Project

General

Profile

Activity

From 05/22/2022 to 06/20/2022

06/20/2022

06:01 PM Regression #13290 (Feedback): Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters
There's not enough info here to troubleshoot this. Discussion of the issue may be continued on the forums: https://fo... Marcos M
02:25 PM Regression #13290 (Resolved): Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters
After upgrading from 2.6.0 to 2.7.0, my Captives Portal users are dropped randomly, having to re-authenticate... Ther... Rafael Ferreira
04:20 PM Bug #13210 (Resolved): PPPoE server panics with multiple client connections
Customer which was previously frequently hitting this issue reports it's been resolved after updating to the RC. Marcos M
04:04 PM Bug #10352: RADIUS authentication fails with MSCHAPv1 or MSCHAPv2 when passwords contain international characters
The issue is still present on 22.01-RELEASE
Any foreseen planning to fix this issue ?
Is someone working on it ? ma...
Patrick Vander Linden
01:03 PM Feature #13286: webConfigurator does not redirect to requested page after login
I understand.
To be honest, one of my main reasons for wanting this merged was because my dashboard takes so darn l...
→ luckman212
12:52 PM Feature #13286: webConfigurator does not redirect to requested page after login
Some pages require parameters to load the right view, so stripping the parameters isn't helpful.
It is not going t...
Jim Pingle
10:18 AM Feature #13286: webConfigurator does not redirect to requested page after login
But, again- nothing prevents a logged in user from bookmarking a page or recalling one from history that actions some... → luckman212
10:15 AM Feature #13286: webConfigurator does not redirect to requested page after login
Doesn't have to be an attack, they could also do it unintentionally by bookmarking or hitting a page from their histo... Jim Pingle
10:07 AM Feature #13286: webConfigurator does not redirect to requested page after login
Not sure I follow how this makes it any less secure than it already is. If a user is logged in already, they can stil... → luckman212
08:49 AM Feature #13286 (Rejected): webConfigurator does not redirect to requested page after login
This is done on purpose for security reasons. Until the entire GUI is purged of any page that takes action on GET, th... Jim Pingle
08:34 AM Feature #13286: webConfigurator does not redirect to requested page after login
PR: https://github.com/pfsense/pfsense/pull/4599 → luckman212
08:33 AM Feature #13286 (Rejected): webConfigurator does not redirect to requested page after login
Something that has bugged me for a while now is that if you are logged out of pfSense, and request a "deep" page e.g.... → luckman212
10:46 AM Bug #13289 (Resolved): Attempting to restore a 0 byte ``config.xml`` prints an error that the file cannot be read
When attempting to restore an empty config.xml file (0 bytes) the GUI prints an error saying the file cannot be read ... Jim Pingle
10:36 AM Bug #13288 (New): Encode FreeRADIUS Custom Options
Currently, fields in the FreeRADIUS package such as @varusersreplyitemsadditionaloptions@ are not encoded in config.x... Marcos M
10:33 AM Feature #13287 (New): Encode OpenVPN Custom Options
The @custom_options@ field for OpenVPN configurations is currently not encoded. This should be encoded in base64. Marcos M
07:46 AM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
Both @auth-gen-token@ and @reneg-sec@ are useful in different ways, we should expose and (optionally) use both. Thoug... Jim Pingle
07:21 AM Bug #13285: Uncaught ArgumentCountError to function openvpn_kill_client()
Okay, thank you Jim for test and quick feedback. DRago_Angel [InV@DER]
07:20 AM Bug #13285 (Duplicate): Uncaught ArgumentCountError to function openvpn_kill_client()
There are no errors when terminating clients on the status page or widget on 22.05/2.7.0 snapshots. Jim Pingle
07:11 AM Bug #13285: Uncaught ArgumentCountError to function openvpn_kill_client()
Sorry, found https://redmine.pfsense.org/issues/12817 but it not mention status page, not sure 12817 also resolve Ope... DRago_Angel [InV@DER]
07:09 AM Bug #13285 (Duplicate): Uncaught ArgumentCountError to function openvpn_kill_client()
Killing session for user using OpenVPN Dashboard Widget or using OpenVPN Status page do not works.
On Widget next er...
DRago_Angel [InV@DER]

06/19/2022

11:11 PM Bug #5413: Reduce disruptions when changing DNS records from DHCP leases in Unbound
Hey Netgate - I get the feeling this affects far more customers than you think.
Can this be assigned to someone to a...
O E
09:34 PM Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes
Just updated "PR #4595":https://github.com/pfsense/pfsense/pull/4595 with the new mitigation changes. Testers & feedb... → luckman212
12:20 PM Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes
It appears we are out of luck on having @devd@ fire events for IP address changes. There is a commit: https://reviews... → luckman212
06:42 PM pfSense Plus Bug #13283 (Not a Bug): PBR forcing traffic out one WAN and back into another WAN with NAT Reflection Fails
Tested this.
With that PBR in place, even traffic that is being NAT'ed from the NAT Reflection rule will be caught...
Marcos M
05:53 PM Bug #13243 (Pull Request Review): OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
Marcos M
02:18 PM Bug #13243: OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
This fixes the original issue:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/821
Reiner Keller wr...
Marcos M
05:52 PM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
It's better to implement @--auth-gen-token [lifetime]@
> --auth-gen-token [lifetime]
> After successful user/passwo...
Marcos M
05:38 PM Feature #12982: Add support for RFC7499 in RADIUS library.
So are you saying that pfsense/freeRadius will not be able to go more then 68 rules? any software you know would be ... Frank Lee
03:58 PM Feature #12982: Add support for RFC7499 in RADIUS library.
I was able to replicate this with a simpler setup by adding a custom option to the @Additional RADIUS Attributes (REP... Marcos M
12:10 PM pfSense Packages Feature #13284 (New): Option to define "Issuer" in OPT configuration.
All QR codes are presently identifying as "FreeRADIUS(username).
Please add an optional variable in user->One-Time...
Jakob Nordgarden
11:11 AM Bug #13280: Entries for ``net.link.ifqmaxlen`` duplicated in ``/boot/loader.conf``
I'm seeing this as well on a VM with @22.05.r.20220609.1919@.... Marcos M

06/18/2022

05:48 PM pfSense Plus Bug #13283 (Not a Bug): PBR forcing traffic out one WAN and back into another WAN with NAT Reflection Fails
Assuming the following configuration:
2 WAN interfaces WAN1 and WAN2
One LAN interface with Host A and Host B.
H...
Kris Phillips
02:34 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
It seems this issue has gotten worse somewhere along the line similar to how others are describing it. Tables now lo... Kris Phillips
02:25 PM Bug #13282 (Resolved): Alias content is sometimes incomplete if the firewall cannot resolve an FQDN in the alias
If an invalid FQDN is present in an alias before a valid one, the entire table will be empty.
For an example, if...
Kris Phillips

06/17/2022

07:24 PM Bug #13281 (Duplicate): Crash Reporter
Duplicate, and already fixed: #12817 Jim Pingle
06:49 PM Bug #13281 (Duplicate): Crash Reporter
Crash report begins. Anonymous machine information:
amd64
12.3-STABLE
FreeBSD 12.3-STABLE plus-RELENG_22_01-n20...
Ilan Birman
04:10 PM Revision 3f4ee315: Template the versions as well
Brad Davis
03:31 PM Bug #13280 (Resolved): Entries for ``net.link.ifqmaxlen`` duplicated in ``/boot/loader.conf``

Using 22.05-RC 22.05.r.20220617.0613 Duplicate entries appear in /boot/loader.conf
Here are the contents of my loa...
Keith Townsend
08:36 AM Bug #13243: OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
Additional to this "informal" bug the ruleset given by Radius parameter isn't stored and when the renegiotion is done... Reiner Keller
07:34 AM Bug #13278 (Needs Patch): OpenVPN dynamic gateway created incorrectly when not pulling routes or server pushes no routes
We're aware of this, but it's an OpenVPN bug, not a bug in our code. As you see, the variables are unpopulated even w... Jim Pingle
01:10 AM Bug #13278: OpenVPN dynamic gateway created incorrectly when not pulling routes or server pushes no routes
This appears to be happening because OpenVPN doesn't populate these environment variables when either option is selec... Adrien Carlyle
07:09 AM Bug #13279 (New): DHCP config override affects Gateway installation.
If you check Configuration Override on the interface in the DHCP Client Configuration section, then open Status => In... Lev Prokofev
07:02 AM Regression #13274 (Resolved): OpenVPN override IPv4 tunnel network field changing value improperly
Working as expected on the latest build. The exact tunnel network address and mask remain, and the resulting @ifconfi... Jim Pingle

06/16/2022

11:54 PM Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes
@dem I believe I'm facing this exact issue, take a look at https://forum.netgate.com/topic/172849/rtsold-not-running-... → luckman212
10:31 PM Bug #13278 (Needs Patch): OpenVPN dynamic gateway created incorrectly when not pulling routes or server pushes no routes
IF: I configure OpenVPN client and set the "Don't pull routes" check box
OR
IF: I include the advanced option: pull...
Adrien Carlyle
09:30 PM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
+1 Also having this problem : 2.6.0-RELEASE (amd64) Emmanuel Rosado
07:50 PM Bug #13277 (Duplicate): IGMP Proxy webConfigurator Page Always Produces Error
Whether your IGMP Proxy settings are correct or not, there is always an error stating "There was a problem applying t... Kris Phillips
07:48 PM Bug #13276 (New): IGMP Proxy Error Message for Logging Links to System Log Instead of Routing Log
If you try to apply a setting that won't apply in IGMP Proxy, it will state "There was a problem applying the changes... Kris Phillips

06/15/2022

03:16 PM Revision 230b2303: Fix OpenVPN override TN handling. Fixes #13274
Jim Pingle
10:42 AM pfSense Docs New Content #13211: OpenVPN DCO Documentation
Updates: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/989cfa8946010d913fddeebc8d8fe740ba409390 Jim Pingle
10:25 AM Regression #13274 (Feedback): OpenVPN override IPv4 tunnel network field changing value improperly
Applied in changeset commit:230b23033a898633681ef0dde4df8f63a2b7258c. Jim Pingle
10:13 AM Regression #13274 (Resolved): OpenVPN override IPv4 tunnel network field changing value improperly
For an override on a subnet topology VPN, the mask on the tunnel network in the override has to reflect the subnet ma... Jim Pingle
03:44 AM Bug #11629: PPPoE WAN IP address different than expected when set static by ISP
We've installed 22.05 on our Netgate 2100 appliance and it's still assigning the wrong IP address to the WAN interfac... Dan Rice

06/14/2022

01:14 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
That one change looks to have solved the issue for me.
Testing in:...
Steve Wheeler
01:04 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
Well... seeing that would have saved me a bunch of debugging... Denny Page
12:41 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
For reference, the redmine for that issue is here:
https://redmine.pfsense.org/issues/13156
Marcos M
12:19 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
The issue apparently stems from the output of "pfctl -vvsr" changing in 22.05. Due to the change in output, pfBlockNG... Denny Page
11:07 AM Bug #13273 (New): dhclient can use conflicting recorded leases
dhclient will attempt to use a previously successful recorded lease if it cannot contact a dhcp server.
However it w...
Steve Wheeler
08:00 AM pfSense Packages Bug #13180: High CPU Utilization with pfb_filter since pfBlockerNG update to devel 3.1.0_4
Looks like a duplicate or related to #13154 Michael Novotny
06:53 AM Regression #13265 (Resolved): Authentication using Voucher cause SQLite3 syntax error
No errors on the latest snapshot. Voucher is accepted, no PHP error, voucher shows in active users and active voucher... Jim Pingle

06/13/2022

08:16 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
Even with changing the rule to use the pfBlockerNG aliases directly, the issue persists - that is I'm not seeing any ... Marcos M
06:16 PM pfSense Packages Bug #13154 (Confirmed): pfBlocker causing excessive CPU load
Still seeing this in 2.7/22.05 so it seems unlikely to be a symptom of #12827 which is mostly fixed there.
The CPU...
Steve Wheeler
02:04 PM Revision 8ba70cfc: Set CP pipeno consistently when null. Fixes #13265
Jim Pingle
11:29 AM Feature #12982: Add support for RFC7499 in RADIUS library.
Ok, so do you know roughly when "someone" can look at this issue further? Frank Lee
10:37 AM Feature #12982: Add support for RFC7499 in RADIUS library.
I can't find where @[ciscoavpair]@ is being set in the code - the only reference I could find was in @pear-Auth_RADIU... Marcos M
11:11 AM Bug #13262 (Resolved): File browser on ``diag_edit.php`` does not encode filenames before display
Tested on... Christopher Cope
10:27 AM Bug #13272 (Pull Request Review): Voucher CSV output has leading space before voucher code
MR: https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/818
Diff attached for wider testing.
Jim Pingle
10:14 AM Bug #13272 (Resolved): Voucher CSV output has leading space before voucher code
When downloading a CSV file for a voucher roll, each voucher has a leading space, so when copying and pasting it gets... Jim Pingle
09:33 AM Regression #13265: Authentication using Voucher cause SQLite3 syntax error
Merged into Plus and CE master branches and picked back into 22.05. Jim Pingle
09:10 AM Regression #13265 (Feedback): Authentication using Voucher cause SQLite3 syntax error
Applied in changeset commit:8ba70cfcf6c86db2c52577bf543a6b72fc2da9e7. Jim Pingle
08:11 AM Regression #13265 (In Progress): Authentication using Voucher cause SQLite3 syntax error
It should be noted that the authentication succeeds and the user can get out, is listed on the active vouchers tab, b... Jim Pingle
08:23 AM pfSense Packages Bug #12992 (Resolved): error: nbproc is not supported any more since HAProxy 2.5
Jim Pingle
08:17 AM pfSense Docs New Content #13270: OpenVPN client gateway is incorrect when the server does not push routes
This has always been the case with OpenVPN. It doesn't populate the environment variables because it doesn't think it... Jim Pingle
05:06 AM pfSense Packages Bug #13271 (Bogus): I got 'The WireGuard service is not running.' after I upgraded my pfSense VM from 22.05.r.20220604.1403 -> 22.05.r.20220609.1919
I've got this issue on one of my pfSense VM after upgrade from 22.05.r.20220604.1403 -> 22.05.r.20220609.1919 ('upgra... Azamat Khakimyanov

06/12/2022

10:32 PM Todo #13268: Dynamically adjust the interface name maximum width in the login banner
I wanted to auto size the columns based on the terminal width, but the shell doesn't seem to export the @$COLUMNS@ va... → luckman212
05:09 PM Todo #13268 (Resolved): Dynamically adjust the interface name maximum width in the login banner
small change to add some width and better align things if interface names are longer than just "WAN", "WAN2" etc.
...
→ luckman212
07:14 PM pfSense Docs New Content #13270 (Resolved): OpenVPN client gateway is incorrect when the server does not push routes
If @IPv4 Local network(s)@ is empty on the server (and no custom options exist to push routes), the client @ovpn-link... Marcos M
02:48 PM Bug #13267 (New): dpinger continues to run on OpenVPN gateway after OpenVPN service is stopped.
Tested on @22.05.r.20220609.1919@.
# Configure OpenVPN client on pfSense
# Assign an interface to the OpenVPN cli...
Marcos M
01:44 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
* removed @case 111)@
* consistency of single/double quotes
* removed a couple of stray @;@ s
→ luckman212
01:21 PM Bug #12920: Gateway behavior differs when the gateway does not exist in the configuration
Updating OP with new symptoms. Marcos M
01:00 PM Revision f185e661: a few updates for the console menu
add full pathnames to all binaries (before some were and some weren't)
less forking for process checking, instead of ...
→ luckman212
11:22 AM Feature #12973: Playback script to perform a configuration upgrade on an arbitrary ``config.xml`` file
Just noting for anyone looking, the script is named @upgradeconfig@ not @updateconfig@ as in Chris' OP. → luckman212
11:14 AM pfSense Plus Bug #13074: AES-GCM with SafeXcel on Netgate 2100 causes MBUF overload
I believe I have hit this as well, 2100 to 7100 GCM tunnel. Is there an upstream FreeBSD bugreport? I believe the fac... → luckman212
11:11 AM Bug #13252: reduce frequency of php-fpm socket connection attempts from check_reload_status
I may have also experienced this on an SG-2100 yesterday. Upgraded from 21.05.1 to 22.05-RC.
After the upgrade, CP...
→ luckman212
08:45 AM pfSense Packages Bug #12992: error: nbproc is not supported any more since HAProxy 2.5
This should be closed since it's been merged → luckman212
12:04 AM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
Pushed more updates to my "PR #4595":https://github.com/pfsense/pfsense/pull/4595 (see over there for details).
I...
→ luckman212

06/11/2022

07:01 PM pfSense Plus Bug #13206: SG-3100 LED GPIO hangs
Daniel Subert wrote in #note-2:
> Hi Jim,
>
> Thanks for the update.
>
> As this issue is already being tracked int...
Kris Phillips
06:45 PM Revision 08e9bcfd: add waning infobox if duplicate IP is entered in DHCP staticmaps
→ luckman212
05:43 PM Regression #13265: Authentication using Voucher cause SQLite3 syntax error
Here is the crash report from my firewall:
Crash report begins. Anonymous machine information:
amd64
12.3-STA...
Kris Phillips
05:41 PM Regression #13265: Authentication using Voucher cause SQLite3 syntax error
I can confirm this issue is present in the RC3 build of 22.05. Kris Phillips
05:08 AM Regression #13265 (Resolved): Authentication using Voucher cause SQLite3 syntax error
Errors:
Crash report begins. Anonymous machine information:
amd64
12.3-STABLE
FreeBSD 12.3-STABLE plus-RELEN...
Lev Prokofev
05:43 PM Revision b707f4d8: fix log spew when deleting static DHCP maps not in arp table, redmine #13263
→ luckman212
04:51 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
Looks good to me. Marcos M
01:50 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
I pushed a revised version, looks like this now
!clipboard-202206111450-srubn.png!
→ luckman212
02:17 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
BBcan177 . wrote in #note-3:
> There seems to have been a change in the pfctl -vvsr output.
>
> The patch below seem...
B. B.
09:11 AM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
Is there a particular reason for that? I'm using a custom alias to keep rule management easier, and to avoid filter l... Marcos M
09:02 AM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
Marcos Mendoza wrote in #note-7:
> > @256 block drop in log quick on ixv5 inet from any to <h_blocklist:19320> label...
BBcan177 .

06/10/2022

10:47 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
> @256 block drop in log quick on ixv5 inet from any to <h_blocklist:19320> label "USER_RULE: pfb_blocklist" label "i... Marcos M
07:49 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
Marcos Mendoza wrote in #note-4:
> Tested change on @22.05@ RC with pfBlockerNG-devel @3.1.0_4@; floating block rule...
BBcan177 .
04:29 PM Feature #13264 (New): IPSec Phase2 select multiple PFS key groups
A user can currently select multiple IPSec encryption and hash algorithms, so it would make sense to add the ability ... Lars Pedersen
12:56 PM Revision 1b5919c7: Encode filename browser.php. Fixes #13262
Jim Pingle
11:36 AM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
I've been running with the PR above for 2 days now, it's survived multiple reboots, and unplug/replug of the secondar... → luckman212
11:18 AM Todo #13263: Reduce log spam when deleting a static DHCP entry
I made and tested this small patch: https://github.com/pfsense/pfsense/pull/4597 → luckman212
10:55 AM Todo #13263 (Resolved): Reduce log spam when deleting a static DHCP entry
This is not a huge priority, but when deleting static DHCP mappings for devices that are offline / not on network and... → luckman212
10:18 AM Bug #13258 (Pull Request Review): Hidden menu option ``100`` incorrectly handles HTTPS detection
Jim Pingle
08:05 AM Bug #13262 (Feedback): File browser on ``diag_edit.php`` does not encode filenames before display
Applied in changeset commit:1b5919c769ba736b44819f71ee1ddce06e2a50c5. Jim Pingle
07:56 AM Bug #13262 (Resolved): File browser on ``diag_edit.php`` does not encode filenames before display
The file browser on @diag_edit.php@ does not encode filenames before display.
A user who can create files with arb...
Jim Pingle
03:39 AM pfSense Packages Bug #13261 (Resolved): Input validation rejects empty ``sudo`` command list, but GUI text says it can be empty
The help text says, " By default the command is "ALL" meaning the user can run any commands. Leaving the commands fi... Danilo Zrenjanin

06/09/2022

11:20 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
The patch works for me on LAN and WAN rules on 22.05 RC using pfBlockerNG-devel 3.1.0_4. I don't have floating rules ... Glenn Hall
11:08 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
Tested change on @22.05@ RC with pfBlockerNG-devel @3.1.0_4@; floating block rule on tagged traffic with description ... Marcos M
09:58 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
There seems to have been a change in the pfctl -vvsr output.
The patch below seems to fix the issue, but would be ...
BBcan177 .
02:51 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
Ok I updated the PR to bring back the hidden option 100 / links browser. I think this is good. Unfortunately when I t... → luckman212
01:31 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
I haven't used @links@ against in the GUI in quite some time so I'm not sure if it still works. If it does we may as ... Jim Pingle
01:28 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
PR: https://github.com/pfsense/pfsense/pull/4596 → luckman212
11:44 AM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
I can't think of any benefit from fixing it; better to remove it. Marcos M
02:07 PM Feature #10446: VIP address is not shown in firewall rules
Marcos Mendoza wrote in #note-5:
> Better to stick with using aliases. VIPs are more for service bindings.
This wil...
Silmor Senedlen
11:38 AM Feature #10446: VIP address is not shown in firewall rules
Silmor Senedlen wrote in #note-4:
> Silmor Senedlen wrote in #note-2:
> > I think it would be nice to be able to ...
Marcos M
02:04 PM Feature #13260 (New): Add support for OpenVPN static-challenge
When using Multi Factor authentication most OpenVPN clients offer a static-challenge option to make the client ask fo... Diego Cortassa
01:32 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
I wanted to make the warning display in a "Yellow Box" too but I looked through the code and couldn't see an easy way... → luckman212
12:41 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
I don't think we should change the default behavior/add extra steps to reach the current behavior.
Something that ...
Jim Pingle
12:36 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
Thank you for the contributions!
In general, it's best to avoid first/second person perspective. A yellowish warni...
Marcos M
07:07 AM Regression #11570 (Pull Request Review): Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
Jim Pingle
01:42 AM pfSense Packages Bug #12765 (Resolved): AutoConfigBackup should ignore Lightsquid/lightparser cron changes
I tested with Lightsquid version 3.0.6_9.
It works fine.
I am marking this ticket resolved.
Danilo Zrenjanin

06/08/2022

11:17 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
I submitted a PR: https://github.com/pfsense/pfsense/pull/4595 that may help some of the cases being hit here. → luckman212
05:02 PM pfSense Packages Bug #13259 (Not a Bug): Reply-to rules are not created with wireguard 0.1.6_1
Jim Pingle
04:57 PM pfSense Packages Bug #13259: Reply-to rules are not created with wireguard 0.1.6_1
Sorry, stupid mistake on my side, it is required to set an upstream gateway on the interface config in order for the ... JB Fuzier
04:53 PM pfSense Packages Bug #13259 (Not a Bug): Reply-to rules are not created with wireguard 0.1.6_1
Hello,
I have noticed that reply-to rules are not created for rules in a wireguard interface even if it is assigne...
JB Fuzier
03:33 PM Feature #10446: VIP address is not shown in firewall rules
Silmor Senedlen wrote in #note-2:
> I think it would be nice to be able to select VIP address from list(which autom...
Silmor Senedlen
01:35 PM pfSense Packages Bug #12808 (Resolved): Wireguard Gateways disabled when Wireguard Service is Manually Restarted
Christian McDonald
10:02 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
Cherry picked this commit to RELENG_2_6_0 ports tree. Look for a package update.
Edit: v0.1.6_2 is available in CE 2...
Christian McDonald
09:31 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
→ luckman212 wrote in #note-13:
> @Valmor if you add the System Patches package and then add a patch using this url:...
Val Mor
07:54 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
@Valmor if you add the System Patches package and then add a patch using this url:
https://github.com/theonemcdona...
→ luckman212
07:46 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
I have similar issue on pfSense 2.6.0-RELEASE.
Configured WireGuard tunnel and set a static route.
After reboot of ...
Val Mor
12:40 PM pfSense Packages Bug #13050 (Resolved): ACME update EasyDNS inline api sign-up link
It looks fine on Acme package version 0.7.1_1.
I am marking this ticket resolved.
Danilo Zrenjanin
12:04 PM Bug #13258 (Resolved): Hidden menu option ``100`` incorrectly handles HTTPS detection
I was poking around in @/etc/rc.initial@ to try to fix something else and I noticed a hidden menu item 100
This op...
→ luckman212
10:38 AM Bug #13257: Exporting a PKCS#12 file from the certificate manager does not use the intended encryption algorithm
See also: #13255 Jim Pingle
10:35 AM Bug #13257 (Resolved): Exporting a PKCS#12 file from the certificate manager does not use the intended encryption algorithm
In source:src/usr/local/www/system_certmanager.php#L198 or thereabouts it sets a parameter @encrypt_key_cipher@ inten... Jim Pingle
09:54 AM Feature #13256 (Resolved): Better handling of duplicate IP addresses in static DHCP assignments
summary:
In 2018 code that prevented duplicate IPs from being used as static DHCP mappings was removed. There are ...
→ luckman212
09:15 AM Bug #13088: Rapidly clicking certain options on OpenVPN Client Overrides can cause hide/show field behavior to invert
I replicated the issue with inverted results when repeating clicks too quickly on 22.05.r.20220604.1403.
After app...
Danilo Zrenjanin
08:52 AM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
I reproduced the issue on 22.01 and 22.05.r.20220604.1403 with the same logs. Danilo Zrenjanin
08:36 AM pfSense Packages Todo #13255 (Resolved): Set PKCS#12 algorithm when exporting OpenVPN ZIP or Windows bundles
Currently when crafting a PKCS#12 archive the OpenVPN Client Export package does not set a specific encryption algori... Jim Pingle
07:48 AM Bug #13254 (Resolved): DNS resolver does not update its configuration or reload during link down events
How to reproduce:
1) Configure the interface with Static IPv4
2) Select this interface in the "Network Interfaces...
Danilo Zrenjanin

06/07/2022

08:55 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
Tested on 22.05 RC.
I was not able to replicate this initially with WAN1 as DHCP and WAN2 as static. After testing a...
Marcos M
10:00 AM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
I experienced this this morning, on 22.05.b.20220531.0600
- dpinger showed my DHCP6 gateway as "down"
- I ran @pgre...
→ luckman212
01:04 PM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
+1 Having this issue since 16th May on two separate boxes CE. Upgraded to 2.6 and still the same. switch to DynDns an... r a
08:50 AM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
+1 Also having this problem David Grenier
12:25 AM pfSense Packages Bug #10436: softflowd no longer sends flow data after upgrade (v0.9.9_1 -> v1.0.0)
I'm starting down a path that involves softflowd. Does anyone know if this issue persists with the latest snaps? → luckman212

06/06/2022

11:17 PM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
any updates on this? I am getting the same error too Pan Teparak
06:55 PM pfSense Packages Feature #12963: Run nmap scans in the background
I can't think of a privacy issue for either - both locations are readable by everyone. The Packet Capture page is in ... Marcos M
02:55 PM pfSense Packages Feature #12963: Run nmap scans in the background
Marcos Mendoza wrote in #note-24:
> Looks good from the testing I've done. Only suggestion I have is that the result...
Phil Wardt
02:58 PM Bug #13253 (Resolved): ``dhcp6c`` is not restarted when applying settings when multiple WANs are configured for DHCP6
After #6880 it seems that when applying settings on multiple WANs, @dhcp6c@ is not restarted so the new configuration... Jim Pingle
02:55 PM Bug #13061 (Resolved): Gateway events for IPv6 affect IPv4 OpenVPN instances and vice versa
Seems to be doing the right thing. IPv6 OpenVPN tunnel kept going when the IPv4 gateway went down and back up. We can... Jim Pingle
02:35 PM Bug #12733 (Resolved): Value of ``net.inet.ip.dummynet.*`` OIDs in ``sysctl`` are ignored
The code for @dummynet_load_module()@ in source:src/etc/inc/util.inc#L3937 ensures the module is loaded before popula... Jim Pingle
01:06 PM Bug #13252 (New): reduce frequency of php-fpm socket connection attempts from check_reload_status
When troubleshooting an issue, I discovered that my system logs were rotating every couple of minutes, due to many of... Royce Williams
12:45 PM Bug #13251: pfTop bugs - backspace key vs CTRL_H, states column, rnr not functional
Ok, fair enough but I do wonder - does backspace work for _anyone_ in this case? Because it appears undefined or at l... → luckman212
12:37 PM Bug #13251 (Not a Bug): pfTop bugs - backspace key vs CTRL_H, states column, rnr not functional
backspace vs ^H is almost always a terminal issue with your client and what it sends. Some things send ^H for backspa... Jim Pingle
12:32 PM Bug #13251 (Not a Bug): pfTop bugs - backspace key vs CTRL_H, states column, rnr not functional
I am not 100% sure but I believe there are bugs in the currently bundled version of pfTop. I opened a thread about th... → luckman212
07:32 AM Todo #13250 (Resolved): Clean up DHCP Server option language
Several options on the page have awkward or inconsistent wording
* "Denied clients will be ignored rather than rej...
Jim Pingle
07:03 AM Bug #12878 (Incomplete): Traffic shaping by interface, route queue bandwidth inbound, out by a large factor.
Jim Pingle
07:02 AM Bug #13249: Running playback comands multiple times results in PHP error
That is known and expected, they aren't designed to run more than once in the same session the way you are doing it. ... Jim Pingle
05:41 AM Bug #12645: ``filterdns`` does not monitor remote IPsec gateways for IPv6 address changes
It's under IKE Endpoint Configuration ----> Remote Gateway (IPV6), to check if FQDN for AAAA record can be used to es... Alex Zaykov
04:17 AM Bug #12645 (Resolved): ``filterdns`` does not monitor remote IPsec gateways for IPv6 address changes
Tested on 22.05-RC (built on Sat Jun 04 14:22:59 UTC 2022)
I'm not sure what to test here but there is no *add_hos...
Azamat Khakimyanov

06/05/2022

08:10 PM Bug #13249 (New): Running playback comands multiple times results in PHP error
Using the console, enter option 12 then run @playback svc restart unbound@ twice. On the second run, the following is... Marcos M
07:38 PM Regression #13248 (New): IPv6 Router Advertisements runs when config.xml does not contain an entry for the interface
After installing @22.05.b.20220531.0600@, I noticed that the @System / Routing@ logs showed the following:
* @2001...
Marcos M
07:09 PM pfSense Packages Bug #13247 (Confirmed): Open-VM-Tools service actions do not work
Installing the package @Open-VM-Tools@ creates two entries under @Status / Services@: @vmware-guestid@ and @vmware-km... Marcos M
06:51 PM pfSense Packages Feature #13246 (New): iperf3 service controls do not work
After installing the @iperf3@ package, an entry is created under @Status / Services@ which includes @Start@, @Stop@, ... Marcos M
06:17 PM pfSense Packages Feature #12963: Run nmap scans in the background
Looks good from the testing I've done. Only suggestion I have is that the results file may be best placed in @/tmp@. Marcos M
04:10 PM pfSense Plus Bug #12974: Typing anything into 1100/2100 recovery installer causes process to stop
Marcos Mendoza wrote in #note-6:
> The wording has been addressed with NG 7431. This issue can be left open to track...
Ryan Coleman
08:23 AM Regression #12821 (Confirmed): Intel e1000 driver (``em``, ``igb``) cannot pass packets tagged with VLAN ``0``
Steve Wheeler

06/04/2022

08:15 PM Regression #12821: Intel e1000 driver (``em``, ``igb``) cannot pass packets tagged with VLAN ``0``
Tested ix interfaces as well. They are not subject to this bug. Based on the fact that Broadcom NICs and Intel ix/i... Kris Phillips
07:54 PM Regression #11545: Primary interface address is not always used when VIPs are present
This bug definitely doesn't just happen with PPPoE interfaces. It is also not consistent and seems to be an "orderin... Kris Phillips
07:50 PM Bug #12878: Traffic shaping by interface, route queue bandwidth inbound, out by a large factor.
Unless further feedback is provided on this redmine, it can likely be closed due to lack of information in Rejected s... Kris Phillips
09:21 AM Feature #13245 (Resolved): Type column on Alias lists
Small QoL addition that adds a Type column to the Alias list views. I was recently cleaning up my aliases and being a... → luckman212

06/03/2022

01:50 PM Bug #12847: On startup "No routing address with matching address" might appear
Replicated the issue on:... Danilo Zrenjanin
01:08 PM Bug #12847 (Resolved): On startup "No routing address with matching address" might appear
No sign of these errors on anything I'm seeing here, static or dynamic, with or without working IPv6 when configured ... Jim Pingle
01:28 PM Bug #11692 (Resolved): ``fixup_default_gateway()`` should not remove a default gateway managed by a dynamic routing daemon
Jim Pingle
01:23 PM Bug #12606 (Resolved): ``devd`` is not configured to act on USB interface attach/detach events
devd hooks are in place and fire as expected when plugging/unplugging a USB Ethernet dongle Jim Pingle
01:09 PM Feature #13070 (Resolved): Allow auto prefix with manual prefix-length in NPt
Jim Pingle
01:01 PM Bug #13241: syslogd doesn't honor the Timezone set in the System/General Setup
Here is the feature request:
https://redmine.pfsense.org/issues/13244
Danilo Zrenjanin
12:54 PM Bug #13241: syslogd doesn't honor the Timezone set in the System/General Setup
Yeah right. It works fine after a reboot. I somehow omitted that part in the docs. Thanks!
However, adding the no...
Danilo Zrenjanin
07:10 AM Bug #13241 (Not a Bug): syslogd doesn't honor the Timezone set in the System/General Setup
That isn't a bug. Each daemon picks up the time zone change when it starts, that isn't up to @syslogd@. To fully acti... Jim Pingle
03:43 AM Bug #13241: syslogd doesn't honor the Timezone set in the System/General Setup
I am getting the same results on:... Danilo Zrenjanin
03:08 AM Bug #13241 (Not a Bug): syslogd doesn't honor the Timezone set in the System/General Setup
It shows the wrong time only in the Status/System Logs/System/General section.
I chose Europe/Belgrade Timezone. ...
Danilo Zrenjanin
01:00 PM Bug #13133 (Resolved): OpenVPN ``client-connect`` file contains ``topology``
Seems to be OK. No error in the client log now, client still gets a proper address using the correct topology Jim Pingle
01:00 PM Feature #13244 (New): Add help text under Timezone settings in the GUI
Adding the note from the docs in the GUI below the Timezone dropdown menu will be helpful.... Danilo Zrenjanin
12:57 PM Bug #12628 (Resolved): OpenVPN re-synchronization also synchronizes override entries unnecessarily in some cases
It's not clear from the original description which specific cases were not necessary, but I'm seeing the CSC files up... Jim Pingle
12:46 PM Bug #13145 (Resolved): Per-user ``route`` files are not removed from ``/tmp`` when they are no longer needed
Routes file is no longer left behind. Jim Pingle
12:42 PM Feature #12407 (Resolved): Use deferred client connections in OpenVPN
This has been back in place for a while. No problems with auth that I've seen, local or RADIUS.
Jim Pingle
12:33 PM Bug #4287: Wrong display for ppp in Interfaces page
Hi Marco,
I have the same problem like you, did you find a solution for it?
Karlo
Karlo Tomka
12:28 PM Bug #13243 (Resolved): OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
When a user authenticates to an OpenVPN instance the OpenVPN status shows an info "i" icon in the actions to display ... Jim Pingle
12:08 PM Bug #13099 (Resolved): Static routes to destinations at L2TP clients are not re-added after a client reconnects
Looks good. Following the procedure above, the route goes away when the client disconnects and comes back when the cl... Jim Pingle
11:22 AM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
follow-up issue: https://redmine.pfsense.org/issues/13242 → luckman212
09:32 AM Feature #12687 (Resolved): Option to disable auto-addition of static routes for ``dpinger``
This works OK as-is. As stated in the comments above it doesn't remove the routes, but the user can reboot or remove ... Jim Pingle
07:51 AM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
What's in now will have to be considered on its own -- any refinements should be done on a separate Redmine issue. Jim Pingle
11:20 AM Feature #13242 (Pull Request Review): Enhancements to static route creation/deletion for dpinger monitor IPs
related redmine: #12687 — (breaking out as requested by @jimp to a separate issue)
Th PR below adds some improveme...
→ luckman212
11:11 AM Todo #12619 (Resolved): Restart services on interface changes
In general this seems to be working as expected from what I can see.
If there are issues with individual services ...
Jim Pingle
10:51 AM Regression #12582 (Resolved): RADVD can be started on both HA nodes when configured with an IPv6 link-local address
Seems to be OK. With radvd set to use an LL VIP I still only see radvd running on the node with master status on its ... Jim Pingle
10:43 AM Regression #12961 (Resolved): CARP event storm when leaving persistent CARP maintenance mode
I'm only seeing one event per VIP now as expected. Jim Pingle
10:32 AM Bug #13076 (New): Marking a gateway as down does not affect IPsec entries using gateway groups
This still isn't working properly. I marked a gateway as down and it has no effect on IPsec. The dynamic DNS entry ch... Jim Pingle
07:41 AM Bug #12590 (Resolved): Dynamic DNS custom IPv6 service fails on 6rd tunnels
Jim Pingle
07:40 AM Bug #13097 (Resolved): PHP error when upgrading from before configuration revision 21.6, ``ipsec_create_vtimap()`` is undefined
No PHP error on upgrade when coming from <21.6 now. Closing. Jim Pingle
07:13 AM Bug #12612 (New): DNS Resolver is restarted during every ``rc.newwanip`` event even for interfaces not used in the resolver
The code looks like it should be right but we can debug it for the next release, it's not a blocker for 22.05. Jim Pingle
01:55 AM Bug #12612: DNS Resolver is restarted during every ``rc.newwanip`` event even for interfaces not used in the resolver
Tested... Danilo Zrenjanin
02:41 AM Bug #12609 (Resolved): IGMP Proxy server is restarted during every ``rc.newwanip`` event
Tested... Danilo Zrenjanin

06/02/2022

10:38 PM Bug #13127 (Resolved): DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
I've tested again on a fresh image and I cannot get it to repeat the blank interface name, the interface name changes... Reid Linnemann
03:30 PM Bug #13127: DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
It's just blank, the table data for the cell is empty. I'll get a chance to have a further look at it in the next few... Reid Linnemann
03:24 PM Bug #13127: DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
@rlinnemann : Can you send a screenshot of that rendered page with the blank ifname? I looked again at the code and i... → luckman212
10:33 PM Bug #13048 (Resolved): Explicit PPPoE disconnect of a WAN Gateway Group member may not restore a default route
Default gateway switches away and back as expected when disconnecting and reconnecting. Jim Pingle
10:06 PM Bug #11629 (Resolved): PPPoE WAN IP address different than expected when set static by ISP
Following the stated procedure I can't reproduce the problem on 22.05 now. I see the interface go down, and when it c... Jim Pingle
09:52 PM Bug #12975 (Resolved): IKEv2 Mobile IPsec clients do not receive ``INTERNAL_DNS_DOMAIN`` (value ``25``) attribute
The new attribute is present in the configuration, the rest is up to clients at this point. Jim Pingle
09:42 PM Bug #11984 (Resolved): Automatic Outbound NAT mode can create incorrect rules in some cases
I can't find any way to reproduce the original issue here, but the code in the change is solid, the scope is removed ... Jim Pingle
09:41 PM Bug #13230: Floating rules on VPN interfaces
That’ll be my issue then, thanks. I did wonder if that was the case. James Chambers
09:31 PM Bug #13240 (Resolved): User is forced to pick an NPt destination IPv6 prefix length even when choosing a drop-down entry which contains a defined prefix length
Following on from #4881
There are two minor issues in the NPt GUI when dealing with dynamic choices:
1. When t...
Jim Pingle
09:27 PM Feature #4881 (Resolved): Allow NPt to use dynamic IPv6 networks
Jim Pingle
09:27 PM Feature #4881: Allow NPt to use dynamic IPv6 networks
Two minor issues:
1. When there are multiple available entries the list isn't cleared and each line also contains ...
Jim Pingle
09:10 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
I saw this bug on 22.05-Devel and now on 22.05-Beta. The rules are working, but are not logged. Glenn Hall
08:55 PM Regression #12862 (Resolved): Some ``sysctl`` OIDs in ``loader.conf.local`` are silently removed
The value of @net.link.ifqmaxlen@ in @loader.conf.local@ is retained across multiple reboots on 22.05 Jim Pingle
08:16 PM Regression #13162 (Resolved): Upgrade does not work when using only IPv6 DNS servers
Seems to be fixed. On 22.01 if I set only IPv6 DNS and tell the GUI to only use remote DNS, the update check does fai... Jim Pingle
08:10 PM Bug #12721 (Resolved): IPv6 gateway group using link local addresses incorrectly logs a gateway change because it not including interface scope properly
Seems to be OK on the latest snapshot. I can't reproduce the problem there. Failover group with two IPv6 tiers, both ... Jim Pingle
08:02 PM Bug #6880 (Resolved): Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
This looks excellent on the latest snapshot.
On 22.01 each interface has a separate configuration and only one of ...
Jim Pingle
06:17 PM Bug #12611 (Resolved): SNMP daemon is restarted during every ``rc.newwanip`` event
Reid Linnemann
03:24 PM Bug #12527 (Resolved): DHCPv6 server does not skip interfaces configured with invalid ranges
Works on latest internal test snapshot. Jim Pingle
09:13 AM Bug #12527: DHCPv6 server does not skip interfaces configured with invalid ranges
The patch did the job.
Tested:...
Danilo Zrenjanin
08:51 AM Bug #12527: DHCPv6 server does not skip interfaces configured with invalid ranges
If nobody else offers feedback before 22.05 releases, this is OK to close. The change appears to be solid but I'd lik... Jim Pingle
08:38 AM Bug #12527: DHCPv6 server does not skip interfaces configured with invalid ranges
Patch was tested successfully by multiple people internally, including several dynamic and static systems in my lab. ... Jim Pingle
08:35 AM Bug #12527 (Feedback): DHCPv6 server does not skip interfaces configured with invalid ranges
Applied in changeset commit:3dc73d391eff61f490798696af78a4cdbeeeaf18. Jim Pingle
08:29 AM Bug #12527: DHCPv6 server does not skip interfaces configured with invalid ranges
MR: https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/814
Patch is attached and fixes it for me here in ...
Jim Pingle
07:56 AM Bug #12527 (Assigned): DHCPv6 server does not skip interfaces configured with invalid ranges
This caused a regression where it's skipping dhcp6 for delegated prefixes. Jim Pingle
03:23 PM Regression #13238 (Resolved): WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
Works on latest internal test snapshot. Jim Pingle
08:58 AM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
I have picked this back into the 22.05 branch and it will be included in the release. Jim Pingle
07:56 AM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
The dhcpd problem appears to be a regression from #12527 and is unrelated to this. Jim Pingle
03:07 PM Bug #13139 (Resolved): Stale ``sshdkeys.dirty`` lock file prevents generating SSH server keys
Reid Linnemann
02:07 PM Revision b79dff5b: Disable distclean to prevent removing distfiles that are still in use
Brad Davis
02:02 PM Bug #12613 (Resolved): DNS Resolver does not restart during link up/down events on a static IP address interface
Based on the original problem description and steps to reproduce it sounds like this specific request is fixed. For t... Jim Pingle
01:56 PM Bug #12613: DNS Resolver does not restart during link up/down events on a static IP address interface
Tested... Danilo Zrenjanin
01:08 PM Revision 3dc73d39: dhcp6 range check/tracked prefix. Fixes #12527
Jim Pingle
11:22 AM Regression #12949 (Resolved): The ruleset is not regenerated after assigning an interface
Confirmed this no longer happens in current 2.7 snapshots. The running ruleset is updated immediately when re-assigni... Steve Wheeler
09:34 AM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
@Flole please test with the updated version of this patch if you have the time: https://github.com/pfsense/pfsense/pu... → luckman212
07:13 AM Bug #13239 (Duplicate): ipv6 based ipsec vpn tunnel bug found with fqdn remote host
Appears to be the same as #12645 which is already fixed in 22.05/2.7.0 snapshots. Jim Pingle
03:14 AM Bug #13239: ipv6 based ipsec vpn tunnel bug found with fqdn remote host
https://forum.netgate.com/topic/171869/ipsec-vpn-bug-found?_=1654156661373 Alex Zaykov
03:13 AM Bug #13239 (Duplicate): ipv6 based ipsec vpn tunnel bug found with fqdn remote host
Hi I would to report the bug, related to ipsec vpn
In the settings of Phase 1 (ike v2)
under:
IKE Endpoint...
Alex Zaykov

06/01/2022

10:29 PM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
Jim Pingle wrote in #note-3:
> I think I've spotted the problem here. In #6880 the scripts were changed around a bit...
Daryl Morse
08:35 AM Regression #13238 (Feedback): WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
Applied in changeset commit:7b9fdf030fbe4e1d5051bf6d8962f365aeb1b69a. Jim Pingle
08:22 AM Regression #13238 (Pull Request Review): WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
I think I've spotted the problem here. In #6880 the scripts were changed around a bit and the withoutra path isn't ge... Jim Pingle
12:14 AM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
Hayden Hill wrote in #note-1:
> I am having the same issue in the development versions of 22.05. "Do not wait for RA...
Daryl Morse
10:03 PM Revision 90c1f864: Switch to hping3 since hping has been EoLed and removed upstream
Brad Davis
07:10 PM Bug #12003 (Resolved): Pie and ``fq_pie`` are missing options and do not handle floating point number input correctly
Reid Linnemann
06:35 PM Revision 4d287e88: Merge pull request #4590 from luckman212/fix-omission-of-pr4551
Jim Pingle
06:11 PM Revision 9c822e62: Merge branch 'pfsense:master' into fix-omission-of-pr4551
Luke Hamburg
05:54 PM Revision 44132b27: oops. forgot to actually process the dpinger_dont_add_static_routes flag
→ luckman212
04:41 PM Bug #12986 (Resolved): DHCP network boot filename can be incorrectly placed in DHCP Pool Options
Reid Linnemann
01:46 PM Feature #12687 (Feedback): Option to disable auto-addition of static routes for ``dpinger``
Jim Pingle
01:37 PM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
Needed one more fix: https://github.com/pfsense/pfsense/pull/4590
That may not make it into 22.05 at this point. I...
Jim Pingle
01:18 PM Revision 7b9fdf03: Always use rstold script header. Fixes #13238
Jim Pingle
01:01 PM Bug #12095: Memory leak in pcscd
Update: looks like the PCSC maintainer has fixed the mem leak: https://github.com/LudovicRousseau/PCSC/issues/55#issu... → luckman212
01:01 PM Bug #12468: Stopping IPsec daemon on the Status / Services page lead to log files flooding if pcscd daemon is enabled
Update: looks like the PCSC maintainer has fixed the mem leak: https://github.com/LudovicRousseau/PCSC/issues/55#issu... → luckman212
11:20 AM Bug #13237: dhcp6c script cannot be executed safely
I get it once every time after saving/applying WAN interface. When I looked at the code, the files get created before... Marcos M
07:55 AM Bug #13237: dhcp6c script cannot be executed safely
The real question here is why it works most of the time then suddenly fails. I'm guessing something is removing the f... Jim Pingle

05/31/2022

09:01 PM Bug #13210: PPPoE server panics with multiple client connections
https://github.com/pfsense/FreeBSD-src/commit/5e816cde27af3cd6e46ea0ffb2d167804899bebd
https://forum.netgate.com/top...
Marcos M
05:50 PM Bug #13210 (Feedback): PPPoE server panics with multiple client connections
Steve Wheeler
05:46 PM Bug #13210: PPPoE server panics with multiple client connections
Pushed fixes:
> Author: Mateusz Guzik <mjg@netgate.com>
> Date: Tue May 31 22:43:37 2022 +0000
>
> pf: fix a...
Mateusz Guzik
07:30 PM Bug #13127: DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
Hmm weird, I didn't experience that on my systems. What's the name of your interface? → luckman212
06:35 PM Bug #13127 (Assigned): DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
When I test this, the interface name becomes an empty string. Reid Linnemann
06:12 PM Bug #13127 (Resolved): DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
Reid Linnemann
06:06 PM Feature #12982: Add support for RFC7499 in RADIUS library.
Hello Marcos, after using your patch, I took the log as requested. It seems it loaded 63 rows and stopped. Frank Lee
01:34 PM Feature #12982: Add support for RFC7499 in RADIUS library.
Hello Marcos, I sent you an email on the result, but It seems it is not outputing the information you need. Not sure... Frank Lee
05:56 PM Bug #13148 (Assigned): Traffic passed by Captive Portal cannot use limiter queues on other rules
This appears to still be broken. Reid Linnemann
05:53 PM pfSense Docs Todo #13236: Document link speed limitations with igc and ix on 6100/4100
Which makes this language on the pfSense interface config pages, though correct, probably in need of some adjustment ... Chris Linstruth
04:31 PM pfSense Docs Todo #13236: Document link speed limitations with igc and ix on 6100/4100
It's been tested by a customer, along with SW and CL.
At best, the ix and igc ports on *both* the 6100 and 4100 wil...
Marcos M
07:44 AM pfSense Docs Todo #13236: Document link speed limitations with igc and ix on 6100/4100
Has that been tested and confirmed? I remember some discussion around that back when the driver was first brought in,... Jim Pingle
05:34 PM Bug #12811 (New): Services are not restarted when PPP interfaces connect
Jim Pingle
05:31 PM Bug #13215 (Assigned): Allowed MAC/IP/Hostname traffic counts for authorized users
Reid Linnemann
05:29 PM Bug #13215 (New): Allowed MAC/IP/Hostname traffic counts for authorized users
The change here was backed out, so needs to be revisited next version Jim Pingle
05:27 PM Regression #13193 (Resolved): Deleting a host entry fails to remove dummynet pipes
Reid Linnemann
05:25 PM Bug #12998 (Resolved): Wireless interface WPA configuration fields are always visible
Appears to be correct on current snapshot Jim Pingle
05:19 PM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
I am having the same issue in the development versions of 22.05. "Do not wait for RA" seems to be the culprit as well. Hayden Hill
05:07 PM Regression #13238 (Resolved): WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
My specific situation is the following:
ISP requires the following settings:
Request only an IPv6 prefix
Do no...
Daryl Morse
05:19 PM Bug #13204 (Resolved): Captive Portal reserves four (instead of two) pipes for client
Reid Linnemann
05:18 PM Bug #12649 (Closed): Allowed IP/Hostname "Direction" option is never used
Reid Linnemann
05:14 PM Regression #12999 (Resolved): Duplicate wireless interfaces are created at boot
No problem on current snapshot Jim Pingle
05:12 PM Regression #12937 (Resolved): Traffic Shaper wizard can produce an invalid ruleset when configured with an IPv4 upstream SIP server
Works now Jim Pingle
05:08 PM Bug #11764: IPv6 link local gateway default status not indicated in GUI
Jim Pingle wrote in #note-14:
> The problem here as exactly stated is solved. If we can reproduce a different (albei...
Daryl Morse
04:45 PM Bug #11764: IPv6 link local gateway default status not indicated in GUI
Hayden Hill wrote in #note-13:
> Hayden Hill wrote in #note-12:
> > I might be having the same issue here. 22.05/2....
Daryl Morse
03:17 PM Bug #11764 (Resolved): IPv6 link local gateway default status not indicated in GUI
The problem here as exactly stated is solved. If we can reproduce a different (albeit similar) problem along a separa... Jim Pingle
04:59 PM Bug #13004 (Resolved): ``write_rcfile()`` does not create ``rc_restart()`` entry
Works now Jim Pingle
04:58 PM Regression #13025 (Resolved): Some services won't start - wrong syntax in autogenerated rc.d scripts
Works now Jim Pingle
04:53 PM Bug #13092 (Resolved): PPPoE WANs fail to reconnect after parameter negotiation failure
Jim Pingle
03:39 PM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
We have tested internally here and can't reproduce any problems with SHA384 or SHA512. In each case so long as both s... Jim Pingle
08:00 AM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
That isn't what the P2P limitation is. The GUI selection for "peer-to-peer SSL/TLS" is fine, it's OpenVPN's internal ... Jim Pingle
03:38 PM Bug #13216 (Resolved): Switching nomacfilter option does not change autorized users rule format
Reid Linnemann
03:33 PM Regression #13056 (Resolved): OpenVPN ``remote_cert_tls`` option does not behave correctly when enabled and later disabled
Option toggles correctly now. I can enable it and the option goes into the config. Disable it and it comes out.
Jim Pingle
03:32 PM Bug #11941 (Resolved): Many ``exec()`` functions do not use full path to executable files
Reid Linnemann
03:28 PM Bug #12141 (Resolved): Lack of DNS or Internet connectivity causes GUI to be slow
Reid Linnemann
03:27 PM Feature #12267 (Resolved): OpenVPN option to limit concurrent connections per user
Jim Pingle
03:27 PM Bug #12332 (Resolved): OpenVPN does not clear old Cisco-AVPair anchor rules in some cases
Jim Pingle
03:25 PM Bug #12771 (Resolved): Automatic filter reload with OpenVPN client gateway uplink happens too soon or not at all
Jim Pingle
03:24 PM Regression #12884 (Resolved): OpenVPN status display for TAP mode services shows peer-to-peer instead of client list in certain cases
Jim Pingle
03:18 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
Sage Badolato wrote in #note-34:
> I cannot test 22.05, I'm on community edition.
You can try a recent 2.7.0 snap...
Jim Pingle
03:01 PM Bug #12691 (Resolved): Support encrypted ``config.xml`` files when restoring during install
Latest commit works well. I get the prompt for the password, I can enter the password and it successfully decrypts an... Jim Pingle
01:08 PM Bug #12691 (Feedback): Support encrypted ``config.xml`` files when restoring during install
MR merged. Jim Pingle
01:04 PM Bug #12691 (Pull Request Review): Support encrypted ``config.xml`` files when restoring during install
MR: https://gitlab.netgate.com/pfSense/FreeBSD-src/-/merge_requests/88
That MR has the proposed changes inside.
Jim Pingle
12:56 PM Bug #12691: Support encrypted ``config.xml`` files when restoring during install
Two problems here:
* It may not be reading the password properly. It would be better to use @dialog@ than a text p...
Jim Pingle
11:12 AM Bug #12691 (Assigned): Support encrypted ``config.xml`` files when restoring during install
Unfortunately, this does not look to be working for me.
This is what I get when I try to decrypt using the install...
Chris Linstruth
02:59 PM Bug #12672 (Resolved): GleSYS Dynamic DNS responses are not parsed properly
No access to provider, no feedback. Closing. Jim Pingle
02:58 PM Feature #12744 (Resolved): IPv6 support for DNSimple Dynamic DNS
No access to provider, no feedback. Closing. Jim Pingle
02:58 PM Feature #12752 (Resolved): Support wildcard Dynamic DNS records on DigitalOcean
No access to provider, no feedback. Closing. Jim Pingle
02:58 PM Bug #12754 (Resolved): Google Domains Dynamic DNS responses are not parsed properly
Jim Pingle
02:58 PM Bug #12761 (Resolved): Input validation prevents configuring wildcard Dynamic DNS records on Google Domains
Jim Pingle
02:49 PM Bug #12721: IPv6 gateway group using link local addresses incorrectly logs a gateway change because it not including interface scope properly
How to verify that this change is working:
1) Create gateway group "WAN_IPv6" which contains:
Tier 1: WAN1 (m...
Loren McQuade
02:31 PM Bug #12721: IPv6 gateway group using link local addresses incorrectly logs a gateway change because it not including interface scope properly
It lacked an assignee before, mostly it's for tracking who fixed the issue.
Ideally we'd like feedback from someon...
Jim Pingle
02:28 PM Bug #12721: IPv6 gateway group using link local addresses incorrectly logs a gateway change because it not including interface scope properly
I see you have assigned this back to me, but I am unsure of what further action is needed on my part. I can verify a... Loren McQuade
02:12 PM Bug #12749 (Resolved): Uninitialized array in ``array_remove_duplicates()``
Jim Pingle
02:10 PM Todo #13100 (Resolved): Transition Captive Portal from IPFW to PF
The work here is complete, any issues we find can be raised separately. Jim Pingle
02:09 PM Bug #12801 (Resolved): User password hashes pseudo-random number generator may return insecure salt value
The correct function is in place now and working properly. Jim Pingle
02:06 PM Bug #13116 (Resolved): OpenVPN client ``tls-client``/``client`` configuration directive not handled properly
This appears to be correct and consistent now. Jim Pingle
02:00 PM Regression #13155 (Resolved): Rule labels in pftop output are not correct
All good now. Proper labels are shown in pftop label view and it didn't negatively impact the firewall log view. Jim Pingle
01:55 PM Todo #13149 (Resolved): Remove unnecessary trailing colon after Outbound NAT "Automatic Rules" section header
The trailing colon is gone. Jim Pingle
01:55 PM Todo #13129 (Resolved): OpenVPN status page improvements
The new changes are present and working well. Jim Pingle
01:50 PM Todo #12701 (Resolved): Reorganize CARP status page
Looks great now Jim Pingle
01:49 PM Feature #12092 (Closed): Utilize new ``pfctl`` abilities to kill states
This has been working well for a while now. Any issues we hit from here can be addressed separately.
Jim Pingle
01:48 PM Regression #13163 (Resolved): Incorrect variable in package error message results in "Array" being printed instead of package name
Jim Pingle
01:42 PM Regression #13178 (Resolved): Incorrect usage of DSCP hex value
This is OK as-is for now. We could consider the other change as a separate request for the next release if needed. Jim Pingle
01:28 PM Bug #9263 (Resolved): Incorrect ICMP reply when using limiters
Assigning to Kristof since it was likely fixed along the way when moving dummynet and such info PF Jim Pingle
01:19 PM Feature #12687 (Resolved): Option to disable auto-addition of static routes for ``dpinger``
That would have to wait for the next release, make a new feature request issue with a link back to this one to track ... Jim Pingle
12:46 PM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
I have a new PR almost ready that dynamically adds/removes the static routes when the checkbox is changed without req... → luckman212
12:04 PM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
This tested OK to me. Note that I only tested the checkbox in on the gateway, since it looks like the other subjects ... Chris Linstruth
01:05 PM Regression #13142 (Resolved): PHP shell ``pfanchordrill`` script produces errors on captive portal tables
The contents of nested captive portal anchors are now displayed as expected. Jim Pingle
12:58 PM Bug #13237: dhcp6c script cannot be executed safely
You're right, I misread it. It's likely what you're thinking. Marcos M
12:42 PM Bug #13237: dhcp6c script cannot be executed safely
Setuid on a shell script? That doesn't seem appropriate. And I don't think that lines up with the checks.
The checks...
Denny Page
12:26 PM Bug #13237: dhcp6c script cannot be executed safely
The checks done for this are
* no setuid
** setuid'ed execution not allowed
** lstat failed
* the file must be owned ...
Marcos M
10:49 AM Bug #13237 (New): dhcp6c script cannot be executed safely
*22.05 Plus Beta on system boot*
When the "Do not wait for a RA" option is selected on the WAN interface, /var/etc...
Denny Page
12:23 PM Regression #13192 (Resolved): Default pipe rate limits are applied to allowed mac/ip/host entries
Reid Linnemann
12:22 PM Regression #13191 (Resolved): Deleting a passthru mac entry fails to remove pf rules and dummynet pipes associated with the passthru mac
Reid Linnemann
12:21 PM Bug #13169 (Resolved): captiveportal_ether_delete_entry() does not delete anchors/pipes
Reid Linnemann
12:18 PM Regression #13147 (Resolved): Captive Portal: Idle timeout does not see activity
Reid Linnemann
12:18 PM Feature #12945 (Resolved): Implement missing ipfw equivalents in libpfctl necessary for captiveportal
Reid Linnemann
12:15 PM Regression #12834 (Resolved): Only TCP traffic is passed outbound through IPFW
Closing, ipfw is out of the mix for 2.7.0/22.05 Reid Linnemann
11:42 AM pfSense Docs Todo #12756: Add information on correct MTU to use with WireGuard
https://lists.zx2c4.com/pipermail/wireguard/2017-December/002201.html... Marcos M
07:58 AM pfSense Docs Todo #12756: Add information on correct MTU to use with WireGuard
@viktor or @cmcdonald — What should the MTU be set to? 1420?
I recently spent a few hours troubleshooting a slow s...
→ luckman212
10:55 AM pfSense Docs New Content #13205: ZFS Boot Environment documentation
Added docs for the new option to disable automatic BE creation during upgrade: https://gitlab.netgate.com/docs/pfSens... Jim Pingle
10:37 AM Bug #13175: PHP error on MAC entry add/edit
Use the revision ID linked in the comment after that.
https://github.com/pfsense/pfsense/commit/b7ddc1b810f16c827c...
Jim Pingle
09:33 AM Bug #13175: PHP error on MAC entry add/edit
Viktor Gurov wrote in #note-2:
> fix:
> https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/787
The link...
Rafael Ferreira
07:55 AM Bug #13230 (Not a Bug): Floating rules on VPN interfaces
From the general description it sounds like when using rules on assigned VPN interfaces you get reply-to so traffic r... Jim Pingle
07:37 AM Bug #13235 (Not a Bug): URL in firewall rule hover does nothing
It's listing the contents of the alias. As that is a URL type alias, that is the content of the alias.
Linking the...
Jim Pingle
07:29 AM Bug #13231 (Not a Bug): OpenVPN custom options may fail after save/restore
OpenVPN directives are to be separated by semicolons, not newlines. That's stated in the text above the box and in th... Jim Pingle
07:20 AM Bug #13093 (In Progress): LDAP authentication fails with extended query and RFC2307 group lookups enabled
OK, we'll nudge this forward for now and proceed once we have more detail. Jim Pingle
02:13 AM pfSense Packages Feature #10818: UDP Broadcast Relay
Hey guys thanks for the shout out, but I have NO clue how to make this a package.
All I was able to do was build a...
Garth Kirkwood
02:02 AM pfSense Packages Feature #10818: UDP Broadcast Relay
Thank you for the information.
Let's hope @Garth Kirkwood sees this then
Øystein Gåsdal

05/30/2022

04:59 PM Bug #13093: LDAP authentication fails with extended query and RFC2307 group lookups enabled
Extended query works.
RFC2307 groups work.
Authentication fails when both are enabled.
The site I'm testing ...
Chris Linstruth
04:57 PM Bug #13093: LDAP authentication fails with extended query and RFC2307 group lookups enabled
I think this is probably still not right. Chris Linstruth
04:02 PM Bug #12923 (Resolved): DHCP "Ignore denied clients" option with MAC Deny list set causes DHCP server to not start
Working correctly on... Christopher Cope
03:54 PM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
Thanks for pointing out the RA-only restriction. I see that stephenw10 has replied in the original forum string that... Steve Wilson
09:32 AM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
Try to reproduce it with OpenVPN Server in Remote Access mode, Peer-to-Peer is not supported - see https://redmine.pf... Marcos M
12:28 PM pfSense Plus Bug #13074: AES-GCM with SafeXcel on Netgate 2100 causes MBUF overload
I mean to say it's not a SafeXcel issue specifically. Thank you for confirming it's only on the 2100 (ARM) platform. Marcos M
12:15 PM pfSense Plus Bug #13074: AES-GCM with SafeXcel on Netgate 2100 causes MBUF overload
Marcos Mendoza wrote in #note-3:
> Note that the issue may not be specific to SafeXcel - e.g. it could happen with In...
Chris S
11:06 AM pfSense Plus Bug #13074: AES-GCM with SafeXcel on Netgate 2100 causes MBUF overload
Note that the issue may not be specific to SafeXcel - e.g. it could happen with Intel QAT as well. Marcos M
12:25 PM Feature #12982: Add support for RFC7499 in RADIUS library.
The issue needs to be narrowed down further. Apply the following patch, reproduce the issue, then submit the /tmp/_DE... Marcos M
10:56 AM pfSense Packages Regression #12140 (Closed): DNSBL https webserver not working
Could not reproduce on 22.05 with pfBlockerNG-devel 3.1.0_4. The no logging of IP addresses has already been resolved... Marcos M
10:40 AM pfSense Packages Feature #10242 (New): E2guardian Web filtering package
Viktor Gurov
10:29 AM pfSense Packages Regression #12476 (Resolved): Suricata 6.0.3_3 Pass List ignores all single IPs
Marcos M
03:30 AM pfSense Packages Feature #11385 (Resolved): Add WireGuard tunneled networks to vpnaddresses list
Tested on 22.01 and on 22.05-BETA (built on Fri May 27 06:21:09 UTC 2022)
When I created Pass List with 'VPN Addre...
Azamat Khakimyanov
02:00 AM pfSense Packages Bug #11892 (Resolved): WireGuard: dpinger does not start correctly on a WireGuard gateway at boot
Tested on 21.05_2, 22.01 and on 22.05-BETA (built on Fri May 27 06:21:09 UTC 2022)
I saw no issue with dpinger and...
Azamat Khakimyanov

05/29/2022

10:57 PM Feature #12982: Add support for RFC7499 in RADIUS library.
Any new update? Frank Lee
08:31 PM Bug #13230 (Feedback): Floating rules on VPN interfaces
More information is needed to understand the issue. Is this occurring with an OpenVPN Server or Client configuration ... Marcos M
07:56 PM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
Hopefully this will be reproducible:
1. Set up Non-DCO OpenVPN server and client with follwing config options: pe...
Steve Wilson
06:31 PM pfSense Plus Bug #13233 (Feedback): OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
Tested on @22.05.b.20220524.0600@.
I was unable to reproduce this issue using OpenVPN RA TLS+User auth. Taking an ...
Marcos M
07:00 PM Bug #12878 (Feedback): Traffic shaping by interface, route queue bandwidth inbound, out by a large factor.
Please test 22.05 BETA when possible and let us know if the issue persists. Details on the Traffic Shaping config and... Marcos M
06:56 PM Bug #12877 (Feedback): Cloudflare DynDNS fails to update more than two addresses
If possible, please re-test after applying the available patch found with the System_Patches package. Marcos M
06:49 PM pfSense Plus Bug #13041 (Closed): DNS resolution of internal network names when logged in via OpenVPN requires workaround
Marcos M
06:38 PM pfSense Plus Bug #13232 (Duplicate): Restoring Config with OpenVPN Custom Options Removes Carriage Returns
This seems more like a feature than a bug, considering that the description and documentation both say to separate wi... Marcos M
06:17 PM Bug #13234 (Not a Bug): Separator locations pushed down when pfSense is rebooted
pfBlockerNG's auto rule creation will affect the placement of separators - this is likely what's happening. If you di... Marcos M
10:29 AM Bug #13234 (Not a Bug): Separator locations pushed down when pfSense is rebooted
This happens when I place a separator at the top of the floating rules and reboot the router. I have not checked othe... Jon Brown
05:34 PM Feature #8173: dhcp6c - RAW Options
Please let us have these features added to pfSense. Half of france is using OPNsense because nothing happens on this ... Tue Madsen
02:09 PM pfSense Docs Todo #13236 (Resolved): Document link speed limitations with igc and ix on 6100/4100
> The I225 built-in phy doesn't support fixed operation, so a speed/duplex setting is emulated by selecting that sing... Marcos M
12:09 PM pfSense Packages Feature #10818: UDP Broadcast Relay
There's no GUI for it, but it can be installed on 22.05/2.7:... Marcos M
11:21 AM pfSense Packages Bug #13153 (Resolved): Static routes bound to WireGuard interfaces are not restored after down / up events
Tested on 22.01 and on 22.05-BETA (built on Fri May 27 06:21:09 UTC 2022)
I wasn't able to reproduce this issue. A...
Azamat Khakimyanov
11:07 AM Bug #13235 (Not a Bug): URL in firewall rule hover does nothing
There is URL present in the modal box you get when you hover over a rule. This URL does nothing.
* Should this URL...
Jon Brown
06:38 AM pfSense Packages Bug #12251 (Resolved): Wireguard 0.1.5 - ignores "KeepAlive" parameter if empty (instead of disabling)
Tested on 22.01
When I used empty 'Keep Alive' field, I got in config: _*PersistentKeepalive = 0*_
When I tried...
Azamat Khakimyanov
03:49 AM pfSense Packages Feature #12719 (Resolved): add igc(4) to the list of INLINE mode (iflib/netmap) supported cards
Tested on 22.01
Interface *igc* was added into 'Supported drivers' list: _Supported drivers: bnxt, cc, cxgbe, cxl, e...
Azamat Khakimyanov
03:48 AM pfSense Packages Feature #11560 (Resolved): add ena(4) to the list of INLINE mode (netmap) supported cards
Tested on 22.01
Interface *ena* was added into 'Supported drivers' list: _Supported drivers: bnxt, cc, cxgbe, cxl, e...
Azamat Khakimyanov

05/28/2022

07:16 PM pfSense Plus Bug #13233 (Feedback): OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
OpenVPN DCO configurations specifying an auth digest algorithm of SHA512 fail to connect. Changing the algorithm to ... Steve Wilson
06:50 PM Bug #12875: Import zabbix-agent6 and zabbix-proxy6 from FreeBSD Ports
Discussed with engineering. This will get brought over in the next repo sync. Kris Phillips
03:19 PM pfSense Plus Bug #13232 (Duplicate): Restoring Config with OpenVPN Custom Options Removes Carriage Returns
If you back up a config on one device and then restore it in another, if you have an OpenVPN client (potentially serv... Kris Phillips
03:06 PM Regression #12821: Intel e1000 driver (``em``, ``igb``) cannot pass packets tagged with VLAN ``0``
Tested this on igc interfaces and it appears this only affects e1000-based NICs. Other Intel NICs would seem to be f... Kris Phillips
02:13 PM pfSense Docs New Content #13211: OpenVPN DCO Documentation
Much more clear to me, thanks! Marcos M
02:10 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
I cannot test 22.05, I'm on community edition. Sage Badolato
01:13 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
I suggest testing on 22.05 BETA if possible. If the issue persists there, it may be related to https://redmine.pfsens... Marcos M
02:01 PM Regression #13203 (Resolved): Floating rules without an interface are not loaded
Marcos M
01:47 PM pfSense Plus Bug #12974: Typing anything into 1100/2100 recovery installer causes process to stop
The wording has been addressed with NG 7431. This issue can be left open to track the behavior issue itself, as it sh... Marcos M
01:14 PM Bug #13228: Recovering interface gateway may not be added back into gateway groups and rules when expected
May be related to https://redmine.pfsense.org/issues/12920. Marcos M
12:59 PM Bug #13231 (Not a Bug): OpenVPN custom options may fail after save/restore
Sometimes after restoring a backup XML file, custom options get formatted improperly. That prevents the OpenVPN servi... Danilo Zrenjanin
12:45 PM Feature #4259 (Resolved): Port forward NAT rules with "any" protocol
Danilo Zrenjanin
12:45 PM Feature #4259: Port forward NAT rules with "any" protocol
Tested:... Danilo Zrenjanin
06:03 AM pfSense Packages Feature #10818: UDP Broadcast Relay
Hi.
Any news on this?
Eagerly awaiting this one
Øystein Gåsdal

05/27/2022

11:54 PM Bug #13230 (Not a Bug): Floating rules on VPN interfaces
With floating rules on OpenVPN and WireGuard interfaces, matching traffic doesn’t seem to return with rules that pass... James Chambers
09:44 PM pfSense Packages Feature #12658: Adding prometheus metrics to darkstat
I think the package is in the FreeBSD ports:... Karim Elatov
07:31 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
I can also confirm that I can replicate this exact issue on my PFSense. Both as a VM and as bare metal.
Using a H...
Sage Badolato
03:04 PM pfSense Docs Todo #13229 (Feedback): Update documentation for IPFW to PF transition for Limiters and Captive Portal
Relevant commits:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/47dd08cc24bb4ffbd476b2d4aebacdb6ccbce895
...
Jim Pingle
02:59 PM pfSense Docs Todo #13229 (Resolved): Update documentation for IPFW to PF transition for Limiters and Captive Portal
Adding for tracking.
Docs are updated to reflect that IPFW is no longer used, it's all in PF now.
Jim Pingle
01:59 PM pfSense Docs New Content #13223 (Feedback): Document new gateway state killing behavior
This should complete the relevant updates (and then some):
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/7...
Jim Pingle
01:15 PM Revision e5d97d7c: Update CARP status state sync note. Fixes #12701
Jim Pingle
10:58 AM Bug #13228 (Resolved): Recovering interface gateway may not be added back into gateway groups and rules when expected
When an interface/gateway recovers and rc.newwanip runs, the gateway may not end up in the ruleset in groups or rules... Jim Pingle
10:15 AM pfSense Plus Feature #13227: Group-based Mobile IPsec Virtual Address Pool assignment via RADIUS
I Should mention you can use my modifcation afterwards by creating the groups identifier and IP pool needed, by creat... Tue Madsen
10:09 AM pfSense Plus Feature #13227 (Resolved): Group-based Mobile IPsec Virtual Address Pool assignment via RADIUS
Currently you cannot create additional Virtual IP Pools to assign mobile users IP addresses from, if you are using EA... Tue Madsen
08:55 AM Todo #12701 (Feedback): Reorganize CARP status page
Applied in changeset commit:e5d97d7ce8bd3346ef8fa6f5477182331d2174b4. Jim Pingle
08:03 AM Todo #12701 (In Progress): Reorganize CARP status page
This could use one small change, to add a note/link in the info block saying the user can set a custom filter host ID... Jim Pingle
08:01 AM Todo #12701 (Resolved): Reorganize CARP status page
Jim Pingle
05:12 AM Todo #12701: Reorganize CARP status page
Tested.... Danilo Zrenjanin
08:00 AM Regression #11545 (New): Primary interface address is not always used when VIPs are present
That other issue could solve it for PPP type interfaces but it's happening on systems without PPP interfaces and thos... Jim Pingle
02:53 AM Regression #11545 (Feedback): Primary interface address is not always used when VIPs are present
Viktor Gurov
02:52 AM Regression #11545: Primary interface address is not always used when VIPs are present
Should be fixed in #11629
Please re-test on the latest 22.05/2.7 snapshots.
Viktor Gurov
06:29 AM Bug #13226 (Confirmed): Disconnecting a user from Captive Portal may allow previously established connections to continue
Able to reproduce.
It looks like @pfSense_kill_status()@ and @pfSense_kill_src states()@ are successfully kill TCP...
Viktor Gurov
05:11 AM Bug #13226: Disconnecting a user from Captive Portal may allow previously established connections to continue
It looks like @pfSense_kill_states()@ and @pfSense_kill_srcstates()@ does not work properly:
https://github.com/pfse...
Viktor Gurov
05:02 AM Bug #13226 (Resolved): Disconnecting a user from Captive Portal may allow previously established connections to continue
Steps to reproduce:
1. Connect to the network through the CP portal.
2. Establish OpenVPN forcing all traffic thr...
Danilo Zrenjanin
05:25 AM Bug #13218: GIF-based interface MTU is assigned to parent interface on boot when parent interface is a LAGG
I've applied it and it looks to do the job. I will keep an eye on it and throw in a couple of reboots over the weeken... Graeme Bragg
02:59 AM Bug #13218: GIF-based interface MTU is assigned to parent interface on boot when parent interface is a LAGG
Graeme Bragg wrote in #note-3:
> Thanks for looking at this so quickly. Please let me know if you need/want me to te...
Viktor Gurov
05:21 AM Bug #13225: Bridges with QinQ interfaces not properly set up at boot
fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/810
Viktor Gurov
03:14 AM Bug #13225 (Resolved): Bridges with QinQ interfaces not properly set up at boot
We have a setup that includes several OpenVPN tunnels, some of them using QinQ. When system is configured using WebUI... Lauri Liuhto
01:58 AM Bug #13224 (Duplicate): Email notification flood when UPS (NUT) and WAN send notifications
When my UPS (monitored with NUT) and one of my WAN (PPPoE) both send email notifications close to each other, it star... Riccardo Ambrosi

05/26/2022

04:29 PM Regression #13182 (Resolved): Enabling /var as a RAM disks conflicts with ZFS
Working as expected on... Christopher Cope
03:33 PM pfSense Docs New Content #13223: Document new gateway state killing behavior
Partial progress: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/a77fae599dcfe8b103cc594bb0164f90723af877 Jim Pingle
03:31 PM pfSense Docs New Content #13223 (In Progress): Document new gateway state killing behavior
Jim Pingle
03:31 PM pfSense Docs New Content #13223 (Resolved): Document new gateway state killing behavior
Add docs for the new gateway state killing behavior, including:
* New choices for the option on System > Advanced,...
Jim Pingle
03:05 PM Revision ce541827: Change Captive Portal anchors order and remove tagged option from L2 rules.
Viktor Gurov
02:28 PM Bug #13222 (New): CARP IP does not listen for NAT-PMP packets
If a client is using a CARP IP for the Network's Gateway address and sends a [x0x0] packet along UDP port 5351 on the... Gavin Greenwalt
01:46 PM Regression #11545: Primary interface address is not always used when VIPs are present
When dynamic interface addresses change, say via DHCP, the common mechanism for handling the address transition is no... Reid Linnemann
01:07 PM Revision 899e2b10: Do not duplicate Captive Portal passthru rule if HTTPS login is enabled
Viktor Gurov
12:54 PM Bug #13218: GIF-based interface MTU is assigned to parent interface on boot when parent interface is a LAGG
Thanks for looking at this so quickly. Please let me know if you need/want me to test anything. Graeme Bragg
07:21 AM Bug #13218 (Pull Request Review): GIF-based interface MTU is assigned to parent interface on boot when parent interface is a LAGG
Jim Pingle
04:19 AM Bug #13218: GIF-based interface MTU is assigned to parent interface on boot when parent interface is a LAGG
fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/806
Viktor Gurov
11:19 AM Bug #13185 (Resolved): LDAP setup does not display 'Global Root CA List' option unless another CA also exists
Tested:... Danilo Zrenjanin
10:51 AM Regression #12827: High latency and packet loss during a filter reload
Updating subject for release notes. Jim Pingle
10:49 AM Regression #13212: Captive Portal redirect not working if HTTPS login is enabled
Not a problem in a release, excluding from release notes. Jim Pingle
10:49 AM Regression #13192: Default pipe rate limits are applied to allowed mac/ip/host entries
Not a problem in a release, excluding from release notes. Jim Pingle
10:48 AM Regression #13191: Deleting a passthru mac entry fails to remove pf rules and dummynet pipes associated with the passthru mac
Not a problem in a release, excluding from release notes. Jim Pingle
10:48 AM Todo #13100: Transition Captive Portal from IPFW to PF
Updating subject for release notes. Jim Pingle
10:46 AM Bug #12733: Value of ``net.inet.ip.dummynet.*`` OIDs in ``sysctl`` are ignored
Updating subject for release notes. Jim Pingle
09:59 AM Feature #13221: Simple View Expired Vouchers Bandwidth History.
Because people says they were not using the data while they did.
I was thinking it is a good idea because that inf...
Raymond Chauke
08:25 AM Feature #13221 (Rejected): Simple View Expired Vouchers Bandwidth History.
Keeping that kind of data for vouchers isn't viable. Jim Pingle
08:23 AM Feature #13221 (Rejected): Simple View Expired Vouchers Bandwidth History.
In the upcoming Latest development 2.8.0-RELEASE i hope to see the sixth tab under the STATUS/CAPTIVE PORTAL MENU tha... Raymond Chauke
08:19 AM pfSense Packages Todo #13190 (Closed): Update System_Patches package for pfSense+ 22.05
Jim Pingle
08:09 AM Bug #13217: dhclient using default pid file location which does not exist
I checked several systems here and most of them had @/var/run/dhclient/@ as expected with proper PID files inside, bu... Jim Pingle
04:29 AM Bug #13217: dhclient using default pid file location which does not exist
fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/807
Viktor Gurov
08:08 AM Feature #13220 (New): Voucher per-roll bandwidth restrictions and traffic quotas

I hope PFSENSE can Enable per-voucher roll bandwidth restriction. where during the vouchers roll creation i can b...
Raymond Chauke
08:05 AM Feature #13219 (New): Enable/Disable single voucher roll
Dear PfSense Team.
I have a voucher roll that is lost, All i want is to disable only that specific lost roll until...
Raymond Chauke

05/25/2022

08:52 PM Bug #13218 (Resolved): GIF-based interface MTU is assigned to parent interface on boot when parent interface is a LAGG

Minimal reproducible configuration:
round-robin LAGG pair assigned as the WAN interface with either an MTU of 1...
Graeme Bragg
08:27 PM Bug #12920: Gateway behavior differs when the gateway does not exist in the configuration
Updating original post with results from 22.05 BETA.
Now the gateway returns to online in every case. However, there...
Marcos M
08:37 AM Bug #12920 (Pull Request Review): Gateway behavior differs when the gateway does not exist in the configuration
Jim Pingle
07:54 AM Bug #12920: Gateway behavior differs when the gateway does not exist in the configuration
fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/804
Viktor Gurov
04:03 PM pfSense Packages Todo #13190: Update System_Patches package for pfSense+ 22.05
Tested on... Christopher Cope
02:23 PM pfSense Docs New Content #13205: ZFS Boot Environment documentation
Added examples for space usage plus a screenshot of the BE list in the GUI:
https://gitlab.netgate.com/docs/pfSense-...
Jim Pingle
12:46 PM pfSense Docs New Content #13205: ZFS Boot Environment documentation
Additional updates: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/89bec80995d33e551bac302b97cdb0ede8192b0e Jim Pingle
02:02 PM Revision 16a6bf51: Always display Global Root CA List. Fixes #13185
Viktor Gurov
02:01 PM Revision 937b2a59: Reload Captive Portal rules on nomacfilter or per-user bandwidth change. Fixes #13216
Viktor Gurov
01:47 PM Revision e65783ae: Check CP rules tag on all steps. Fixes #13215
Viktor Gurov
01:00 PM Revision af54e92e: Get all nested anchors when drilling. Fixes #13142
Jim Pingle
12:25 PM pfSense Docs New Content #13211: OpenVPN DCO Documentation
Fixed: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/c57402fb16d3519d4394697a36c99c7f2fbc2b9b Jim Pingle
11:36 AM Bug #13217 (New): dhclient using default pid file location which does not exist
The dhclient by default uses the location of /var/run/dhclient/dhclient.interface.pid to store the PID for the client... Paul Arbour
09:10 AM Bug #13185 (Feedback): LDAP setup does not display 'Global Root CA List' option unless another CA also exists
Applied in changeset commit:16a6bf51901960c81b1a36c908b6df750456f476. Viktor Gurov
08:36 AM Bug #13185 (Pull Request Review): LDAP setup does not display 'Global Root CA List' option unless another CA also exists
Jim Pingle
04:14 AM Bug #13185: LDAP setup does not display 'Global Root CA List' option unless another CA also exists
fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/803
Viktor Gurov
09:10 AM Bug #13216 (Feedback): Switching nomacfilter option does not change autorized users rule format
Applied in changeset commit:937b2a59a2c4a5c88df30835dc3f86901a91e257. Viktor Gurov
08:35 AM Bug #13216 (Pull Request Review): Switching nomacfilter option does not change autorized users rule format
Jim Pingle
03:46 AM Bug #13216: Switching nomacfilter option does not change autorized users rule format
fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/802
Viktor Gurov
03:15 AM Bug #13216 (Resolved): Switching nomacfilter option does not change autorized users rule format
Authorized CP users rules format is not changed after switching the @nomacfilter@ option,
workaround - disable/enabl...
Viktor Gurov
09:10 AM Bug #13215 (Feedback): Allowed MAC/IP/Hostname traffic counts for authorized users
Applied in changeset commit:e65783ae7ec9aa7234e6cde61d2f73cd927080fa. Viktor Gurov
08:34 AM Bug #13215 (Pull Request Review): Allowed MAC/IP/Hostname traffic counts for authorized users
Jim Pingle
03:06 AM Bug #13215: Allowed MAC/IP/Hostname traffic counts for authorized users
fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/801
Viktor Gurov
03:03 AM Bug #13215 (Incomplete): Allowed MAC/IP/Hostname traffic counts for authorized users
This is due to rewriting pf tags.
CP rules must check @tagged@ value on all steps.
Viktor Gurov
08:20 AM pfSense Packages Bug #13214 (Pull Request Review): AttributeError: 'NoneType' object has no attribute 'text'
Jim Pingle
02:57 AM pfSense Packages Bug #13214: AttributeError: 'NoneType' object has no attribute 'text'
Updated pull request [[https://github.com/pfsense/FreeBSD-ports/pull/1168]] Ian Grindley
02:51 AM pfSense Packages Bug #13214 (Resolved): AttributeError: 'NoneType' object has no attribute 'text'
After installing Prometheus node_exporter error messages appeared containing the following:
Arpwatch Notification ...
Ian Grindley
08:19 AM Bug #13213 (Not a Bug): allow no-lan configurations
That is just the default interface label. You can rename that to whatever you want. Anything else it triggers you can... Jim Pingle
02:16 AM Bug #13213 (Not a Bug): allow no-lan configurations
The scenario:
pfSense is launched in a cloud provider (like AWS or Hetzner). By default there's only one interface ...
Alex Kolesnik
08:10 AM Regression #13142 (Feedback): PHP shell ``pfanchordrill`` script produces errors on captive portal tables
Applied in changeset commit:af54e92e65495d8ad76eb9698d5ae6b709504c0b. Jim Pingle
08:02 AM Regression #13142 (In Progress): PHP shell ``pfanchordrill`` script produces errors on captive portal tables
This needs one more small fix as pfanchordrill is not catching the new captive portal nested anchors. Jim Pingle
07:57 AM Feature #1831: Captive portal IPv6 support
Now that Captive Portal has been migrated to pf this may be possible with some effort. If not we can always re-evalua... Jim Pingle
07:41 AM Regression #13212 (Resolved): Captive Portal redirect not working if HTTPS login is enabled
This is working for me as well on the latest snapshot. User gets appropriately redirected to the portal page using th... Jim Pingle
06:11 AM Regression #13212: Captive Portal redirect not working if HTTPS login is enabled
Tested the patch on the:... Danilo Zrenjanin
04:27 AM Feature #9536: Support dynamic prefix in DHCPv6 Server
This ticket is already open for years now.
Any chance to get dynamic prefix delegation to downstream router work ?
Manuel Wagner
03:50 AM pfSense Packages Bug #13209: Parsing Filter log by pfBlockerNG creates IP Block log with Source/Destination mixed up or wrong Direcion
Azamat Khakimyanov wrote:
> I think parsing function pfb_daemon_filterlog from https://gist.githubusercontent.com/BB...
Djerk Geurts
03:10 AM Bug #12733 (Feedback): Value of ``net.inet.ip.dummynet.*`` OIDs in ``sysctl`` are ignored
Implemented: https://github.com/pfsense/pfsense/blob/master/src/etc/inc/captiveportal.inc#L495 Viktor Gurov
01:54 AM Revision fee50323: captiveportal: Add both https/http rules for cps with https. Fixes #13212
Alter captiveportal_zone_portalports to return an array of alias/port pairs
rather than a single pair. If https is en...
Reid Linnemann

05/24/2022

09:05 PM Regression #13212 (Feedback): Captive Portal redirect not working if HTTPS login is enabled
Applied in changeset commit:fee503237a77916b6b9d2fdc3c61ecb7b3d8fcc8. Reid Linnemann
03:17 PM Regression #13212 (Resolved): Captive Portal redirect not working if HTTPS login is enabled
With "Enable HTTPS login" checked and a proper (trusted, via LE/ACME) cert in place, captive portal clients do not de... Jim Pingle
08:28 PM Revision 514441c6: Fix CP pipe function call. Fixes #13204
Jim Pingle
08:09 PM pfSense Plus Bug #13206: SG-3100 LED GPIO hangs
Hi Jim,
Thanks for the update.
As this issue is already being tracked internally, would you happen to know if t...
Daniel Subert
07:23 AM pfSense Plus Bug #13206: SG-3100 LED GPIO hangs
We're already tracking this internally (NG 5882) but have yet to reliably reproduce it. We've only encountered it a v... Jim Pingle
01:12 AM pfSense Plus Bug #13206 (New): SG-3100 LED GPIO hangs
Hi,
https://forum.netgate.com/topic/165566/number-of-running-processes-increasing
We seem to be experiencing th...
Daniel Subert
07:53 PM Revision b4a6c702: Remount ZFS datasets after configuring RAM disks to ensure they are used. For #13182
Christian McDonald
06:37 PM Bug #11764: IPv6 link local gateway default status not indicated in GUI
Hayden Hill wrote in #note-12:
> I might be having the same issue here. 22.05/2.07 Beta, IPV6 is "working" but gatew...
Hayden Hill
12:53 PM Bug #11764: IPv6 link local gateway default status not indicated in GUI
I might be having the same issue here. 22.05/2.07 Beta, IPV6 is "working" but gateway monitor always shows "pending".... Hayden Hill
05:04 PM Bug #13014: Deadlock in Charon VICI interface
No, this is not fixed. However, chances are excellent this is an old & known bug: use-after-free in key-related state... Mateusz Guzik
04:50 PM Bug #13014: Deadlock in Charon VICI interface
We think this is fixed, but need additional testing to know for sure. Brad Davis
04:29 PM Revision 262e6900: Fix RAM disk handling in pfSense-rc on ZFS
Christian McDonald
04:22 PM pfSense Docs New Content #13211: OpenVPN DCO Documentation
> OpenVPN DCO is available exclusively on pfSense® Plus software
May be misinterpreted to mean DCO is only available...
Marcos M
02:10 PM pfSense Docs New Content #13211 (Feedback): OpenVPN DCO Documentation
Added DCO to the docs: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/dbef94227eb26be4be76655fedc0f8aa3df9bc43... Jim Pingle
09:50 AM pfSense Docs New Content #13211 (In Progress): OpenVPN DCO Documentation
Jim Pingle
09:50 AM pfSense Docs New Content #13211 (Resolved): OpenVPN DCO Documentation
Add documentation for OpenVPN DCO including:
* Similar content to the recent blog post summarizing what it is/how ...
Jim Pingle
03:56 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
I added the setting from https://docs.netgate.com/pfsense/en/latest/troubleshooting/filterdns-thread-errors.html and ... Eduard Rozenberg
02:34 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
I was able to (unreliably) reproduce this on latest 22.05 snapshot. I then exited filterdns and started it with verbo... Marcos M
03:31 PM Bug #13204: Captive Portal reserves four (instead of two) pipes for client
One function call was missed when making this change, I fixed it: https://gitlab.netgate.com/pfSense/pfSense/-/commit... Jim Pingle
02:37 PM pfSense Docs New Content #13205: ZFS Boot Environment documentation
Looks good! Marcos M
02:34 PM pfSense Docs New Content #13205 (Feedback): ZFS Boot Environment documentation
Updates based on feedback: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/ad9ef24ac5101c5bd253c24df338bb4b8453... Jim Pingle
02:14 PM pfSense Docs New Content #13205 (In Progress): ZFS Boot Environment documentation
Jim Pingle
11:43 AM pfSense Docs New Content #13205: ZFS Boot Environment documentation
Feedback:
h3. Managing Boot Environments in the GUI
> Indicates the current next ZFS Boot Environment
italicize "nex...
Marcos M
02:24 PM Revision a1ccf0db: Improvements to ramdisk functions for improved handling on ZFS
Christian McDonald
01:14 PM Revision ff72903f: PKG_DBDIR/CACHEDIR should be accessed at /var/db/pkg and /var/cache/pkg in all cases
Christian McDonald
12:44 PM pfSense Packages Bug #13209: Parsing Filter log by pfBlockerNG creates IP Block log with Source/Destination mixed up or wrong Direcion
Happy to provide more detail if needed.
Regarding the interfaces, we actually have 4 wan interfaces and all internal...
Djerk Geurts
07:50 AM pfSense Packages Bug #13209: Parsing Filter log by pfBlockerNG creates IP Block log with Source/Destination mixed up or wrong Direcion
Customer created this topic on forum: https://forum.netgate.com/topic/172322/ip_block-log-entry-query-direction Azamat Khakimyanov
07:38 AM pfSense Packages Bug #13209 (New): Parsing Filter log by pfBlockerNG creates IP Block log with Source/Destination mixed up or wrong Direcion
According to our customer he got weird pfBlockeNG log in 'ip_block.log' file.
For example
_May 20 16:23:12,16530438...
Azamat Khakimyanov
11:53 AM Todo #13100 (Feedback): Transition Captive Portal from IPFW to PF
Jim Pingle
11:46 AM Feature #12945 (Feedback): Implement missing ipfw equivalents in libpfctl necessary for captiveportal
Reid Linnemann
09:33 AM Bug #13210 (Resolved): PPPoE server panics with multiple client connections
When using the PPPoE server it's possible to trigger a kernel panic if enough clients attempt to connect. It appears ... Steve Wheeler
07:43 AM Bug #12796: 2.5.2 -> 2.6.0 upgrade segfaults if certain packages are installed.
For what it's worth this isn't a problem specific to pfSense or our repositories. I've seen this in base FreeBSD when... Jim Pingle
07:26 AM Bug #12870: Clicking Save & Force Update on a Dynamic DNS entry results in a GUI timeout
No plans for a point release at this time.
You can install the "System Patches package":https://docs.netgate.com/p...
Jim Pingle
07:16 AM Bug #12870: Clicking Save & Force Update on a Dynamic DNS entry results in a GUI timeout
Jim Pingle wrote in #note-14:
> I can't reproduce this on any of my Namecheap entries on today's snapshot with the f...
Chris Swinney
06:46 AM Regression #13150 (Resolved): Captive Portal not applying per user bandwidths
Viktor Gurov
04:39 AM Regression #13150: Captive Portal not applying per user bandwidths
Upload/download bandwidth restrictions works as expected. Viktor Gurov
04:56 AM pfSense Packages Feature #13207 (New): The feed column on the Alerts page is confusing
When you look at your alerts in the feed column, and per row, there are 2 records present, the current detection and ... Jon Brown

05/23/2022

09:30 PM Revision 91d8c6c9: Revert "Fixes RAM disk handling on ZFS (support boot environments)"
This reverts commit e6b47d6812b1a46738c75a8991cd1393b200d7ef Christian McDonald
09:02 PM Revision e6b47d68: Fixes RAM disk handling on ZFS (support boot environments)
Christian McDonald
08:25 PM Revision db6e63dd: Revert "Fix RAM disk support for ZFS layout changes related to BEs. Fixes #13182"
This reverts commit b9097e4cfe3fcbdec86a00a5a470d93d05ea8102 Christian McDonald
06:36 PM Revision 32661caf: Captive Portal pipes reserve fix. Fixes #13204
Viktor Gurov
06:24 PM Revision 889bec18: Generate floating rules with "any" interface. Fix #13203
Marcos M
05:07 PM Revision b9097e4c: Fix RAM disk support for ZFS layout changes related to BEs. Fixes #13182
Christian McDonald
03:11 PM Regression #12827 (Resolved): High latency and packet loss during a filter reload
As there is no packet loss and the impact is significantly better than the last release we can call this solved for n... Jim Pingle
02:31 PM Regression #12827: High latency and packet loss during a filter reload
Here are some additional results between current and previous versions.... Marcos M
11:37 AM Regression #12827: High latency and packet loss during a filter reload
Steve Wheeler wrote in #note-26:
> Ruleset load times in 22.05 look like:
> [...]
>
> Tested in: 22.05.b.2022052...
Michael Novotny
11:30 AM Regression #12827: High latency and packet loss during a filter reload
Ruleset load times in 22.05 look like:... Steve Wheeler
03:08 PM pfSense Docs New Content #13205 (Feedback): ZFS Boot Environment documentation
Initial commit: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/e972b47a24de9fe822c331ad6b13c48872da2aa5
Sta...
Jim Pingle
02:53 PM pfSense Docs New Content #13205 (Resolved): ZFS Boot Environment documentation
Write documentation for the new ZFS Boot Environment feature.
Mostly done, adding this for tracking.
Jim Pingle
03:02 PM Revision 6b73b812: Do not force setting a gateway with floating match limiter rules. Fix #13027
Marcos M
01:55 PM Revision 533b6c5a: Incompatible OpenVPN P2P option note. Issue #13189
Jim Pingle
01:45 PM Bug #13204 (Feedback): Captive Portal reserves four (instead of two) pipes for client
Applied in changeset commit:32661caf9549d8675763e814c9ceb9c2b47b2f02. Viktor Gurov
01:32 PM Bug #13204 (Pull Request Review): Captive Portal reserves four (instead of two) pipes for client
Jim Pingle
01:28 PM Bug #13204: Captive Portal reserves four (instead of two) pipes for client
fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/798
Viktor Gurov
01:25 PM Bug #13204 (Resolved): Captive Portal reserves four (instead of two) pipes for client
@/var/db/captiveportaldn.rules@ reserves 4 pipes for each client, instead of 2 (in/out) Viktor Gurov
01:40 PM Regression #13203 (Feedback): Floating rules without an interface are not loaded
Applied in changeset commit:889bec18ecd0828e1401abcc1c8c4c8ec73aef81. Marcos M
01:34 PM Regression #13203: Floating rules without an interface are not loaded
Looks good in my test case:... Steve Wheeler
01:25 PM Regression #13203 (Pull Request Review): Floating rules without an interface are not loaded
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/797 Marcos M
01:05 PM Regression #13203 (Resolved): Floating rules without an interface are not loaded
In @22.01@, the following floating rule with no interface can be created:... Marcos M
12:23 PM pfSense Docs Correction #13186 (Resolved): Help link on some pages doesn't lead to documents the user might expect
These are all taken care of now, at least what is possible.
These redirects are handled server side so the fixes a...
Jim Pingle
12:15 PM Regression #13182 (Feedback): Enabling /var as a RAM disks conflicts with ZFS
Applied in changeset commit:b9097e4cfe3fcbdec86a00a5a470d93d05ea8102. Christian McDonald
10:43 AM Bug #13027 (Resolved): Input validation requires a gateway for floating ``match out`` rules
Works as expected. Testing details in MR. Marcos M
10:40 AM Bug #13027 (Feedback): Input validation requires a gateway for floating ``match out`` rules
Applied in changeset commit:6b73b812b884cbc394137b07bab34b9a23bc66f0. Marcos M
10:33 AM Regression #13026 (Resolved): Limiters do not work
Tested on BETA build with connections initiated from inside and outside the firewall. Limiters now work as expected. Marcos M
10:17 AM Bug #12579 (Resolved): Utilize ``dnctl(8)`` to apply limiter changes without a filter reload
No issues with this in testing. Marcos M
10:11 AM pfSense Plus Regression #13183 (Feedback): ZFS module is loaded on systems without ZFS
Fix merged. Try again. Christian McDonald
09:48 AM Feature #12407: Use deferred client connections in OpenVPN
This fix would not affect that issue given it uses a different script. See https://redmine.pfsense.org/issues/12382#n... Marcos M
07:14 AM Feature #12407: Use deferred client connections in OpenVPN
Just as a quick question: should that also help with
https://redmine.pfsense.org/issues/12382
or does that issu...
Jens Groh
09:41 AM Revision 3d1a553e: Captive Portal hostname pipes delete fix. Issue #13193
Viktor Gurov
09:09 AM Regression #13193 (Feedback): Deleting a host entry fails to remove dummynet pipes
Merged:
https://github.com/pfsense/pfsense/commit/3d1a553e7aa1615f6d228325dbaac3901cad3811
Viktor Gurov
07:38 AM Regression #13193 (Pull Request Review): Deleting a host entry fails to remove dummynet pipes
Jim Pingle
04:43 AM Regression #13193: Deleting a host entry fails to remove dummynet pipes
fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/794
Viktor Gurov
09:02 AM pfSense Plus Todo #13189 (Feedback): Input validation should reject the combination of DCO and P2P mode
Base of the note (for CE and Plus that doesn't mention DCO): https://gitlab.netgate.com/pfSense/pfSense/-/commit/533b... Jim Pingle
08:38 AM pfSense Plus Todo #13189 (In Progress): Input validation should reject the combination of DCO and P2P mode
Still needs a note under the IPv4 tunnel network fields about this not being compatible. Jim Pingle
08:26 AM pfSense Plus Todo #13189 (Feedback): Input validation should reject the combination of DCO and P2P mode
Merged: https://gitlab.netgate.com/pfSense/factory/-/commit/16c76f982b7c82d8cc89266e6fe15b3947774085 Jim Pingle
08:58 AM pfSense Packages Bug #13202 (New): Missing Protocols on IP Feed Groups Advanced Inbound/Outbound Firewall Rule settings
While messing around with IP Block list feeds, I found a feed that was very restrictive but it only seemed to block u... Jon Brown
08:47 AM Regression #13191 (Feedback): Deleting a passthru mac entry fails to remove pf rules and dummynet pipes associated with the passthru mac
Reid Linnemann
08:04 AM pfSense Packages Todo #13190 (Feedback): Update System_Patches package for pfSense+ 22.05
Merged. Jim Pingle
12:35 AM pfSense Packages Todo #13190 (Pull Request Review): Update System_Patches package for pfSense+ 22.05
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/240 Marcos M
06:34 AM pfSense Packages Feature #13201 (New): Add FireHol Security IP Feeds
I have found an excellent repository of automatically created IP security feeds that should be added to pfBlockerNG f... Jon Brown
06:16 AM pfSense Packages Feature #13200 (New): Custom DNS Servers for Alert settings
I am running DNS Hijacking so all DNS/DoT/DoH is run through pfSense and then forwarded securley to Quad9 using DoT.
...
Jon Brown
06:05 AM pfSense Packages Feature #13196: remove NoVirusThanks feed
Cannot edit issue, this should be a BUG Jon Brown
05:28 AM pfSense Packages Feature #13196 (New): remove NoVirusThanks feed
NoVirusThanks / NVT_BL / http://www.ipspamlist.com/public_feeds.csv
This is a dead feed, although it is a valid li...
Jon Brown
06:05 AM pfSense Packages Feature #13198: Dark Theme Styling issues - Alerts White bar
Cannot edit issue, this should be a BUG Jon Brown
05:56 AM pfSense Packages Feature #13198 (New): Dark Theme Styling issues - Alerts White bar
When running the Dark Theme there are information bars that are white (not styled properly) that are hard to read unl... Jon Brown
06:03 AM pfSense Packages Feature #13199 (New): Feed groups should not have the first listing in the group bar
Currently when a new group is created with a single or multiple feeds in it, the first row is always grey with the fi... Jon Brown
05:35 AM pfSense Packages Feature #13197 (New): Put a Single donation link and a proper patreon lin in the pfBlocker Support Banner / Widget
On the pfBlockerNG support banner I would like the ability to make a single donation, PayPal maybe.
I think that i...
Jon Brown
05:22 AM pfSense Packages Feature #13195 (New): Dedicated website for Feed mangement - Community Driven
What would be useful is a website where end users could submit new feeds, flag dead ones, and rate current feeds.
...
Jon Brown
05:16 AM pfSense Packages Bug #13194 (New): Remove dead Malc0de feed
the following feeds need removing because they are dead:
* PRI4 / Malc0de / https://malc0de.com/bl/BOOT
the websi...
Jon Brown
04:28 AM Revision 65530037: captiveportal: Only apply per-user default bw to pipes for user auth. Fixes #13192
captiveportal_pipe_configure() was unaware of the context of the pipes it was
creating (user auth vs. allowed mac/ip/...
Reid Linnemann
03:41 AM Revision 43bd2b88: captiveportal: Correct errors in passthru mac deletion. Fixes #13192
Correct identifier mismatches in captiveportal_passthrumac_delete_entry()
($hostent vs $mac)
Correct and rename capt...
Reid Linnemann
12:33 AM Bug #11539: Mobile IPsec ``split_include`` value of ``0.0.0.0/0`` causes some clients to fail
Tested on 22.05 - I couldn't reproduce the original issue using the native (OxygenOS) android 11 IKEv2 MSCHAPv2 client. Marcos M

05/22/2022

11:12 PM Regression #13193 (Resolved): Deleting a host entry fails to remove dummynet pipes
When removing an allowed host, pipes are not cleared that were added for the entry. This may only apply if the hostna... Reid Linnemann
10:55 PM Regression #13192 (Feedback): Default pipe rate limits are applied to allowed mac/ip/host entries
Applied in changeset commit:43bd2b88b7774bba0c54d2f02eb429bfafb8d235. Reid Linnemann
09:58 PM Regression #13192 (Assigned): Default pipe rate limits are applied to allowed mac/ip/host entries
Reid Linnemann
09:56 PM Regression #13192 (Resolved): Default pipe rate limits are applied to allowed mac/ip/host entries
When adding an allowed mac, ip, or host, if the up or down bandwidth are not specified and a default per user bandwid... Reid Linnemann
09:58 PM Regression #13191 (Assigned): Deleting a passthru mac entry fails to remove pf rules and dummynet pipes associated with the passthru mac
Reid Linnemann
06:50 PM Regression #13191 (Resolved): Deleting a passthru mac entry fails to remove pf rules and dummynet pipes associated with the passthru mac
When a passthru mac entry is deleted, the pipes associated with the entry are intended to be removed, followed by the... Reid Linnemann
06:45 PM Bug #13169 (Feedback): captiveportal_ether_delete_entry() does not delete anchors/pipes
passthru mac is a separate issue Reid Linnemann
 

Also available in: Atom