM Todo #12044 (Resolved): Improve IPsec identifier settings
- Descriptions are better, options I've tried are all working. If new problems come up they can be added as new and sep...
-
02:23 PM Todo #12289 (Resolved): Update "IPsec Filter Mode" option values and help text to reflect that VTI mode also helps transport mode (e.g. GRE)
- Updated text is present now.
-
02:22 PM Regression #12279 (Resolved): Uninitialized config array and escaped html in ipsec widget
- Not a problem anymore
-
02:22 PM Bug #12189 (Resolved): IPsec status shows connect buttons while tunnel is connecting
- Working as expected now.
-
02:22 PM Bug #12298 (Resolved): IPsec manual initiation and termination should use a timeout value or forced actions
- Working as expected now.
-
02:17 PM Bug #12252 (Resolved): IPv6 DNS servers from dynamic sources are not listed on ``status_interfaces.php``
- Dynamic IPv6 DNS server is now shown on the page as expected.
-
02:01 PM Todo #12171 (Resolved): Upgrade to ``pkg`` 1.17.x
- No problems of note, @pkg-1.17.1@ is present on snapshots.
-
01:56 PM pfSense Packages Feature #12358 (New): IP List Copy/Import/Export
- I've added both of my items in one issue, as they are all part of the same functionality.
I'd like to see if it's ... -
01:37 PM Regression #12333 (Resolved): DNS resolver using incorrect variable name when making ACL for OpenVPN IPv6 Tunnel Network
- Working correctly on current snapshots. I hit this on ~5 VMs when it was broken but all are OK on today's snapshot.
-
01:36 PM Bug #11969 (Resolved): PHP error if no DHCPv6 Relay interfaces are selected
- Unable to reproduce the errors on a current snapshot. Looks good to me.
-
01:33 PM Regression #12337 (Resolved): IPsec widget generates errors if no tunnels are defined
- No errors from the widget that I can see now:
* No errors when there are no tunnels (P1 or P2)
* No errors on any... -
01:30 PM Todo #12299 (Resolved): Update default ``config.xml``
- Default configuration is current now. All the above points are addressed.
-
01:22 PM Regression #12306 (Resolved): Certificate info block has CA info, not certificate info
- Expected output is present now.
-
01:21 PM Todo #12060 (Resolved): Remove deprecated ``libzmq`` code and references
- All traces are gone as far as I can see.
-
01:20 PM Todo #10298 (Resolved): Use SHA-512 for user password hashes
- Working as expected.
* New users get SHA-512 password only.
* Existing users get SHA-512 when their password is c... -
12:47 PM Bug #12138 (Resolved): Clicking "logout" on portal page does not function when logout popup is disabled
- This works fine on the current code as far as I can see. With or without the logout popup, navigating back to the ful...
-
12:46 PM Bug #12357 (New): Captive Portal popup Logout button loads full login page in popup when clicked
- When clicking the "Logout" button on the Captive Portal logout popup window, the small popup window attempts to show ...
-
12:16 PM Bug #12356 (Pull Request Review): Validation when deleting a VIP does not check if the VIP is used by IPsec phase 1 entries
-
12:12 PM Bug #12356: Validation when deleting a VIP does not check if the VIP is used by IPsec phase 1 entries
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/383 -
10:50 AM Bug #12356 (Resolved): Validation when deleting a VIP does not check if the VIP is used by IPsec phase 1 entries
- It is possible to delete the Virtual IP that is used by IPsec PH1
see the result in the attached screenshot -
10:14 AM Regression #12345 (Feedback): Captive Portal users cannot get past portal even after successfully logging in
- MR merged, commit:9dac41af43a5b977a604098688776987c4f76722 -- Tested locally and it works here, but could use wider t...
-
09:19 AM Regression #12345: Captive Portal users cannot get past portal even after successfully logging in
- Merge request:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/382
As far as I can tell this ruleset ... -
10:11 AM Bug #12355 (Closed): Captive Portal database and ``ipfw`` rules are out of sync after unclean shutdown
- If a Captive Portal zone does not have the "Preserve connected users across reboot" option set and the firewall encou...
-
09:11 AM pfSense Packages Todo #12354 (Feedback): Update haproxy-devel to mitigate CVE-2021-40346
- As per https://nvd.nist.gov/vuln/detail/CVE-2021-40346 need update to fix BUG/MAJOR: htx: fix missing header name len...
-
08:59 AM Feature #12349: Disks dashboard widget to replace Disk Usage section of System Information widget
- Updating subject for release notes
-
07:50 AM Feature #12321 (Pull Request Review): Pop-up window to view firewall rules generated from RADIUS ACL entries on the OpenVPN status page
-
04:51 AM Feature #12321: Pop-up window to view firewall rules generated from RADIUS ACL entries on the OpenVPN status page
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/381
-
07:47 AM Bug #12350 (Confirmed): Incorrect label for IPsec DH group 32
-
12:37 AM Bug #12350 (Resolved): Incorrect label for IPsec DH group 32
- In the settings UI for IKE Phase 1 and Phase 2 configurations, DH Group 32 is referred to as "Elliptic Curve 25519, 4...
-
02:28 AM pfSense Packages Bug #12204 (Resolved): Certificate Manager page doesn't show Syslog-NG used certificates
- You are right. I've just confirmed. The Certificate Manager page showed Syslog-NG used certificates after selecting T...
-
01:43 AM Bug #12352 (Resolved): Update Dynamic DNS code for one.com to use their new login process
- from https://forum.netgate.com/topic/124904/dynamic-dns-one-com/19:...
-
01:02 AM pfSense Packages Todo #12351: Remove non-functional feeds
- https://github.com/pfsense/FreeBSD-ports/pull/1107
CoinBlockerList is OK - see "The final URL for this feed will... -
12:43 AM pfSense Packages Todo #12351 (Feedback): Remove non-functional feeds
- https://raw.githubusercontent.com/joeylane/hosts/master/hosts - Not found
https://isc.sans.edu/feeds/suspiciousdomai...
Also available in: Atom