Project

General

Profile

Activity

From 05/27/2022 to 06/25/2022

06/25/2022

07:01 PM pfSense Docs Correction #11223 (Resolved): Azure Marketplace links are invalid
Chris W
07:01 PM pfSense Docs Correction #11223: Azure Marketplace links are invalid
Looks like this was fixed. The corrected links point to https://azuremarketplace.microsoft.com/en-us/marketplace/apps... Chris W
05:47 PM Bug #12544: OpenSSH vulnerabilities
This bug report can be closed. pfSense Plus 22.05 comes with OpenSSH 8.8p1, which is not vulnerable to any of these ... Kris Phillips
05:42 PM Bug #8207: 2.4 cannot boot as a Xen VM with more than 7 NICs
Due to lack of confirmation, this bug report should be rejected unless it can be verified that there is a problem on ... Kris Phillips
05:41 PM Bug #9626: When deny write permission is assigned to a user, there is no error feedback if the user tries to write something
Can confirm this is still an issue in 22.05 of pfSense Plus. There is no visual feedback or an error notification du... Kris Phillips
05:39 PM Bug #7996: Unnecessary link tag in login page
This is still present in pfSense Plus 22.05. Kris Phillips
05:38 PM pfSense Packages Bug #10602 (Resolved): Dashboard->Traffic Graphs bandwidth designations on hover pop-ups
Tested this on pfSense Plus 22.05. Not sure when this was fixed, but this looks to be resolved. Closing out this bu... Kris Phillips
05:34 PM pfSense Plus Bug #11626: Google LDAP connections fail due to lack of SNI for TLS 1.3
Jim Pingle wrote in #note-15:
> Nudge this ahead so we have more time to ensure there aren't any regressions from th...
Kris Phillips
05:30 PM pfSense Plus Feature #12546: Add 2FA Support to pfSense Plus Local Database Authentication
Further expounding on this, it appears that Viscosity has native capability to add prompts in the client config.
...
Kris Phillips
05:03 PM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
Jim Pingle wrote in #note-9:
> Marcos Mendoza wrote in #note-7:
> > I created https://redmine.pfsense.org/issues/13...
Kris Phillips
05:00 PM Bug #13003: Malicious Driver Detection event on ``ixl(4)`` driver
Christoph Vieten wrote in #note-5:
> Kris Phillips wrote in #note-3:
> > Christoph Vieten wrote in #note-2:
> > > ...
Kris Phillips
03:25 PM pfSense Docs Todo #12770: Feedback on Firewall — Configuring firewall rules
Merge request:
https://gitlab.netgate.com/docs/pfSense-docs/-/merge_requests/42
Chris W
10:59 AM pfSense Packages Bug #11572: Auto created firewall rules have IPv4 as protocol only - even for IPv6 lists.
Still an issue in 2.6.0
Why not remove pfblockerNG from Repo if it's no more fixed and maintained anyway? Saves ti...
Beat Siegenthaler
05:41 AM Bug #13301 (Duplicate): Bug #13239 = (?) = #12645 appease not fixed - ipv6 based ipsec vpn tunnel bug found with fqdn remote host
Hi,
I reported the bug earlier : https://redmine.pfsense.org/issues/13239#change-61632
ipv6 based ipsec vpn tun...
Alex Zaykov
05:33 AM Bug #12645: ``filterdns`` does not monitor remote IPsec gateways for IPv6 address changes
tested on the latest built 22.05-RC (amd64) built on Fri Jun 17 06:34:36 UTC 2022
the bug is not fixed, Ipsec tunnel...
Alex Zaykov

06/24/2022

10:10 PM Feature #13296: Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
It's where the bug entries are for FreeBSD ports are, and where a feature request can be submitted. Marcos M
04:16 PM Bug #9471 (Resolved): GIF tunnel not added to interface group after reboot

added GIF,LAN,PPPoE and GRE to the group of interfaces, GIF is added to the interface group after reboot
ifconfi...
Alhusein Zawi
03:09 PM Revision 3222c70a: Omit VIPs from interface address selection. Fixes #11545
Add function get_interface_addresses() which wraps around pfSense_get_ifaddrs() and
filters VIPs before selecting an ...
Reid Linnemann
02:50 PM pfSense Packages Bug #13261 (Feedback): Input validation rejects empty ``sudo`` command list, but GUI text says it can be empty
Merged: https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/commit/a056c1984a174248da0a0f8c541d9441678a2339 Christopher Cope
01:23 PM pfSense Packages Bug #13261 (Pull Request Review): Input validation rejects empty ``sudo`` command list, but GUI text says it can be empty
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/251 Christopher Cope
11:31 AM pfSense Docs Correction #13300 (Resolved): Corrected Silabs driver URL
Jim Pingle
11:20 AM pfSense Docs Correction #13300 (Resolved): Corrected Silabs driver URL
Current link in the Windows tab of the Connecting to the Console Port pages for Netgate firewalls (excluding 1100 and... Chris W
11:21 AM pfSense Packages Bug #13299 (Resolved): Cron package needs basic input validation and output encoding
Tested and working as expected on... Christopher Cope
10:18 AM pfSense Packages Bug #13299 (Feedback): Cron package needs basic input validation and output encoding
Fixed: https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/commit/1a8a2f338592428dd46e543a884b1758b68198c9 Jim Pingle
10:09 AM pfSense Packages Bug #13299 (Resolved): Cron package needs basic input validation and output encoding
The cron package does not validate its inputs nor does it encode its output. This can lead to a potential stored XSS.... Jim Pingle
10:25 AM Regression #11545: Primary interface address is not always used when VIPs are present
I believe I have a fix for this issue. I created a variation on pfSense_get_interface_addresses() named pfSense_get_i... Reid Linnemann
10:15 AM Regression #11545 (Feedback): Primary interface address is not always used when VIPs are present
Applied in changeset commit:3222c70aaf783336901f7b1225727b5973ba865a. Reid Linnemann
07:47 AM Bug #13298: Dynv6 Dynamic DNS client does not check the response code when updating
PR: https://github.com/pfsense/pfsense/pull/4605 Jim Pingle
07:16 AM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
Marcos Mendoza wrote in #note-7:
> I created https://redmine.pfsense.org/issues/13293 for that. Given that @auth-gen...
Jim Pingle

06/23/2022

08:49 PM Revision adfb1d2b: fix: Dynv6 checkIP
Check return of update to release check IP Tiago d'Avila
07:49 PM pfSense Packages Bug #8454: Arpwatch package break email notifications from other sources
Is this still current as of 22.05? I just started playing with Arpwatch. What exactly does the "Disable Cron emails" ... → luckman212
04:01 PM Bug #13298: Dynv6 Dynamic DNS client does not check the response code when updating
*Testing*
Tested with https://dynv6.com
Tiago Beling d'Avila
03:58 PM Bug #13298 (Resolved): Dynv6 Dynamic DNS client does not check the response code when updating
Check return of update to release check IP Tiago Beling d'Avila
12:04 PM Feature #13297 (New): Support for Gateway Groups as Static Route destinations
It could be interesting to have the possibility to use a group of gateways with static routes in a failover scenario.... Vincent D.
07:06 AM Regression #11316: Unbound crashes with signal 11 when reloading
Why is this closed ??
All was ok for my pfsense until a power outage.
I have pfsense 2.6 up to date and it has been...
mururoa mururoa
01:31 AM Bug #13003: Malicious Driver Detection event on ``ixl(4)`` driver
Kris Phillips wrote in #note-3:
> Christoph Vieten wrote in #note-2:
> > Same happened on 2.6.0 with Intel x710-T4 ...
Christoph Vieten

06/22/2022

09:31 PM Feature #13296: Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
@mmendoza was that last link you posted supposed to show something related? for me it just appears to be a list of ev... → luckman212
05:54 PM Feature #13296: Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
It's http://wide-dhcpv6.sourceforge.net/
See:
https://github.com/pfsense/FreeBSD-ports/tree/devel/net/dhcp6
http...
Marcos M
04:47 PM Feature #13296: Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
I'm still hazy on exactly which dhcp6c implementation is currently shipping. I _thought_ it was the "hrs-allbsd/wide-... → luckman212
04:01 PM Feature #13296 (New): Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
Some ISPs are rolling out IPv6 and not directly providing a globally routable WAN address via DHCPv6. Instead, they a... Anonymous
09:04 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
hello guys
Configurator (Scope):
Interfaces: WAN-DHCP4|WAN2-DHCP4
Gateway Group: Failover (WAN_DHCP Gateway: 192...
Alefe Ortiz
06:06 PM Feature #13294: Change gateway name
There's no functionality to rename the gateway/group and update all of the places where it could be used. That could ... Marcos M
10:27 AM Feature #13294 (New): Change gateway name
After clicking on a gateway on system_gateways_edit.php, which takes the user to e.g., system_gateways_edit.php?id=0,... Kay Avila
05:19 PM Revision d55e0d4b: fix func params for get_dpinger_status() call in gwlb.inc
→ luckman212
04:15 PM Revision 7e9a12e9: Centralize the branches into builder_defaults.sh to simplify and eliminate overwriting the variables
Brad Davis
12:26 PM Bug #13295 (Resolved): Incorrect function parameters for ``get_dpinger_status()`` call in ``gwlb.inc``
There seems to be an error in @gwlb.inc@ around line 479. The call to @get_dpinger_status()@ has the @$action_disable... → luckman212
02:12 AM Revision 5ecee3d7: scrubing -> scrubbing
→ luckman212

06/21/2022

03:47 PM Revision 098cdb61: Add version config for use by pfSense-repo
Brad Davis
02:37 PM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
I created https://redmine.pfsense.org/issues/13293 for that. Given that @auth-gen-token@ handles the issue with frequ... Marcos M
02:35 PM Feature #13293 (New): Option to set auth-gen-token in OpenVPN GUI
This option is useful to avoid having to frequently manually re-authenticate when using MFA.
> --auth-gen-token [lif...
Marcos M
12:06 PM pfSense Packages Feature #13292 (New): Separator
It'd be really nice if there was a way to add a separator to the certificates list in the ACME package. Nothing fanc... Marc Mapplebeck
10:22 AM pfSense Docs Todo #13291 (Duplicate): Notification documentation
I know there is documentation here on how to setup notification
https://docs.netgate.com/pfsense/en/latest/config/...
Meme meme
01:00 AM Bug #13210: PPPoE server panics with multiple client connections
Sorry, wanted to add it here for documentation purpose but forgot to make it yesterday:... Jens Groh

06/20/2022

06:01 PM Regression #13290 (Feedback): Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters
There's not enough info here to troubleshoot this. Discussion of the issue may be continued on the forums: https://fo... Marcos M
02:25 PM Regression #13290 (Resolved): Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters
After upgrading from 2.6.0 to 2.7.0, my Captives Portal users are dropped randomly, having to re-authenticate... Ther... Rafael Ferreira
04:20 PM Bug #13210 (Resolved): PPPoE server panics with multiple client connections
Customer which was previously frequently hitting this issue reports it's been resolved after updating to the RC. Marcos M
04:04 PM Bug #10352: RADIUS authentication fails with MSCHAPv1 or MSCHAPv2 when passwords contain international characters
The issue is still present on 22.01-RELEASE
Any foreseen planning to fix this issue ?
Is someone working on it ? ma...
Patrick Vander Linden
01:03 PM Feature #13286: webConfigurator does not redirect to requested page after login
I understand.
To be honest, one of my main reasons for wanting this merged was because my dashboard takes so darn l...
→ luckman212
12:52 PM Feature #13286: webConfigurator does not redirect to requested page after login
Some pages require parameters to load the right view, so stripping the parameters isn't helpful.
It is not going t...
Jim Pingle
10:18 AM Feature #13286: webConfigurator does not redirect to requested page after login
But, again- nothing prevents a logged in user from bookmarking a page or recalling one from history that actions some... → luckman212
10:15 AM Feature #13286: webConfigurator does not redirect to requested page after login
Doesn't have to be an attack, they could also do it unintentionally by bookmarking or hitting a page from their histo... Jim Pingle
10:07 AM Feature #13286: webConfigurator does not redirect to requested page after login
Not sure I follow how this makes it any less secure than it already is. If a user is logged in already, they can stil... → luckman212
08:49 AM Feature #13286 (Rejected): webConfigurator does not redirect to requested page after login
This is done on purpose for security reasons. Until the entire GUI is purged of any page that takes action on GET, th... Jim Pingle
08:34 AM Feature #13286: webConfigurator does not redirect to requested page after login
PR: https://github.com/pfsense/pfsense/pull/4599 → luckman212
08:33 AM Feature #13286 (Rejected): webConfigurator does not redirect to requested page after login
Something that has bugged me for a while now is that if you are logged out of pfSense, and request a "deep" page e.g.... → luckman212
10:46 AM Bug #13289 (Resolved): Attempting to restore a 0 byte ``config.xml`` prints an error that the file cannot be read
When attempting to restore an empty config.xml file (0 bytes) the GUI prints an error saying the file cannot be read ... Jim Pingle
10:36 AM Bug #13288 (New): Encode FreeRADIUS Custom Options
Currently, fields in the FreeRADIUS package such as @varusersreplyitemsadditionaloptions@ are not encoded in config.x... Marcos M
10:33 AM Feature #13287 (New): Encode OpenVPN Custom Options
The @custom_options@ field for OpenVPN configurations is currently not encoded. This should be encoded in base64. Marcos M
07:46 AM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
Both @auth-gen-token@ and @reneg-sec@ are useful in different ways, we should expose and (optionally) use both. Thoug... Jim Pingle
07:21 AM Bug #13285: Uncaught ArgumentCountError to function openvpn_kill_client()
Okay, thank you Jim for test and quick feedback. DRago_Angel [InV@DER]
07:20 AM Bug #13285 (Duplicate): Uncaught ArgumentCountError to function openvpn_kill_client()
There are no errors when terminating clients on the status page or widget on 22.05/2.7.0 snapshots. Jim Pingle
07:11 AM Bug #13285: Uncaught ArgumentCountError to function openvpn_kill_client()
Sorry, found https://redmine.pfsense.org/issues/12817 but it not mention status page, not sure 12817 also resolve Ope... DRago_Angel [InV@DER]
07:09 AM Bug #13285 (Duplicate): Uncaught ArgumentCountError to function openvpn_kill_client()
Killing session for user using OpenVPN Dashboard Widget or using OpenVPN Status page do not works.
On Widget next er...
DRago_Angel [InV@DER]

06/19/2022

11:11 PM Bug #5413: Reduce disruptions when changing DNS records from DHCP leases in Unbound
Hey Netgate - I get the feeling this affects far more customers than you think.
Can this be assigned to someone to a...
O E
09:34 PM Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes
Just updated "PR #4595":https://github.com/pfsense/pfsense/pull/4595 with the new mitigation changes. Testers & feedb... → luckman212
12:20 PM Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes
It appears we are out of luck on having @devd@ fire events for IP address changes. There is a commit: https://reviews... → luckman212
06:42 PM pfSense Plus Bug #13283 (Not a Bug): PBR forcing traffic out one WAN and back into another WAN with NAT Reflection Fails
Tested this.
With that PBR in place, even traffic that is being NAT'ed from the NAT Reflection rule will be caught...
Marcos M
05:53 PM Bug #13243 (Pull Request Review): OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
Marcos M
02:18 PM Bug #13243: OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
This fixes the original issue:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/821
Reiner Keller wr...
Marcos M
05:52 PM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
It's better to implement @--auth-gen-token [lifetime]@
> --auth-gen-token [lifetime]
> After successful user/passwo...
Marcos M
05:38 PM Feature #12982: Add support for RFC7499 in RADIUS library.
So are you saying that pfsense/freeRadius will not be able to go more then 68 rules? any software you know would be ... Frank Lee
03:58 PM Feature #12982: Add support for RFC7499 in RADIUS library.
I was able to replicate this with a simpler setup by adding a custom option to the @Additional RADIUS Attributes (REP... Marcos M
12:10 PM pfSense Packages Feature #13284 (New): Option to define "Issuer" in OPT configuration.
All QR codes are presently identifying as "FreeRADIUS(username).
Please add an optional variable in user->One-Time...
Jakob Nordgarden
11:11 AM Bug #13280: Entries for ``net.link.ifqmaxlen`` duplicated in ``/boot/loader.conf``
I'm seeing this as well on a VM with @22.05.r.20220609.1919@.... Marcos M

06/18/2022

05:48 PM pfSense Plus Bug #13283 (Not a Bug): PBR forcing traffic out one WAN and back into another WAN with NAT Reflection Fails
Assuming the following configuration:
2 WAN interfaces WAN1 and WAN2
One LAN interface with Host A and Host B.
H...
Kris Phillips
02:34 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
It seems this issue has gotten worse somewhere along the line similar to how others are describing it. Tables now lo... Kris Phillips
02:25 PM Bug #13282 (Resolved): Alias content is sometimes incomplete if the firewall cannot resolve an FQDN in the alias
If an invalid FQDN is present in an alias before a valid one, the entire table will be empty.
For an example, if...
Kris Phillips

06/17/2022

07:24 PM Bug #13281 (Duplicate): Crash Reporter
Duplicate, and already fixed: #12817 Jim Pingle
06:49 PM Bug #13281 (Duplicate): Crash Reporter
Crash report begins. Anonymous machine information:
amd64
12.3-STABLE
FreeBSD 12.3-STABLE plus-RELENG_22_01-n20...
Ilan Birman
04:10 PM Revision 3f4ee315: Template the versions as well
Brad Davis
03:31 PM Bug #13280 (Resolved): Entries for ``net.link.ifqmaxlen`` duplicated in ``/boot/loader.conf``

Using 22.05-RC 22.05.r.20220617.0613 Duplicate entries appear in /boot/loader.conf
Here are the contents of my loa...
Keith Townsend
08:36 AM Bug #13243: OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
Additional to this "informal" bug the ruleset given by Radius parameter isn't stored and when the renegiotion is done... Reiner Keller
07:34 AM Bug #13278 (Needs Patch): OpenVPN dynamic gateway created incorrectly when not pulling routes or server pushes no routes
We're aware of this, but it's an OpenVPN bug, not a bug in our code. As you see, the variables are unpopulated even w... Jim Pingle
01:10 AM Bug #13278: OpenVPN dynamic gateway created incorrectly when not pulling routes or server pushes no routes
This appears to be happening because OpenVPN doesn't populate these environment variables when either option is selec... Adrien Carlyle
07:09 AM Bug #13279 (New): DHCP config override affects Gateway installation.
If you check Configuration Override on the interface in the DHCP Client Configuration section, then open Status => In... Lev Prokofev
07:02 AM Regression #13274 (Resolved): OpenVPN override IPv4 tunnel network field changing value improperly
Working as expected on the latest build. The exact tunnel network address and mask remain, and the resulting @ifconfi... Jim Pingle

06/16/2022

11:54 PM Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes
@dem I believe I'm facing this exact issue, take a look at https://forum.netgate.com/topic/172849/rtsold-not-running-... → luckman212
10:31 PM Bug #13278 (Needs Patch): OpenVPN dynamic gateway created incorrectly when not pulling routes or server pushes no routes
IF: I configure OpenVPN client and set the "Don't pull routes" check box
OR
IF: I include the advanced option: pull...
Adrien Carlyle
09:30 PM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
+1 Also having this problem : 2.6.0-RELEASE (amd64) Emmanuel Rosado
07:50 PM Bug #13277 (Duplicate): IGMP Proxy webConfigurator Page Always Produces Error
Whether your IGMP Proxy settings are correct or not, there is always an error stating "There was a problem applying t... Kris Phillips
07:48 PM Bug #13276 (New): IGMP Proxy Error Message for Logging Links to System Log Instead of Routing Log
If you try to apply a setting that won't apply in IGMP Proxy, it will state "There was a problem applying the changes... Kris Phillips

06/15/2022

03:16 PM Revision 230b2303: Fix OpenVPN override TN handling. Fixes #13274
Jim Pingle
10:42 AM pfSense Docs New Content #13211: OpenVPN DCO Documentation
Updates: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/989cfa8946010d913fddeebc8d8fe740ba409390 Jim Pingle
10:25 AM Regression #13274 (Feedback): OpenVPN override IPv4 tunnel network field changing value improperly
Applied in changeset commit:230b23033a898633681ef0dde4df8f63a2b7258c. Jim Pingle
10:13 AM Regression #13274 (Resolved): OpenVPN override IPv4 tunnel network field changing value improperly
For an override on a subnet topology VPN, the mask on the tunnel network in the override has to reflect the subnet ma... Jim Pingle
03:44 AM Bug #11629: PPPoE WAN IP address different than expected when set static by ISP
We've installed 22.05 on our Netgate 2100 appliance and it's still assigning the wrong IP address to the WAN interfac... Dan Rice

06/14/2022

01:14 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
That one change looks to have solved the issue for me.
Testing in:...
Steve Wheeler
01:04 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
Well... seeing that would have saved me a bunch of debugging... Denny Page
12:41 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
For reference, the redmine for that issue is here:
https://redmine.pfsense.org/issues/13156
Marcos M
12:19 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
The issue apparently stems from the output of "pfctl -vvsr" changing in 22.05. Due to the change in output, pfBlockNG... Denny Page
11:07 AM Bug #13273 (New): dhclient can use conflicting recorded leases
dhclient will attempt to use a previously successful recorded lease if it cannot contact a dhcp server.
However it w...
Steve Wheeler
08:00 AM pfSense Packages Bug #13180: High CPU Utilization with pfb_filter since pfBlockerNG update to devel 3.1.0_4
Looks like a duplicate or related to #13154 Michael Novotny
06:53 AM Regression #13265 (Resolved): Authentication using Voucher cause SQLite3 syntax error
No errors on the latest snapshot. Voucher is accepted, no PHP error, voucher shows in active users and active voucher... Jim Pingle

06/13/2022

08:16 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
Even with changing the rule to use the pfBlockerNG aliases directly, the issue persists - that is I'm not seeing any ... Marcos M
06:16 PM pfSense Packages Bug #13154 (Confirmed): pfBlocker causing excessive CPU load
Still seeing this in 2.7/22.05 so it seems unlikely to be a symptom of #12827 which is mostly fixed there.
The CPU...
Steve Wheeler
02:04 PM Revision 8ba70cfc: Set CP pipeno consistently when null. Fixes #13265
Jim Pingle
11:29 AM Feature #12982: Add support for RFC7499 in RADIUS library.
Ok, so do you know roughly when "someone" can look at this issue further? Frank Lee
10:37 AM Feature #12982: Add support for RFC7499 in RADIUS library.
I can't find where @[ciscoavpair]@ is being set in the code - the only reference I could find was in @pear-Auth_RADIU... Marcos M
11:11 AM Bug #13262 (Resolved): File browser on ``diag_edit.php`` does not encode filenames before display
Tested on... Christopher Cope
10:27 AM Bug #13272 (Pull Request Review): Voucher CSV output has leading space before voucher code
MR: https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/818
Diff attached for wider testing.
Jim Pingle
10:14 AM Bug #13272 (Resolved): Voucher CSV output has leading space before voucher code
When downloading a CSV file for a voucher roll, each voucher has a leading space, so when copying and pasting it gets... Jim Pingle
09:33 AM Regression #13265: Authentication using Voucher cause SQLite3 syntax error
Merged into Plus and CE master branches and picked back into 22.05. Jim Pingle
09:10 AM Regression #13265 (Feedback): Authentication using Voucher cause SQLite3 syntax error
Applied in changeset commit:8ba70cfcf6c86db2c52577bf543a6b72fc2da9e7. Jim Pingle
08:11 AM Regression #13265 (In Progress): Authentication using Voucher cause SQLite3 syntax error
It should be noted that the authentication succeeds and the user can get out, is listed on the active vouchers tab, b... Jim Pingle
08:23 AM pfSense Packages Bug #12992 (Resolved): error: nbproc is not supported any more since HAProxy 2.5
Jim Pingle
08:17 AM pfSense Docs New Content #13270: OpenVPN client gateway is incorrect when the server does not push routes
This has always been the case with OpenVPN. It doesn't populate the environment variables because it doesn't think it... Jim Pingle
05:06 AM pfSense Packages Bug #13271 (Bogus): I got 'The WireGuard service is not running.' after I upgraded my pfSense VM from 22.05.r.20220604.1403 -> 22.05.r.20220609.1919
I've got this issue on one of my pfSense VM after upgrade from 22.05.r.20220604.1403 -> 22.05.r.20220609.1919 ('upgra... Azamat Khakimyanov

06/12/2022

10:32 PM Todo #13268: Dynamically adjust the interface name maximum width in the login banner
I wanted to auto size the columns based on the terminal width, but the shell doesn't seem to export the @$COLUMNS@ va... → luckman212
05:09 PM Todo #13268 (Resolved): Dynamically adjust the interface name maximum width in the login banner
small change to add some width and better align things if interface names are longer than just "WAN", "WAN2" etc.
...
→ luckman212
07:14 PM pfSense Docs New Content #13270 (Resolved): OpenVPN client gateway is incorrect when the server does not push routes
If @IPv4 Local network(s)@ is empty on the server (and no custom options exist to push routes), the client @ovpn-link... Marcos M
02:48 PM Bug #13267 (New): dpinger continues to run on OpenVPN gateway after OpenVPN service is stopped.
Tested on @22.05.r.20220609.1919@.
# Configure OpenVPN client on pfSense
# Assign an interface to the OpenVPN cli...
Marcos M
01:44 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
* removed @case 111)@
* consistency of single/double quotes
* removed a couple of stray @;@ s
→ luckman212
01:21 PM Bug #12920: Gateway behavior differs when the gateway does not exist in the configuration
Updating OP with new symptoms. Marcos M
01:00 PM Revision f185e661: a few updates for the console menu
add full pathnames to all binaries (before some were and some weren't)
less forking for process checking, instead of ...
→ luckman212
11:22 AM Feature #12973: Playback script to perform a configuration upgrade on an arbitrary ``config.xml`` file
Just noting for anyone looking, the script is named @upgradeconfig@ not @updateconfig@ as in Chris' OP. → luckman212
11:14 AM pfSense Plus Bug #13074: AES-GCM with SafeXcel on Netgate 2100 causes MBUF overload
I believe I have hit this as well, 2100 to 7100 GCM tunnel. Is there an upstream FreeBSD bugreport? I believe the fac... → luckman212
11:11 AM Bug #13252: reduce frequency of php-fpm socket connection attempts from check_reload_status
I may have also experienced this on an SG-2100 yesterday. Upgraded from 21.05.1 to 22.05-RC.
After the upgrade, CP...
→ luckman212
08:45 AM pfSense Packages Bug #12992: error: nbproc is not supported any more since HAProxy 2.5
This should be closed since it's been merged → luckman212
12:04 AM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
Pushed more updates to my "PR #4595":https://github.com/pfsense/pfsense/pull/4595 (see over there for details).
I...
→ luckman212

06/11/2022

07:01 PM pfSense Plus Bug #13206: SG-3100 LED GPIO hangs
Daniel Subert wrote in #note-2:
> Hi Jim,
>
> Thanks for the update.
>
> As this issue is already being tracked int...
Kris Phillips
06:45 PM Revision 08e9bcfd: add waning infobox if duplicate IP is entered in DHCP staticmaps
→ luckman212
05:43 PM Regression #13265: Authentication using Voucher cause SQLite3 syntax error
Here is the crash report from my firewall:
Crash report begins. Anonymous machine information:
amd64
12.3-STA...
Kris Phillips
05:41 PM Regression #13265: Authentication using Voucher cause SQLite3 syntax error
I can confirm this issue is present in the RC3 build of 22.05. Kris Phillips
05:08 AM Regression #13265 (Resolved): Authentication using Voucher cause SQLite3 syntax error
Errors:
Crash report begins. Anonymous machine information:
amd64
12.3-STABLE
FreeBSD 12.3-STABLE plus-RELEN...
Lev Prokofev
05:43 PM Revision b707f4d8: fix log spew when deleting static DHCP maps not in arp table, redmine #13263
→ luckman212
04:51 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
Looks good to me. Marcos M
01:50 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
I pushed a revised version, looks like this now
!clipboard-202206111450-srubn.png!
→ luckman212
02:17 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
BBcan177 . wrote in #note-3:
> There seems to have been a change in the pfctl -vvsr output.
>
> The patch below seem...
B. B.
09:11 AM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
Is there a particular reason for that? I'm using a custom alias to keep rule management easier, and to avoid filter l... Marcos M
09:02 AM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
Marcos Mendoza wrote in #note-7:
> > @256 block drop in log quick on ixv5 inet from any to <h_blocklist:19320> label...
BBcan177 .

06/10/2022

10:47 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
> @256 block drop in log quick on ixv5 inet from any to <h_blocklist:19320> label "USER_RULE: pfb_blocklist" label "i... Marcos M
07:49 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
Marcos Mendoza wrote in #note-4:
> Tested change on @22.05@ RC with pfBlockerNG-devel @3.1.0_4@; floating block rule...
BBcan177 .
04:29 PM Feature #13264 (New): IPSec Phase2 select multiple PFS key groups
A user can currently select multiple IPSec encryption and hash algorithms, so it would make sense to add the ability ... Lars Pedersen
12:56 PM Revision 1b5919c7: Encode filename browser.php. Fixes #13262
Jim Pingle
11:36 AM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
I've been running with the PR above for 2 days now, it's survived multiple reboots, and unplug/replug of the secondar... → luckman212
11:18 AM Todo #13263: Reduce log spam when deleting a static DHCP entry
I made and tested this small patch: https://github.com/pfsense/pfsense/pull/4597 → luckman212
10:55 AM Todo #13263 (Resolved): Reduce log spam when deleting a static DHCP entry
This is not a huge priority, but when deleting static DHCP mappings for devices that are offline / not on network and... → luckman212
10:18 AM Bug #13258 (Pull Request Review): Hidden menu option ``100`` incorrectly handles HTTPS detection
Jim Pingle
08:05 AM Bug #13262 (Feedback): File browser on ``diag_edit.php`` does not encode filenames before display
Applied in changeset commit:1b5919c769ba736b44819f71ee1ddce06e2a50c5. Jim Pingle
07:56 AM Bug #13262 (Resolved): File browser on ``diag_edit.php`` does not encode filenames before display
The file browser on @diag_edit.php@ does not encode filenames before display.
A user who can create files with arb...
Jim Pingle
03:39 AM pfSense Packages Bug #13261 (Resolved): Input validation rejects empty ``sudo`` command list, but GUI text says it can be empty
The help text says, " By default the command is "ALL" meaning the user can run any commands. Leaving the commands fi... Danilo Zrenjanin

06/09/2022

11:20 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
The patch works for me on LAN and WAN rules on 22.05 RC using pfBlockerNG-devel 3.1.0_4. I don't have floating rules ... Glenn Hall
11:08 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
Tested change on @22.05@ RC with pfBlockerNG-devel @3.1.0_4@; floating block rule on tagged traffic with description ... Marcos M
09:58 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
There seems to have been a change in the pfctl -vvsr output.
The patch below seems to fix the issue, but would be ...
BBcan177 .
02:51 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
Ok I updated the PR to bring back the hidden option 100 / links browser. I think this is good. Unfortunately when I t... → luckman212
01:31 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
I haven't used @links@ against in the GUI in quite some time so I'm not sure if it still works. If it does we may as ... Jim Pingle
01:28 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
PR: https://github.com/pfsense/pfsense/pull/4596 → luckman212
11:44 AM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
I can't think of any benefit from fixing it; better to remove it. Marcos M
02:07 PM Feature #10446: VIP address is not shown in firewall rules
Marcos Mendoza wrote in #note-5:
> Better to stick with using aliases. VIPs are more for service bindings.
This wil...
Silmor Senedlen
11:38 AM Feature #10446: VIP address is not shown in firewall rules
Silmor Senedlen wrote in #note-4:
> Silmor Senedlen wrote in #note-2:
> > I think it would be nice to be able to ...
Marcos M
02:04 PM Feature #13260 (New): Add support for OpenVPN static-challenge
When using Multi Factor authentication most OpenVPN clients offer a static-challenge option to make the client ask fo... Diego Cortassa
01:32 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
I wanted to make the warning display in a "Yellow Box" too but I looked through the code and couldn't see an easy way... → luckman212
12:41 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
I don't think we should change the default behavior/add extra steps to reach the current behavior.
Something that ...
Jim Pingle
12:36 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
Thank you for the contributions!
In general, it's best to avoid first/second person perspective. A yellowish warni...
Marcos M
07:07 AM Regression #11570 (Pull Request Review): Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
Jim Pingle
01:42 AM pfSense Packages Bug #12765 (Resolved): AutoConfigBackup should ignore Lightsquid/lightparser cron changes
I tested with Lightsquid version 3.0.6_9.
It works fine.
I am marking this ticket resolved.
Danilo Zrenjanin

06/08/2022

11:17 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
I submitted a PR: https://github.com/pfsense/pfsense/pull/4595 that may help some of the cases being hit here. → luckman212
05:02 PM pfSense Packages Bug #13259 (Not a Bug): Reply-to rules are not created with wireguard 0.1.6_1
Jim Pingle
04:57 PM pfSense Packages Bug #13259: Reply-to rules are not created with wireguard 0.1.6_1
Sorry, stupid mistake on my side, it is required to set an upstream gateway on the interface config in order for the ... JB Fuzier
04:53 PM pfSense Packages Bug #13259 (Not a Bug): Reply-to rules are not created with wireguard 0.1.6_1
Hello,
I have noticed that reply-to rules are not created for rules in a wireguard interface even if it is assigne...
JB Fuzier
03:33 PM Feature #10446: VIP address is not shown in firewall rules
Silmor Senedlen wrote in #note-2:
> I think it would be nice to be able to select VIP address from list(which autom...
Silmor Senedlen
01:35 PM pfSense Packages Bug #12808 (Resolved): Wireguard Gateways disabled when Wireguard Service is Manually Restarted
Christian McDonald
10:02 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
Cherry picked this commit to RELENG_2_6_0 ports tree. Look for a package update.
Edit: v0.1.6_2 is available in CE 2...
Christian McDonald
09:31 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
→ luckman212 wrote in #note-13:
> @Valmor if you add the System Patches package and then add a patch using this url:...
Val Mor
07:54 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
@Valmor if you add the System Patches package and then add a patch using this url:
https://github.com/theonemcdona...
→ luckman212
07:46 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
I have similar issue on pfSense 2.6.0-RELEASE.
Configured WireGuard tunnel and set a static route.
After reboot of ...
Val Mor
12:40 PM pfSense Packages Bug #13050 (Resolved): ACME update EasyDNS inline api sign-up link
It looks fine on Acme package version 0.7.1_1.
I am marking this ticket resolved.
Danilo Zrenjanin
12:04 PM Bug #13258 (Resolved): Hidden menu option ``100`` incorrectly handles HTTPS detection
I was poking around in @/etc/rc.initial@ to try to fix something else and I noticed a hidden menu item 100
This op...
→ luckman212
10:38 AM Bug #13257: Exporting a PKCS#12 file from the certificate manager does not use the intended encryption algorithm
See also: #13255 Jim Pingle
10:35 AM Bug #13257 (Resolved): Exporting a PKCS#12 file from the certificate manager does not use the intended encryption algorithm
In source:src/usr/local/www/system_certmanager.php#L198 or thereabouts it sets a parameter @encrypt_key_cipher@ inten... Jim Pingle
09:54 AM Feature #13256 (Resolved): Better handling of duplicate IP addresses in static DHCP assignments
summary:
In 2018 code that prevented duplicate IPs from being used as static DHCP mappings was removed. There are ...
→ luckman212
09:15 AM Bug #13088: Rapidly clicking certain options on OpenVPN Client Overrides can cause hide/show field behavior to invert
I replicated the issue with inverted results when repeating clicks too quickly on 22.05.r.20220604.1403.
After app...
Danilo Zrenjanin
08:52 AM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
I reproduced the issue on 22.01 and 22.05.r.20220604.1403 with the same logs. Danilo Zrenjanin
08:36 AM pfSense Packages Todo #13255 (Resolved): Set PKCS#12 algorithm when exporting OpenVPN ZIP or Windows bundles
Currently when crafting a PKCS#12 archive the OpenVPN Client Export package does not set a specific encryption algori... Jim Pingle
07:48 AM Bug #13254 (Resolved): DNS resolver does not update its configuration or reload during link down events
How to reproduce:
1) Configure the interface with Static IPv4
2) Select this interface in the "Network Interfaces...
Danilo Zrenjanin

06/07/2022

08:55 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
Tested on 22.05 RC.
I was not able to replicate this initially with WAN1 as DHCP and WAN2 as static. After testing a...
Marcos M
10:00 AM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
I experienced this this morning, on 22.05.b.20220531.0600
- dpinger showed my DHCP6 gateway as "down"
- I ran @pgre...
→ luckman212
01:04 PM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
+1 Having this issue since 16th May on two separate boxes CE. Upgraded to 2.6 and still the same. switch to DynDns an... r a
08:50 AM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
+1 Also having this problem David Grenier
12:25 AM pfSense Packages Bug #10436: softflowd no longer sends flow data after upgrade (v0.9.9_1 -> v1.0.0)
I'm starting down a path that involves softflowd. Does anyone know if this issue persists with the latest snaps? → luckman212

06/06/2022

11:17 PM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
any updates on this? I am getting the same error too Pan Teparak
06:55 PM pfSense Packages Feature #12963: Run nmap scans in the background
I can't think of a privacy issue for either - both locations are readable by everyone. The Packet Capture page is in ... Marcos M
02:55 PM pfSense Packages Feature #12963: Run nmap scans in the background
Marcos Mendoza wrote in #note-24:
> Looks good from the testing I've done. Only suggestion I have is that the result...
Phil Wardt
02:58 PM Bug #13253 (Resolved): ``dhcp6c`` is not restarted when applying settings when multiple WANs are configured for DHCP6
After #6880 it seems that when applying settings on multiple WANs, @dhcp6c@ is not restarted so the new configuration... Jim Pingle
02:55 PM Bug #13061 (Resolved): Gateway events for IPv6 affect IPv4 OpenVPN instances and vice versa
Seems to be doing the right thing. IPv6 OpenVPN tunnel kept going when the IPv4 gateway went down and back up. We can... Jim Pingle
02:35 PM Bug #12733 (Resolved): Value of ``net.inet.ip.dummynet.*`` OIDs in ``sysctl`` are ignored
The code for @dummynet_load_module()@ in source:src/etc/inc/util.inc#L3937 ensures the module is loaded before popula... Jim Pingle
01:06 PM Bug #13252 (New): reduce frequency of php-fpm socket connection attempts from check_reload_status
When troubleshooting an issue, I discovered that my system logs were rotating every couple of minutes, due to many of... Royce Williams
12:45 PM Bug #13251: pfTop bugs - backspace key vs CTRL_H, states column, rnr not functional
Ok, fair enough but I do wonder - does backspace work for _anyone_ in this case? Because it appears undefined or at l... → luckman212
12:37 PM Bug #13251 (Not a Bug): pfTop bugs - backspace key vs CTRL_H, states column, rnr not functional
backspace vs ^H is almost always a terminal issue with your client and what it sends. Some things send ^H for backspa... Jim Pingle
12:32 PM Bug #13251 (Not a Bug): pfTop bugs - backspace key vs CTRL_H, states column, rnr not functional
I am not 100% sure but I believe there are bugs in the currently bundled version of pfTop. I opened a thread about th... → luckman212
07:32 AM Todo #13250 (Resolved): Clean up DHCP Server option language
Several options on the page have awkward or inconsistent wording
* "Denied clients will be ignored rather than rej...
Jim Pingle
07:03 AM Bug #12878 (Incomplete): Traffic shaping by interface, route queue bandwidth inbound, out by a large factor.
Jim Pingle
07:02 AM Bug #13249: Running playback comands multiple times results in PHP error
That is known and expected, they aren't designed to run more than once in the same session the way you are doing it. ... Jim Pingle
05:41 AM Bug #12645: ``filterdns`` does not monitor remote IPsec gateways for IPv6 address changes
It's under IKE Endpoint Configuration ----> Remote Gateway (IPV6), to check if FQDN for AAAA record can be used to es... Alex Zaykov
04:17 AM Bug #12645 (Resolved): ``filterdns`` does not monitor remote IPsec gateways for IPv6 address changes
Tested on 22.05-RC (built on Sat Jun 04 14:22:59 UTC 2022)
I'm not sure what to test here but there is no *add_hos...
Azamat Khakimyanov

06/05/2022

08:10 PM Bug #13249 (New): Running playback comands multiple times results in PHP error
Using the console, enter option 12 then run @playback svc restart unbound@ twice. On the second run, the following is... Marcos M
07:38 PM Regression #13248 (New): IPv6 Router Advertisements runs when config.xml does not contain an entry for the interface
After installing @22.05.b.20220531.0600@, I noticed that the @System / Routing@ logs showed the following:
* @2001...
Marcos M
07:09 PM pfSense Packages Bug #13247 (Confirmed): Open-VM-Tools service actions do not work
Installing the package @Open-VM-Tools@ creates two entries under @Status / Services@: @vmware-guestid@ and @vmware-km... Marcos M
06:51 PM pfSense Packages Feature #13246 (New): iperf3 service controls do not work
After installing the @iperf3@ package, an entry is created under @Status / Services@ which includes @Start@, @Stop@, ... Marcos M
06:17 PM pfSense Packages Feature #12963: Run nmap scans in the background
Looks good from the testing I've done. Only suggestion I have is that the results file may be best placed in @/tmp@. Marcos M
04:10 PM pfSense Plus Bug #12974: Typing anything into 1100/2100 recovery installer causes process to stop
Marcos Mendoza wrote in #note-6:
> The wording has been addressed with NG 7431. This issue can be left open to track...
Ryan Coleman
08:23 AM Regression #12821 (Confirmed): Intel e1000 driver (``em``, ``igb``) cannot pass packets tagged with VLAN ``0``
Steve Wheeler

06/04/2022

08:15 PM Regression #12821: Intel e1000 driver (``em``, ``igb``) cannot pass packets tagged with VLAN ``0``
Tested ix interfaces as well. They are not subject to this bug. Based on the fact that Broadcom NICs and Intel ix/i... Kris Phillips
07:54 PM Regression #11545: Primary interface address is not always used when VIPs are present
This bug definitely doesn't just happen with PPPoE interfaces. It is also not consistent and seems to be an "orderin... Kris Phillips
07:50 PM Bug #12878: Traffic shaping by interface, route queue bandwidth inbound, out by a large factor.
Unless further feedback is provided on this redmine, it can likely be closed due to lack of information in Rejected s... Kris Phillips
09:21 AM Feature #13245 (Resolved): Type column on Alias lists
Small QoL addition that adds a Type column to the Alias list views. I was recently cleaning up my aliases and being a... → luckman212

06/03/2022

01:50 PM Bug #12847: On startup "No routing address with matching address" might appear
Replicated the issue on:... Danilo Zrenjanin
01:08 PM Bug #12847 (Resolved): On startup "No routing address with matching address" might appear
No sign of these errors on anything I'm seeing here, static or dynamic, with or without working IPv6 when configured ... Jim Pingle
01:28 PM Bug #11692 (Resolved): ``fixup_default_gateway()`` should not remove a default gateway managed by a dynamic routing daemon
Jim Pingle
01:23 PM Bug #12606 (Resolved): ``devd`` is not configured to act on USB interface attach/detach events
devd hooks are in place and fire as expected when plugging/unplugging a USB Ethernet dongle Jim Pingle
01:09 PM Feature #13070 (Resolved): Allow auto prefix with manual prefix-length in NPt
Jim Pingle
01:01 PM Bug #13241: syslogd doesn't honor the Timezone set in the System/General Setup
Here is the feature request:
https://redmine.pfsense.org/issues/13244
Danilo Zrenjanin
12:54 PM Bug #13241: syslogd doesn't honor the Timezone set in the System/General Setup
Yeah right. It works fine after a reboot. I somehow omitted that part in the docs. Thanks!
However, adding the no...
Danilo Zrenjanin
07:10 AM Bug #13241 (Not a Bug): syslogd doesn't honor the Timezone set in the System/General Setup
That isn't a bug. Each daemon picks up the time zone change when it starts, that isn't up to @syslogd@. To fully acti... Jim Pingle
03:43 AM Bug #13241: syslogd doesn't honor the Timezone set in the System/General Setup
I am getting the same results on:... Danilo Zrenjanin
03:08 AM Bug #13241 (Not a Bug): syslogd doesn't honor the Timezone set in the System/General Setup
It shows the wrong time only in the Status/System Logs/System/General section.
I chose Europe/Belgrade Timezone. ...
Danilo Zrenjanin
01:00 PM Bug #13133 (Resolved): OpenVPN ``client-connect`` file contains ``topology``
Seems to be OK. No error in the client log now, client still gets a proper address using the correct topology Jim Pingle
01:00 PM Feature #13244 (New): Add help text under Timezone settings in the GUI
Adding the note from the docs in the GUI below the Timezone dropdown menu will be helpful.... Danilo Zrenjanin
12:57 PM Bug #12628 (Resolved): OpenVPN re-synchronization also synchronizes override entries unnecessarily in some cases
It's not clear from the original description which specific cases were not necessary, but I'm seeing the CSC files up... Jim Pingle
12:46 PM Bug #13145 (Resolved): Per-user ``route`` files are not removed from ``/tmp`` when they are no longer needed
Routes file is no longer left behind. Jim Pingle
12:42 PM Feature #12407 (Resolved): Use deferred client connections in OpenVPN
This has been back in place for a while. No problems with auth that I've seen, local or RADIUS.
Jim Pingle
12:33 PM Bug #4287: Wrong display for ppp in Interfaces page
Hi Marco,
I have the same problem like you, did you find a solution for it?
Karlo
Karlo Tomka
12:28 PM Bug #13243 (Resolved): OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
When a user authenticates to an OpenVPN instance the OpenVPN status shows an info "i" icon in the actions to display ... Jim Pingle
12:08 PM Bug #13099 (Resolved): Static routes to destinations at L2TP clients are not re-added after a client reconnects
Looks good. Following the procedure above, the route goes away when the client disconnects and comes back when the cl... Jim Pingle
11:22 AM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
follow-up issue: https://redmine.pfsense.org/issues/13242 → luckman212
09:32 AM Feature #12687 (Resolved): Option to disable auto-addition of static routes for ``dpinger``
This works OK as-is. As stated in the comments above it doesn't remove the routes, but the user can reboot or remove ... Jim Pingle
07:51 AM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
What's in now will have to be considered on its own -- any refinements should be done on a separate Redmine issue. Jim Pingle
11:20 AM Feature #13242 (Pull Request Review): Enhancements to static route creation/deletion for dpinger monitor IPs
related redmine: #12687 — (breaking out as requested by @jimp to a separate issue)
Th PR below adds some improveme...
→ luckman212
11:11 AM Todo #12619 (Resolved): Restart services on interface changes
In general this seems to be working as expected from what I can see.
If there are issues with individual services ...
Jim Pingle
10:51 AM Regression #12582 (Resolved): RADVD can be started on both HA nodes when configured with an IPv6 link-local address
Seems to be OK. With radvd set to use an LL VIP I still only see radvd running on the node with master status on its ... Jim Pingle
10:43 AM Regression #12961 (Resolved): CARP event storm when leaving persistent CARP maintenance mode
I'm only seeing one event per VIP now as expected. Jim Pingle
10:32 AM Bug #13076 (New): Marking a gateway as down does not affect IPsec entries using gateway groups
This still isn't working properly. I marked a gateway as down and it has no effect on IPsec. The dynamic DNS entry ch... Jim Pingle
07:41 AM Bug #12590 (Resolved): Dynamic DNS custom IPv6 service fails on 6rd tunnels
Jim Pingle
07:40 AM Bug #13097 (Resolved): PHP error when upgrading from before configuration revision 21.6, ``ipsec_create_vtimap()`` is undefined
No PHP error on upgrade when coming from <21.6 now. Closing. Jim Pingle
07:13 AM Bug #12612 (New): DNS Resolver is restarted during every ``rc.newwanip`` event even for interfaces not used in the resolver
The code looks like it should be right but we can debug it for the next release, it's not a blocker for 22.05. Jim Pingle
01:55 AM Bug #12612: DNS Resolver is restarted during every ``rc.newwanip`` event even for interfaces not used in the resolver
Tested... Danilo Zrenjanin
02:41 AM Bug #12609 (Resolved): IGMP Proxy server is restarted during every ``rc.newwanip`` event
Tested... Danilo Zrenjanin

06/02/2022

10:38 PM Bug #13127 (Resolved): DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
I've tested again on a fresh image and I cannot get it to repeat the blank interface name, the interface name changes... Reid Linnemann
03:30 PM Bug #13127: DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
It's just blank, the table data for the cell is empty. I'll get a chance to have a further look at it in the next few... Reid Linnemann
03:24 PM Bug #13127: DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
@rlinnemann : Can you send a screenshot of that rendered page with the blank ifname? I looked again at the code and i... → luckman212
10:33 PM Bug #13048 (Resolved): Explicit PPPoE disconnect of a WAN Gateway Group member may not restore a default route
Default gateway switches away and back as expected when disconnecting and reconnecting. Jim Pingle
10:06 PM Bug #11629 (Resolved): PPPoE WAN IP address different than expected when set static by ISP
Following the stated procedure I can't reproduce the problem on 22.05 now. I see the interface go down, and when it c... Jim Pingle
09:52 PM Bug #12975 (Resolved): IKEv2 Mobile IPsec clients do not receive ``INTERNAL_DNS_DOMAIN`` (value ``25``) attribute
The new attribute is present in the configuration, the rest is up to clients at this point. Jim Pingle
09:42 PM Bug #11984 (Resolved): Automatic Outbound NAT mode can create incorrect rules in some cases
I can't find any way to reproduce the original issue here, but the code in the change is solid, the scope is removed ... Jim Pingle
09:41 PM Bug #13230: Floating rules on VPN interfaces
That’ll be my issue then, thanks. I did wonder if that was the case. James Chambers
09:31 PM Bug #13240 (Resolved): User is forced to pick an NPt destination IPv6 prefix length even when choosing a drop-down entry which contains a defined prefix length
Following on from #4881
There are two minor issues in the NPt GUI when dealing with dynamic choices:
1. When t...
Jim Pingle
09:27 PM Feature #4881 (Resolved): Allow NPt to use dynamic IPv6 networks
Jim Pingle
09:27 PM Feature #4881: Allow NPt to use dynamic IPv6 networks
Two minor issues:
1. When there are multiple available entries the list isn't cleared and each line also contains ...
Jim Pingle
09:10 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
I saw this bug on 22.05-Devel and now on 22.05-Beta. The rules are working, but are not logged. Glenn Hall
08:55 PM Regression #12862 (Resolved): Some ``sysctl`` OIDs in ``loader.conf.local`` are silently removed
The value of @net.link.ifqmaxlen@ in @loader.conf.local@ is retained across multiple reboots on 22.05 Jim Pingle
08:16 PM Regression #13162 (Resolved): Upgrade does not work when using only IPv6 DNS servers
Seems to be fixed. On 22.01 if I set only IPv6 DNS and tell the GUI to only use remote DNS, the update check does fai... Jim Pingle
08:10 PM Bug #12721 (Resolved): IPv6 gateway group using link local addresses incorrectly logs a gateway change because it not including interface scope properly
Seems to be OK on the latest snapshot. I can't reproduce the problem there. Failover group with two IPv6 tiers, both ... Jim Pingle
08:02 PM Bug #6880 (Resolved): Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
This looks excellent on the latest snapshot.
On 22.01 each interface has a separate configuration and only one of ...
Jim Pingle
06:17 PM Bug #12611 (Resolved): SNMP daemon is restarted during every ``rc.newwanip`` event
Reid Linnemann
03:24 PM Bug #12527 (Resolved): DHCPv6 server does not skip interfaces configured with invalid ranges
Works on latest internal test snapshot. Jim Pingle
09:13 AM Bug #12527: DHCPv6 server does not skip interfaces configured with invalid ranges
The patch did the job.
Tested:...
Danilo Zrenjanin
08:51 AM Bug #12527: DHCPv6 server does not skip interfaces configured with invalid ranges
If nobody else offers feedback before 22.05 releases, this is OK to close. The change appears to be solid but I'd lik... Jim Pingle
08:38 AM Bug #12527: DHCPv6 server does not skip interfaces configured with invalid ranges
Patch was tested successfully by multiple people internally, including several dynamic and static systems in my lab. ... Jim Pingle
08:35 AM Bug #12527 (Feedback): DHCPv6 server does not skip interfaces configured with invalid ranges
Applied in changeset commit:3dc73d391eff61f490798696af78a4cdbeeeaf18. Jim Pingle
08:29 AM Bug #12527: DHCPv6 server does not skip interfaces configured with invalid ranges
MR: https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/814
Patch is attached and fixes it for me here in ...
Jim Pingle
07:56 AM Bug #12527 (Assigned): DHCPv6 server does not skip interfaces configured with invalid ranges
This caused a regression where it's skipping dhcp6 for delegated prefixes. Jim Pingle
03:23 PM Regression #13238 (Resolved): WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
Works on latest internal test snapshot. Jim Pingle
08:58 AM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
I have picked this back into the 22.05 branch and it will be included in the release. Jim Pingle
07:56 AM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
The dhcpd problem appears to be a regression from #12527 and is unrelated to this. Jim Pingle
03:07 PM Bug #13139 (Resolved): Stale ``sshdkeys.dirty`` lock file prevents generating SSH server keys
Reid Linnemann
02:07 PM Revision b79dff5b: Disable distclean to prevent removing distfiles that are still in use
Brad Davis
02:02 PM Bug #12613 (Resolved): DNS Resolver does not restart during link up/down events on a static IP address interface
Based on the original problem description and steps to reproduce it sounds like this specific request is fixed. For t... Jim Pingle
01:56 PM Bug #12613: DNS Resolver does not restart during link up/down events on a static IP address interface
Tested... Danilo Zrenjanin
01:08 PM Revision 3dc73d39: dhcp6 range check/tracked prefix. Fixes #12527
Jim Pingle
11:22 AM Regression #12949 (Resolved): The ruleset is not regenerated after assigning an interface
Confirmed this no longer happens in current 2.7 snapshots. The running ruleset is updated immediately when re-assigni... Steve Wheeler
09:34 AM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
@Flole please test with the updated version of this patch if you have the time: https://github.com/pfsense/pfsense/pu... → luckman212
07:13 AM Bug #13239 (Duplicate): ipv6 based ipsec vpn tunnel bug found with fqdn remote host
Appears to be the same as #12645 which is already fixed in 22.05/2.7.0 snapshots. Jim Pingle
03:14 AM Bug #13239: ipv6 based ipsec vpn tunnel bug found with fqdn remote host
https://forum.netgate.com/topic/171869/ipsec-vpn-bug-found?_=1654156661373 Alex Zaykov
03:13 AM Bug #13239 (Duplicate): ipv6 based ipsec vpn tunnel bug found with fqdn remote host
Hi I would to report the bug, related to ipsec vpn
In the settings of Phase 1 (ike v2)
under:
IKE Endpoint...
Alex Zaykov

06/01/2022

10:29 PM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
Jim Pingle wrote in #note-3:
> I think I've spotted the problem here. In #6880 the scripts were changed around a bit...
Daryl Morse
08:35 AM Regression #13238 (Feedback): WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
Applied in changeset commit:7b9fdf030fbe4e1d5051bf6d8962f365aeb1b69a. Jim Pingle
08:22 AM Regression #13238 (Pull Request Review): WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
I think I've spotted the problem here. In #6880 the scripts were changed around a bit and the withoutra path isn't ge... Jim Pingle
12:14 AM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
Hayden Hill wrote in #note-1:
> I am having the same issue in the development versions of 22.05. "Do not wait for RA...
Daryl Morse
10:03 PM Revision 90c1f864: Switch to hping3 since hping has been EoLed and removed upstream
Brad Davis
07:10 PM Bug #12003 (Resolved): Pie and ``fq_pie`` are missing options and do not handle floating point number input correctly
Reid Linnemann
06:35 PM Revision 4d287e88: Merge pull request #4590 from luckman212/fix-omission-of-pr4551
Jim Pingle
06:11 PM Revision 9c822e62: Merge branch 'pfsense:master' into fix-omission-of-pr4551
Luke Hamburg
05:54 PM Revision 44132b27: oops. forgot to actually process the dpinger_dont_add_static_routes flag
→ luckman212
04:41 PM Bug #12986 (Resolved): DHCP network boot filename can be incorrectly placed in DHCP Pool Options
Reid Linnemann
01:46 PM Feature #12687 (Feedback): Option to disable auto-addition of static routes for ``dpinger``
Jim Pingle
01:37 PM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
Needed one more fix: https://github.com/pfsense/pfsense/pull/4590
That may not make it into 22.05 at this point. I...
Jim Pingle
01:18 PM Revision 7b9fdf03: Always use rstold script header. Fixes #13238
Jim Pingle
01:01 PM Bug #12095: Memory leak in pcscd
Update: looks like the PCSC maintainer has fixed the mem leak: https://github.com/LudovicRousseau/PCSC/issues/55#issu... → luckman212
01:01 PM Bug #12468: Stopping IPsec daemon on the Status / Services page lead to log files flooding if pcscd daemon is enabled
Update: looks like the PCSC maintainer has fixed the mem leak: https://github.com/LudovicRousseau/PCSC/issues/55#issu... → luckman212
11:20 AM Bug #13237: dhcp6c script cannot be executed safely
I get it once every time after saving/applying WAN interface. When I looked at the code, the files get created before... Marcos M
07:55 AM Bug #13237: dhcp6c script cannot be executed safely
The real question here is why it works most of the time then suddenly fails. I'm guessing something is removing the f... Jim Pingle

05/31/2022

09:01 PM Bug #13210: PPPoE server panics with multiple client connections
https://github.com/pfsense/FreeBSD-src/commit/5e816cde27af3cd6e46ea0ffb2d167804899bebd
https://forum.netgate.com/top...
Marcos M
05:50 PM Bug #13210 (Feedback): PPPoE server panics with multiple client connections
Steve Wheeler
05:46 PM Bug #13210: PPPoE server panics with multiple client connections
Pushed fixes:
> Author: Mateusz Guzik <mjg@netgate.com>
> Date: Tue May 31 22:43:37 2022 +0000
>
> pf: fix a...
Mateusz Guzik
07:30 PM Bug #13127: DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
Hmm weird, I didn't experience that on my systems. What's the name of your interface? → luckman212
06:35 PM Bug #13127 (Assigned): DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
When I test this, the interface name becomes an empty string. Reid Linnemann
06:12 PM Bug #13127 (Resolved): DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
Reid Linnemann
06:06 PM Feature #12982: Add support for RFC7499 in RADIUS library.
Hello Marcos, after using your patch, I took the log as requested. It seems it loaded 63 rows and stopped. Frank Lee
01:34 PM Feature #12982: Add support for RFC7499 in RADIUS library.
Hello Marcos, I sent you an email on the result, but It seems it is not outputing the information you need. Not sure... Frank Lee
05:56 PM Bug #13148 (Assigned): Traffic passed by Captive Portal cannot use limiter queues on other rules
This appears to still be broken. Reid Linnemann
05:53 PM pfSense Docs Todo #13236: Document link speed limitations with igc and ix on 6100/4100
Which makes this language on the pfSense interface config pages, though correct, probably in need of some adjustment ... Chris Linstruth
04:31 PM pfSense Docs Todo #13236: Document link speed limitations with igc and ix on 6100/4100
It's been tested by a customer, along with SW and CL.
At best, the ix and igc ports on *both* the 6100 and 4100 wil...
Marcos M
07:44 AM pfSense Docs Todo #13236: Document link speed limitations with igc and ix on 6100/4100
Has that been tested and confirmed? I remember some discussion around that back when the driver was first brought in,... Jim Pingle
05:34 PM Bug #12811 (New): Services are not restarted when PPP interfaces connect
Jim Pingle
05:31 PM Bug #13215 (Assigned): Allowed MAC/IP/Hostname traffic counts for authorized users
Reid Linnemann
05:29 PM Bug #13215 (New): Allowed MAC/IP/Hostname traffic counts for authorized users
The change here was backed out, so needs to be revisited next version Jim Pingle
05:27 PM Regression #13193 (Resolved): Deleting a host entry fails to remove dummynet pipes
Reid Linnemann
05:25 PM Bug #12998 (Resolved): Wireless interface WPA configuration fields are always visible
Appears to be correct on current snapshot Jim Pingle
05:19 PM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
I am having the same issue in the development versions of 22.05. "Do not wait for RA" seems to be the culprit as well. Hayden Hill
05:07 PM Regression #13238 (Resolved): WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
My specific situation is the following:
ISP requires the following settings:
Request only an IPv6 prefix
Do no...
Daryl Morse
05:19 PM Bug #13204 (Resolved): Captive Portal reserves four (instead of two) pipes for client
Reid Linnemann
05:18 PM Bug #12649 (Closed): Allowed IP/Hostname "Direction" option is never used
Reid Linnemann
05:14 PM Regression #12999 (Resolved): Duplicate wireless interfaces are created at boot
No problem on current snapshot Jim Pingle
05:12 PM Regression #12937 (Resolved): Traffic Shaper wizard can produce an invalid ruleset when configured with an IPv4 upstream SIP server
Works now Jim Pingle
05:08 PM Bug #11764: IPv6 link local gateway default status not indicated in GUI
Jim Pingle wrote in #note-14:
> The problem here as exactly stated is solved. If we can reproduce a different (albei...
Daryl Morse
04:45 PM Bug #11764: IPv6 link local gateway default status not indicated in GUI
Hayden Hill wrote in #note-13:
> Hayden Hill wrote in #note-12:
> > I might be having the same issue here. 22.05/2....
Daryl Morse
03:17 PM Bug #11764 (Resolved): IPv6 link local gateway default status not indicated in GUI
The problem here as exactly stated is solved. If we can reproduce a different (albeit similar) problem along a separa... Jim Pingle
04:59 PM Bug #13004 (Resolved): ``write_rcfile()`` does not create ``rc_restart()`` entry
Works now Jim Pingle
04:58 PM Regression #13025 (Resolved): Some services won't start - wrong syntax in autogenerated rc.d scripts
Works now Jim Pingle
04:53 PM Bug #13092 (Resolved): PPPoE WANs fail to reconnect after parameter negotiation failure
Jim Pingle
03:39 PM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
We have tested internally here and can't reproduce any problems with SHA384 or SHA512. In each case so long as both s... Jim Pingle
08:00 AM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
That isn't what the P2P limitation is. The GUI selection for "peer-to-peer SSL/TLS" is fine, it's OpenVPN's internal ... Jim Pingle
03:38 PM Bug #13216 (Resolved): Switching nomacfilter option does not change autorized users rule format
Reid Linnemann
03:33 PM Regression #13056 (Resolved): OpenVPN ``remote_cert_tls`` option does not behave correctly when enabled and later disabled
Option toggles correctly now. I can enable it and the option goes into the config. Disable it and it comes out.
Jim Pingle
03:32 PM Bug #11941 (Resolved): Many ``exec()`` functions do not use full path to executable files
Reid Linnemann
03:28 PM Bug #12141 (Resolved): Lack of DNS or Internet connectivity causes GUI to be slow
Reid Linnemann
03:27 PM Feature #12267 (Resolved): OpenVPN option to limit concurrent connections per user
Jim Pingle
03:27 PM Bug #12332 (Resolved): OpenVPN does not clear old Cisco-AVPair anchor rules in some cases
Jim Pingle
03:25 PM Bug #12771 (Resolved): Automatic filter reload with OpenVPN client gateway uplink happens too soon or not at all
Jim Pingle
03:24 PM Regression #12884 (Resolved): OpenVPN status display for TAP mode services shows peer-to-peer instead of client list in certain cases
Jim Pingle
03:18 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
Sage Badolato wrote in #note-34:
> I cannot test 22.05, I'm on community edition.
You can try a recent 2.7.0 snap...
Jim Pingle
03:01 PM Bug #12691 (Resolved): Support encrypted ``config.xml`` files when restoring during install
Latest commit works well. I get the prompt for the password, I can enter the password and it successfully decrypts an... Jim Pingle
01:08 PM Bug #12691 (Feedback): Support encrypted ``config.xml`` files when restoring during install
MR merged. Jim Pingle
01:04 PM Bug #12691 (Pull Request Review): Support encrypted ``config.xml`` files when restoring during install
MR: https://gitlab.netgate.com/pfSense/FreeBSD-src/-/merge_requests/88
That MR has the proposed changes inside.
Jim Pingle
12:56 PM Bug #12691: Support encrypted ``config.xml`` files when restoring during install
Two problems here:
* It may not be reading the password properly. It would be better to use @dialog@ than a text p...
Jim Pingle
11:12 AM Bug #12691 (Assigned): Support encrypted ``config.xml`` files when restoring during install
Unfortunately, this does not look to be working for me.
This is what I get when I try to decrypt using the install...
Chris Linstruth
02:59 PM Bug #12672 (Resolved): GleSYS Dynamic DNS responses are not parsed properly
No access to provider, no feedback. Closing. Jim Pingle
02:58 PM Feature #12744 (Resolved): IPv6 support for DNSimple Dynamic DNS
No access to provider, no feedback. Closing. Jim Pingle
02:58 PM Feature #12752 (Resolved): Support wildcard Dynamic DNS records on DigitalOcean
No access to provider, no feedback. Closing. Jim Pingle
02:58 PM Bug #12754 (Resolved): Google Domains Dynamic DNS responses are not parsed properly
Jim Pingle
02:58 PM Bug #12761 (Resolved): Input validation prevents configuring wildcard Dynamic DNS records on Google Domains
Jim Pingle
02:49 PM Bug #12721: IPv6 gateway group using link local addresses incorrectly logs a gateway change because it not including interface scope properly
How to verify that this change is working:
1) Create gateway group "WAN_IPv6" which contains:
Tier 1: WAN1 (m...
Loren McQuade
02:31 PM Bug #12721: IPv6 gateway group using link local addresses incorrectly logs a gateway change because it not including interface scope properly
It lacked an assignee before, mostly it's for tracking who fixed the issue.
Ideally we'd like feedback from someon...
Jim Pingle
02:28 PM Bug #12721: IPv6 gateway group using link local addresses incorrectly logs a gateway change because it not including interface scope properly
I see you have assigned this back to me, but I am unsure of what further action is needed on my part. I can verify a... Loren McQuade
02:12 PM Bug #12749 (Resolved): Uninitialized array in ``array_remove_duplicates()``
Jim Pingle
02:10 PM Todo #13100 (Resolved): Transition Captive Portal from IPFW to PF
The work here is complete, any issues we find can be raised separately. Jim Pingle
02:09 PM Bug #12801 (Resolved): User password hashes pseudo-random number generator may return insecure salt value
The correct function is in place now and working properly. Jim Pingle
02:06 PM Bug #13116 (Resolved): OpenVPN client ``tls-client``/``client`` configuration directive not handled properly
This appears to be correct and consistent now. Jim Pingle
02:00 PM Regression #13155 (Resolved): Rule labels in pftop output are not correct
All good now. Proper labels are shown in pftop label view and it didn't negatively impact the firewall log view. Jim Pingle
01:55 PM Todo #13149 (Resolved): Remove unnecessary trailing colon after Outbound NAT "Automatic Rules" section header
The trailing colon is gone. Jim Pingle
01:55 PM Todo #13129 (Resolved): OpenVPN status page improvements
The new changes are present and working well. Jim Pingle
01:50 PM Todo #12701 (Resolved): Reorganize CARP status page
Looks great now Jim Pingle
01:49 PM Feature #12092 (Closed): Utilize new ``pfctl`` abilities to kill states
This has been working well for a while now. Any issues we hit from here can be addressed separately.
Jim Pingle
01:48 PM Regression #13163 (Resolved): Incorrect variable in package error message results in "Array" being printed instead of package name
Jim Pingle
01:42 PM Regression #13178 (Resolved): Incorrect usage of DSCP hex value
This is OK as-is for now. We could consider the other change as a separate request for the next release if needed. Jim Pingle
01:28 PM Bug #9263 (Resolved): Incorrect ICMP reply when using limiters
Assigning to Kristof since it was likely fixed along the way when moving dummynet and such info PF Jim Pingle
01:19 PM Feature #12687 (Resolved): Option to disable auto-addition of static routes for ``dpinger``
That would have to wait for the next release, make a new feature request issue with a link back to this one to track ... Jim Pingle
12:46 PM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
I have a new PR almost ready that dynamically adds/removes the static routes when the checkbox is changed without req... → luckman212
12:04 PM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
This tested OK to me. Note that I only tested the checkbox in on the gateway, since it looks like the other subjects ... Chris Linstruth
01:05 PM Regression #13142 (Resolved): PHP shell ``pfanchordrill`` script produces errors on captive portal tables
The contents of nested captive portal anchors are now displayed as expected. Jim Pingle
12:58 PM Bug #13237: dhcp6c script cannot be executed safely
You're right, I misread it. It's likely what you're thinking. Marcos M
12:42 PM Bug #13237: dhcp6c script cannot be executed safely
Setuid on a shell script? That doesn't seem appropriate. And I don't think that lines up with the checks.
The checks...
Denny Page
12:26 PM Bug #13237: dhcp6c script cannot be executed safely
The checks done for this are
* no setuid
** setuid'ed execution not allowed
** lstat failed
* the file must be owned ...
Marcos M
10:49 AM Bug #13237 (New): dhcp6c script cannot be executed safely
*22.05 Plus Beta on system boot*
When the "Do not wait for a RA" option is selected on the WAN interface, /var/etc...
Denny Page
12:23 PM Regression #13192 (Resolved): Default pipe rate limits are applied to allowed mac/ip/host entries
Reid Linnemann
12:22 PM Regression #13191 (Resolved): Deleting a passthru mac entry fails to remove pf rules and dummynet pipes associated with the passthru mac
Reid Linnemann
12:21 PM Bug #13169 (Resolved): captiveportal_ether_delete_entry() does not delete anchors/pipes
Reid Linnemann
12:18 PM Regression #13147 (Resolved): Captive Portal: Idle timeout does not see activity
Reid Linnemann
12:18 PM Feature #12945 (Resolved): Implement missing ipfw equivalents in libpfctl necessary for captiveportal
Reid Linnemann
12:15 PM Regression #12834 (Resolved): Only TCP traffic is passed outbound through IPFW
Closing, ipfw is out of the mix for 2.7.0/22.05 Reid Linnemann
11:42 AM pfSense Docs Todo #12756: Add information on correct MTU to use with WireGuard
https://lists.zx2c4.com/pipermail/wireguard/2017-December/002201.html... Marcos M
07:58 AM pfSense Docs Todo #12756: Add information on correct MTU to use with WireGuard
@viktor or @cmcdonald — What should the MTU be set to? 1420?
I recently spent a few hours troubleshooting a slow s...
→ luckman212
10:55 AM pfSense Docs New Content #13205: ZFS Boot Environment documentation
Added docs for the new option to disable automatic BE creation during upgrade: https://gitlab.netgate.com/docs/pfSens... Jim Pingle
10:37 AM Bug #13175: PHP error on MAC entry add/edit
Use the revision ID linked in the comment after that.
https://github.com/pfsense/pfsense/commit/b7ddc1b810f16c827c...
Jim Pingle
09:33 AM Bug #13175: PHP error on MAC entry add/edit
Viktor Gurov wrote in #note-2:
> fix:
> https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/787
The link...
Rafael Ferreira
07:55 AM Bug #13230 (Not a Bug): Floating rules on VPN interfaces
From the general description it sounds like when using rules on assigned VPN interfaces you get reply-to so traffic r... Jim Pingle
07:37 AM Bug #13235 (Not a Bug): URL in firewall rule hover does nothing
It's listing the contents of the alias. As that is a URL type alias, that is the content of the alias.
Linking the...
Jim Pingle
07:29 AM Bug #13231 (Not a Bug): OpenVPN custom options may fail after save/restore
OpenVPN directives are to be separated by semicolons, not newlines. That's stated in the text above the box and in th... Jim Pingle
07:20 AM Bug #13093 (In Progress): LDAP authentication fails with extended query and RFC2307 group lookups enabled
OK, we'll nudge this forward for now and proceed once we have more detail. Jim Pingle
02:13 AM pfSense Packages Feature #10818: UDP Broadcast Relay
Hey guys thanks for the shout out, but I have NO clue how to make this a package.
All I was able to do was build a...
Garth Kirkwood
02:02 AM pfSense Packages Feature #10818: UDP Broadcast Relay
Thank you for the information.
Let's hope @Garth Kirkwood sees this then
Øystein Gåsdal

05/30/2022

04:59 PM Bug #13093: LDAP authentication fails with extended query and RFC2307 group lookups enabled
Extended query works.
RFC2307 groups work.
Authentication fails when both are enabled.
The site I'm testing ...
Chris Linstruth
04:57 PM Bug #13093: LDAP authentication fails with extended query and RFC2307 group lookups enabled
I think this is probably still not right. Chris Linstruth
04:02 PM Bug #12923 (Resolved): DHCP "Ignore denied clients" option with MAC Deny list set causes DHCP server to not start
Working correctly on... Christopher Cope
03:54 PM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
Thanks for pointing out the RA-only restriction. I see that stephenw10 has replied in the original forum string that... Steve Wilson
09:32 AM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
Try to reproduce it with OpenVPN Server in Remote Access mode, Peer-to-Peer is not supported - see https://redmine.pf... Marcos M
12:28 PM pfSense Plus Bug #13074: AES-GCM with SafeXcel on Netgate 2100 causes MBUF overload
I mean to say it's not a SafeXcel issue specifically. Thank you for confirming it's only on the 2100 (ARM) platform. Marcos M
12:15 PM pfSense Plus Bug #13074: AES-GCM with SafeXcel on Netgate 2100 causes MBUF overload
Marcos Mendoza wrote in #note-3:
> Note that the issue may not be specific to SafeXcel - e.g. it could happen with In...
Chris S
11:06 AM pfSense Plus Bug #13074: AES-GCM with SafeXcel on Netgate 2100 causes MBUF overload
Note that the issue may not be specific to SafeXcel - e.g. it could happen with Intel QAT as well. Marcos M
12:25 PM Feature #12982: Add support for RFC7499 in RADIUS library.
The issue needs to be narrowed down further. Apply the following patch, reproduce the issue, then submit the /tmp/_DE... Marcos M
10:56 AM pfSense Packages Regression #12140 (Closed): DNSBL https webserver not working
Could not reproduce on 22.05 with pfBlockerNG-devel 3.1.0_4. The no logging of IP addresses has already been resolved... Marcos M
10:40 AM pfSense Packages Feature #10242 (New): E2guardian Web filtering package
Viktor Gurov
10:29 AM pfSense Packages Regression #12476 (Resolved): Suricata 6.0.3_3 Pass List ignores all single IPs
Marcos M
03:30 AM pfSense Packages Feature #11385 (Resolved): Add WireGuard tunneled networks to vpnaddresses list
Tested on 22.01 and on 22.05-BETA (built on Fri May 27 06:21:09 UTC 2022)
When I created Pass List with 'VPN Addre...
Azamat Khakimyanov
02:00 AM pfSense Packages Bug #11892 (Resolved): WireGuard: dpinger does not start correctly on a WireGuard gateway at boot
Tested on 21.05_2, 22.01 and on 22.05-BETA (built on Fri May 27 06:21:09 UTC 2022)
I saw no issue with dpinger and...
Azamat Khakimyanov

05/29/2022

10:57 PM Feature #12982: Add support for RFC7499 in RADIUS library.
Any new update? Frank Lee
08:31 PM Bug #13230 (Feedback): Floating rules on VPN interfaces
More information is needed to understand the issue. Is this occurring with an OpenVPN Server or Client configuration ... Marcos M
07:56 PM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
Hopefully this will be reproducible:
1. Set up Non-DCO OpenVPN server and client with follwing config options: pe...
Steve Wilson
06:31 PM pfSense Plus Bug #13233 (Feedback): OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
Tested on @22.05.b.20220524.0600@.
I was unable to reproduce this issue using OpenVPN RA TLS+User auth. Taking an ...
Marcos M
07:00 PM Bug #12878 (Feedback): Traffic shaping by interface, route queue bandwidth inbound, out by a large factor.
Please test 22.05 BETA when possible and let us know if the issue persists. Details on the Traffic Shaping config and... Marcos M
06:56 PM Bug #12877 (Feedback): Cloudflare DynDNS fails to update more than two addresses
If possible, please re-test after applying the available patch found with the System_Patches package. Marcos M
06:49 PM pfSense Plus Bug #13041 (Closed): DNS resolution of internal network names when logged in via OpenVPN requires workaround
Marcos M
06:38 PM pfSense Plus Bug #13232 (Duplicate): Restoring Config with OpenVPN Custom Options Removes Carriage Returns
This seems more like a feature than a bug, considering that the description and documentation both say to separate wi... Marcos M
06:17 PM Bug #13234 (Not a Bug): Separator locations pushed down when pfSense is rebooted
pfBlockerNG's auto rule creation will affect the placement of separators - this is likely what's happening. If you di... Marcos M
10:29 AM Bug #13234 (Not a Bug): Separator locations pushed down when pfSense is rebooted
This happens when I place a separator at the top of the floating rules and reboot the router. I have not checked othe... Jon Brown
05:34 PM Feature #8173: dhcp6c - RAW Options
Please let us have these features added to pfSense. Half of france is using OPNsense because nothing happens on this ... Tue Madsen
02:09 PM pfSense Docs Todo #13236 (Resolved): Document link speed limitations with igc and ix on 6100/4100
> The I225 built-in phy doesn't support fixed operation, so a speed/duplex setting is emulated by selecting that sing... Marcos M
12:09 PM pfSense Packages Feature #10818: UDP Broadcast Relay
There's no GUI for it, but it can be installed on 22.05/2.7:... Marcos M
11:21 AM pfSense Packages Bug #13153 (Resolved): Static routes bound to WireGuard interfaces are not restored after down / up events
Tested on 22.01 and on 22.05-BETA (built on Fri May 27 06:21:09 UTC 2022)
I wasn't able to reproduce this issue. A...
Azamat Khakimyanov
11:07 AM Bug #13235 (Not a Bug): URL in firewall rule hover does nothing
There is URL present in the modal box you get when you hover over a rule. This URL does nothing.
* Should this URL...
Jon Brown
06:38 AM pfSense Packages Bug #12251 (Resolved): Wireguard 0.1.5 - ignores "KeepAlive" parameter if empty (instead of disabling)
Tested on 22.01
When I used empty 'Keep Alive' field, I got in config: _*PersistentKeepalive = 0*_
When I tried...
Azamat Khakimyanov
03:49 AM pfSense Packages Feature #12719 (Resolved): add igc(4) to the list of INLINE mode (iflib/netmap) supported cards
Tested on 22.01
Interface *igc* was added into 'Supported drivers' list: _Supported drivers: bnxt, cc, cxgbe, cxl, e...
Azamat Khakimyanov
03:48 AM pfSense Packages Feature #11560 (Resolved): add ena(4) to the list of INLINE mode (netmap) supported cards
Tested on 22.01
Interface *ena* was added into 'Supported drivers' list: _Supported drivers: bnxt, cc, cxgbe, cxl, e...
Azamat Khakimyanov

05/28/2022

07:16 PM pfSense Plus Bug #13233 (Feedback): OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
OpenVPN DCO configurations specifying an auth digest algorithm of SHA512 fail to connect. Changing the algorithm to ... Steve Wilson
06:50 PM Bug #12875: Import zabbix-agent6 and zabbix-proxy6 from FreeBSD Ports
Discussed with engineering. This will get brought over in the next repo sync. Kris Phillips
03:19 PM pfSense Plus Bug #13232 (Duplicate): Restoring Config with OpenVPN Custom Options Removes Carriage Returns
If you back up a config on one device and then restore it in another, if you have an OpenVPN client (potentially serv... Kris Phillips
03:06 PM Regression #12821: Intel e1000 driver (``em``, ``igb``) cannot pass packets tagged with VLAN ``0``
Tested this on igc interfaces and it appears this only affects e1000-based NICs. Other Intel NICs would seem to be f... Kris Phillips
02:13 PM pfSense Docs New Content #13211: OpenVPN DCO Documentation
Much more clear to me, thanks! Marcos M
02:10 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
I cannot test 22.05, I'm on community edition. Sage Badolato
01:13 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
I suggest testing on 22.05 BETA if possible. If the issue persists there, it may be related to https://redmine.pfsens... Marcos M
02:01 PM Regression #13203 (Resolved): Floating rules without an interface are not loaded
Marcos M
01:47 PM pfSense Plus Bug #12974: Typing anything into 1100/2100 recovery installer causes process to stop
The wording has been addressed with NG 7431. This issue can be left open to track the behavior issue itself, as it sh... Marcos M
01:14 PM Bug #13228: Recovering interface gateway may not be added back into gateway groups and rules when expected
May be related to https://redmine.pfsense.org/issues/12920. Marcos M
12:59 PM Bug #13231 (Not a Bug): OpenVPN custom options may fail after save/restore
Sometimes after restoring a backup XML file, custom options get formatted improperly. That prevents the OpenVPN servi... Danilo Zrenjanin
12:45 PM Feature #4259 (Resolved): Port forward NAT rules with "any" protocol
Danilo Zrenjanin
12:45 PM Feature #4259: Port forward NAT rules with "any" protocol
Tested:... Danilo Zrenjanin
06:03 AM pfSense Packages Feature #10818: UDP Broadcast Relay
Hi.
Any news on this?
Eagerly awaiting this one
Øystein Gåsdal

05/27/2022

11:54 PM Bug #13230 (Not a Bug): Floating rules on VPN interfaces
With floating rules on OpenVPN and WireGuard interfaces, matching traffic doesn’t seem to return with rules that pass... James Chambers
09:44 PM pfSense Packages Feature #12658: Adding prometheus metrics to darkstat
I think the package is in the FreeBSD ports:... Karim Elatov
07:31 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
I can also confirm that I can replicate this exact issue on my PFSense. Both as a VM and as bare metal.
Using a H...
Sage Badolato
03:04 PM pfSense Docs Todo #13229 (Feedback): Update documentation for IPFW to PF transition for Limiters and Captive Portal
Relevant commits:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/47dd08cc24bb4ffbd476b2d4aebacdb6ccbce895
...
Jim Pingle
02:59 PM pfSense Docs Todo #13229 (Resolved): Update documentation for IPFW to PF transition for Limiters and Captive Portal
Adding for tracking.
Docs are updated to reflect that IPFW is no longer used, it's all in PF now.
Jim Pingle
01:59 PM pfSense Docs New Content #13223 (Feedback): Document new gateway state killing behavior
This should complete the relevant updates (and then some):
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/7...
Jim Pingle
01:15 PM Revision e5d97d7c: Update CARP status state sync note. Fixes #12701
Jim Pingle
10:58 AM Bug #13228 (Resolved): Recovering interface gateway may not be added back into gateway groups and rules when expected
When an interface/gateway recovers and rc.newwanip runs, the gateway may not end up in the ruleset in groups or rules... Jim Pingle
10:15 AM pfSense Plus Feature #13227: Group-based Mobile IPsec Virtual Address Pool assignment via RADIUS
I Should mention you can use my modifcation afterwards by creating the groups identifier and IP pool needed, by creat... Tue Madsen
10:09 AM pfSense Plus Feature #13227 (Resolved): Group-based Mobile IPsec Virtual Address Pool assignment via RADIUS
Currently you cannot create additional Virtual IP Pools to assign mobile users IP addresses from, if you are using EA... Tue Madsen
08:55 AM Todo #12701 (Feedback): Reorganize CARP status page
Applied in changeset commit:e5d97d7ce8bd3346ef8fa6f5477182331d2174b4. Jim Pingle
08:03 AM Todo #12701 (In Progress): Reorganize CARP status page
This could use one small change, to add a note/link in the info block saying the user can set a custom filter host ID... Jim Pingle
08:01 AM Todo #12701 (Resolved): Reorganize CARP status page
Jim Pingle
05:12 AM Todo #12701: Reorganize CARP status page
Tested.... Danilo Zrenjanin
08:00 AM Regression #11545 (New): Primary interface address is not always used when VIPs are present
That other issue could solve it for PPP type interfaces but it's happening on systems without PPP interfaces and thos... Jim Pingle
02:53 AM Regression #11545 (Feedback): Primary interface address is not always used when VIPs are present
Viktor Gurov
02:52 AM Regression #11545: Primary interface address is not always used when VIPs are present
Should be fixed in #11629
Please re-test on the latest 22.05/2.7 snapshots.
Viktor Gurov
06:29 AM Bug #13226 (Confirmed): Disconnecting a user from Captive Portal may allow previously established connections to continue
Able to reproduce.
It looks like @pfSense_kill_status()@ and @pfSense_kill_src states()@ are successfully kill TCP...
Viktor Gurov
05:11 AM Bug #13226: Disconnecting a user from Captive Portal may allow previously established connections to continue
It looks like @pfSense_kill_states()@ and @pfSense_kill_srcstates()@ does not work properly:
https://github.com/pfse...
Viktor Gurov
05:02 AM Bug #13226 (Resolved): Disconnecting a user from Captive Portal may allow previously established connections to continue
Steps to reproduce:
1. Connect to the network through the CP portal.
2. Establish OpenVPN forcing all traffic thr...
Danilo Zrenjanin
05:25 AM Bug #13218: GIF-based interface MTU is assigned to parent interface on boot when parent interface is a LAGG
I've applied it and it looks to do the job. I will keep an eye on it and throw in a couple of reboots over the weeken... Graeme Bragg
02:59 AM Bug #13218: GIF-based interface MTU is assigned to parent interface on boot when parent interface is a LAGG
Graeme Bragg wrote in #note-3:
> Thanks for looking at this so quickly. Please let me know if you need/want me to te...
Viktor Gurov
05:21 AM Bug #13225: Bridges with QinQ interfaces not properly set up at boot
fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/810
Viktor Gurov
03:14 AM Bug #13225 (Resolved): Bridges with QinQ interfaces not properly set up at boot
We have a setup that includes several OpenVPN tunnels, some of them using QinQ. When system is configured using WebUI... Lauri Liuhto
01:58 AM Bug #13224 (Duplicate): Email notification flood when UPS (NUT) and WAN send notifications
When my UPS (monitored with NUT) and one of my WAN (PPPoE) both send email notifications close to each other, it star... Riccardo Ambrosi
 

Also available in: Atom