Activity
From 05/27/2022 to 06/25/2022
06/25/2022
-
07:01 PM pfSense Docs Correction #11223 (Resolved): Azure Marketplace links are invalid
-
07:01 PM pfSense Docs Correction #11223: Azure Marketplace links are invalid
- Looks like this was fixed. The corrected links point to https://azuremarketplace.microsoft.com/en-us/marketplace/apps...
-
05:47 PM Bug #12544: OpenSSH vulnerabilities
- This bug report can be closed. pfSense Plus 22.05 comes with OpenSSH 8.8p1, which is not vulnerable to any of these ...
-
05:42 PM Bug #8207: 2.4 cannot boot as a Xen VM with more than 7 NICs
- Due to lack of confirmation, this bug report should be rejected unless it can be verified that there is a problem on ...
-
05:41 PM Bug #9626: When deny write permission is assigned to a user, there is no error feedback if the user tries to write something
- Can confirm this is still an issue in 22.05 of pfSense Plus. There is no visual feedback or an error notification du...
-
05:39 PM Bug #7996: Unnecessary link tag in login page
- This is still present in pfSense Plus 22.05.
-
05:38 PM pfSense Packages Bug #10602 (Resolved): Dashboard->Traffic Graphs bandwidth designations on hover pop-ups
- Tested this on pfSense Plus 22.05. Not sure when this was fixed, but this looks to be resolved. Closing out this bu...
-
05:34 PM pfSense Plus Bug #11626: Google LDAP connections fail due to lack of SNI for TLS 1.3
- Jim Pingle wrote in #note-15:
> Nudge this ahead so we have more time to ensure there aren't any regressions from th... -
05:30 PM pfSense Plus Feature #12546: Add 2FA Support to pfSense Plus Local Database Authentication
- Further expounding on this, it appears that Viscosity has native capability to add prompts in the client config.
... -
05:03 PM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
- Jim Pingle wrote in #note-9:
> Marcos Mendoza wrote in #note-7:
> > I created https://redmine.pfsense.org/issues/13... -
05:00 PM Bug #13003: Malicious Driver Detection event on ``ixl(4)`` driver
- Christoph Vieten wrote in #note-5:
> Kris Phillips wrote in #note-3:
> > Christoph Vieten wrote in #note-2:
> > > ... -
03:25 PM pfSense Docs Todo #12770: Feedback on Firewall — Configuring firewall rules
- Merge request:
https://gitlab.netgate.com/docs/pfSense-docs/-/merge_requests/42 -
10:59 AM pfSense Packages Bug #11572: Auto created firewall rules have IPv4 as protocol only - even for IPv6 lists.
- Still an issue in 2.6.0
Why not remove pfblockerNG from Repo if it's no more fixed and maintained anyway? Saves ti... -
05:41 AM Bug #13301 (Duplicate): Bug #13239 = (?) = #12645 appease not fixed - ipv6 based ipsec vpn tunnel bug found with fqdn remote host
- Hi,
I reported the bug earlier : https://redmine.pfsense.org/issues/13239#change-61632
ipv6 based ipsec vpn tun... -
05:33 AM Bug #12645: ``filterdns`` does not monitor remote IPsec gateways for IPv6 address changes
- tested on the latest built 22.05-RC (amd64) built on Fri Jun 17 06:34:36 UTC 2022
the bug is not fixed, Ipsec tunnel...
06/24/2022
-
10:10 PM Feature #13296: Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
- It's where the bug entries are for FreeBSD ports are, and where a feature request can be submitted.
-
04:16 PM Bug #9471 (Resolved): GIF tunnel not added to interface group after reboot
added GIF,LAN,PPPoE and GRE to the group of interfaces, GIF is added to the interface group after reboot
ifconfi...-
03:09 PM Revision 3222c70a: Omit VIPs from interface address selection. Fixes #11545
- Add function get_interface_addresses() which wraps around pfSense_get_ifaddrs() and
filters VIPs before selecting an ... -
02:50 PM pfSense Packages Bug #13261 (Feedback): Input validation rejects empty ``sudo`` command list, but GUI text says it can be empty
- Merged: https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/commit/a056c1984a174248da0a0f8c541d9441678a2339
-
01:23 PM pfSense Packages Bug #13261 (Pull Request Review): Input validation rejects empty ``sudo`` command list, but GUI text says it can be empty
- https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/251
-
11:31 AM pfSense Docs Correction #13300 (Resolved): Corrected Silabs driver URL
-
11:20 AM pfSense Docs Correction #13300 (Resolved): Corrected Silabs driver URL
- Current link in the Windows tab of the Connecting to the Console Port pages for Netgate firewalls (excluding 1100 and...
-
11:21 AM pfSense Packages Bug #13299 (Resolved): Cron package needs basic input validation and output encoding
- Tested and working as expected on...
-
10:18 AM pfSense Packages Bug #13299 (Feedback): Cron package needs basic input validation and output encoding
- Fixed: https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/commit/1a8a2f338592428dd46e543a884b1758b68198c9
-
10:09 AM pfSense Packages Bug #13299 (Resolved): Cron package needs basic input validation and output encoding
- The cron package does not validate its inputs nor does it encode its output. This can lead to a potential stored XSS....
-
10:25 AM Regression #11545: Primary interface address is not always used when VIPs are present
- I believe I have a fix for this issue. I created a variation on pfSense_get_interface_addresses() named pfSense_get_i...
-
10:15 AM Regression #11545 (Feedback): Primary interface address is not always used when VIPs are present
- Applied in changeset commit:3222c70aaf783336901f7b1225727b5973ba865a.
-
07:47 AM Bug #13298: Dynv6 Dynamic DNS client does not check the response code when updating
- PR: https://github.com/pfsense/pfsense/pull/4605
-
07:16 AM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
- Marcos Mendoza wrote in #note-7:
> I created https://redmine.pfsense.org/issues/13293 for that. Given that @auth-gen...
06/23/2022
- 08:49 PM Revision adfb1d2b: fix: Dynv6 checkIP
- Check return of update to release check IP
-
07:49 PM pfSense Packages Bug #8454: Arpwatch package break email notifications from other sources
- Is this still current as of 22.05? I just started playing with Arpwatch. What exactly does the "Disable Cron emails" ...
-
04:01 PM Bug #13298: Dynv6 Dynamic DNS client does not check the response code when updating
- *Testing*
Tested with https://dynv6.com -
03:58 PM Bug #13298 (Resolved): Dynv6 Dynamic DNS client does not check the response code when updating
- Check return of update to release check IP
-
12:04 PM Feature #13297 (New): Support for Gateway Groups as Static Route destinations
- It could be interesting to have the possibility to use a group of gateways with static routes in a failover scenario....
-
07:06 AM Regression #11316: Unbound crashes with signal 11 when reloading
- Why is this closed ??
All was ok for my pfsense until a power outage.
I have pfsense 2.6 up to date and it has been... -
01:31 AM Bug #13003: Malicious Driver Detection event on ``ixl(4)`` driver
- Kris Phillips wrote in #note-3:
> Christoph Vieten wrote in #note-2:
> > Same happened on 2.6.0 with Intel x710-T4 ...
06/22/2022
-
09:31 PM Feature #13296: Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
- @mmendoza was that last link you posted supposed to show something related? for me it just appears to be a list of ev...
-
05:54 PM Feature #13296: Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
- It's http://wide-dhcpv6.sourceforge.net/
See:
https://github.com/pfsense/FreeBSD-ports/tree/devel/net/dhcp6
http... -
04:47 PM Feature #13296: Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
- I'm still hazy on exactly which dhcp6c implementation is currently shipping. I _thought_ it was the "hrs-allbsd/wide-...
-
04:01 PM Feature #13296 (New): Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
- Some ISPs are rolling out IPv6 and not directly providing a globally routable WAN address via DHCPv6. Instead, they a...
-
09:04 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- hello guys
Configurator (Scope):
Interfaces: WAN-DHCP4|WAN2-DHCP4
Gateway Group: Failover (WAN_DHCP Gateway: 192... -
06:06 PM Feature #13294: Change gateway name
- There's no functionality to rename the gateway/group and update all of the places where it could be used. That could ...
-
10:27 AM Feature #13294 (New): Change gateway name
- After clicking on a gateway on system_gateways_edit.php, which takes the user to e.g., system_gateways_edit.php?id=0,...
-
05:19 PM Revision d55e0d4b: fix func params for get_dpinger_status() call in gwlb.inc
-
04:15 PM Revision 7e9a12e9: Centralize the branches into builder_defaults.sh to simplify and eliminate overwriting the variables
-
12:26 PM Bug #13295 (Resolved): Incorrect function parameters for ``get_dpinger_status()`` call in ``gwlb.inc``
- There seems to be an error in @gwlb.inc@ around line 479. The call to @get_dpinger_status()@ has the @$action_disable...
-
02:12 AM Revision 5ecee3d7: scrubing -> scrubbing
06/21/2022
-
03:47 PM Revision 098cdb61: Add version config for use by pfSense-repo
-
02:37 PM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
- I created https://redmine.pfsense.org/issues/13293 for that. Given that @auth-gen-token@ handles the issue with frequ...
-
02:35 PM Feature #13293 (New): Option to set auth-gen-token in OpenVPN GUI
- This option is useful to avoid having to frequently manually re-authenticate when using MFA.
> --auth-gen-token [lif... -
12:06 PM pfSense Packages Feature #13292 (New): Separator
- It'd be really nice if there was a way to add a separator to the certificates list in the ACME package. Nothing fanc...
-
10:22 AM pfSense Docs Todo #13291 (Duplicate): Notification documentation
- I know there is documentation here on how to setup notification
https://docs.netgate.com/pfsense/en/latest/config/... -
01:00 AM Bug #13210: PPPoE server panics with multiple client connections
- Sorry, wanted to add it here for documentation purpose but forgot to make it yesterday:...
06/20/2022
-
06:01 PM Regression #13290 (Feedback): Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters
- There's not enough info here to troubleshoot this. Discussion of the issue may be continued on the forums: https://fo...
-
02:25 PM Regression #13290 (Resolved): Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters
- After upgrading from 2.6.0 to 2.7.0, my Captives Portal users are dropped randomly, having to re-authenticate... Ther...
-
04:20 PM Bug #13210 (Resolved): PPPoE server panics with multiple client connections
- Customer which was previously frequently hitting this issue reports it's been resolved after updating to the RC.
-
04:04 PM Bug #10352: RADIUS authentication fails with MSCHAPv1 or MSCHAPv2 when passwords contain international characters
- The issue is still present on 22.01-RELEASE
Any foreseen planning to fix this issue ?
Is someone working on it ? ma... -
01:03 PM Feature #13286: webConfigurator does not redirect to requested page after login
- I understand.
To be honest, one of my main reasons for wanting this merged was because my dashboard takes so darn l... -
12:52 PM Feature #13286: webConfigurator does not redirect to requested page after login
- Some pages require parameters to load the right view, so stripping the parameters isn't helpful.
It is not going t... -
10:18 AM Feature #13286: webConfigurator does not redirect to requested page after login
- But, again- nothing prevents a logged in user from bookmarking a page or recalling one from history that actions some...
-
10:15 AM Feature #13286: webConfigurator does not redirect to requested page after login
- Doesn't have to be an attack, they could also do it unintentionally by bookmarking or hitting a page from their histo...
-
10:07 AM Feature #13286: webConfigurator does not redirect to requested page after login
- Not sure I follow how this makes it any less secure than it already is. If a user is logged in already, they can stil...
-
08:49 AM Feature #13286 (Rejected): webConfigurator does not redirect to requested page after login
- This is done on purpose for security reasons. Until the entire GUI is purged of any page that takes action on GET, th...
-
08:34 AM Feature #13286: webConfigurator does not redirect to requested page after login
- PR: https://github.com/pfsense/pfsense/pull/4599
-
08:33 AM Feature #13286 (Rejected): webConfigurator does not redirect to requested page after login
- Something that has bugged me for a while now is that if you are logged out of pfSense, and request a "deep" page e.g....
-
10:46 AM Bug #13289 (Resolved): Attempting to restore a 0 byte ``config.xml`` prints an error that the file cannot be read
- When attempting to restore an empty config.xml file (0 bytes) the GUI prints an error saying the file cannot be read ...
-
10:36 AM Bug #13288 (New): Encode FreeRADIUS Custom Options
- Currently, fields in the FreeRADIUS package such as @varusersreplyitemsadditionaloptions@ are not encoded in config.x...
-
10:33 AM Feature #13287 (New): Encode OpenVPN Custom Options
- The @custom_options@ field for OpenVPN configurations is currently not encoded. This should be encoded in base64.
-
07:46 AM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
- Both @auth-gen-token@ and @reneg-sec@ are useful in different ways, we should expose and (optionally) use both. Thoug...
-
07:21 AM Bug #13285: Uncaught ArgumentCountError to function openvpn_kill_client()
- Okay, thank you Jim for test and quick feedback.
-
07:20 AM Bug #13285 (Duplicate): Uncaught ArgumentCountError to function openvpn_kill_client()
- There are no errors when terminating clients on the status page or widget on 22.05/2.7.0 snapshots.
-
07:11 AM Bug #13285: Uncaught ArgumentCountError to function openvpn_kill_client()
- Sorry, found https://redmine.pfsense.org/issues/12817 but it not mention status page, not sure 12817 also resolve Ope...
-
07:09 AM Bug #13285 (Duplicate): Uncaught ArgumentCountError to function openvpn_kill_client()
- Killing session for user using OpenVPN Dashboard Widget or using OpenVPN Status page do not works.
On Widget next er...
06/19/2022
-
11:11 PM Bug #5413: Reduce disruptions when changing DNS records from DHCP leases in Unbound
- Hey Netgate - I get the feeling this affects far more customers than you think.
Can this be assigned to someone to a... -
09:34 PM Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes
- Just updated "PR #4595":https://github.com/pfsense/pfsense/pull/4595 with the new mitigation changes. Testers & feedb...
-
12:20 PM Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes
- It appears we are out of luck on having @devd@ fire events for IP address changes. There is a commit: https://reviews...
-
06:42 PM pfSense Plus Bug #13283 (Not a Bug): PBR forcing traffic out one WAN and back into another WAN with NAT Reflection Fails
- Tested this.
With that PBR in place, even traffic that is being NAT'ed from the NAT Reflection rule will be caught... -
05:53 PM Bug #13243 (Pull Request Review): OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
-
02:18 PM Bug #13243: OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
- This fixes the original issue:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/821
Reiner Keller wr... -
05:52 PM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
- It's better to implement @--auth-gen-token [lifetime]@
> --auth-gen-token [lifetime]
> After successful user/passwo... -
05:38 PM Feature #12982: Add support for RFC7499 in RADIUS library.
- So are you saying that pfsense/freeRadius will not be able to go more then 68 rules? any software you know would be ...
-
03:58 PM Feature #12982: Add support for RFC7499 in RADIUS library.
- I was able to replicate this with a simpler setup by adding a custom option to the @Additional RADIUS Attributes (REP...
-
12:10 PM pfSense Packages Feature #13284 (New): Option to define "Issuer" in OPT configuration.
- All QR codes are presently identifying as "FreeRADIUS(username).
Please add an optional variable in user->One-Time... -
11:11 AM Bug #13280: Entries for ``net.link.ifqmaxlen`` duplicated in ``/boot/loader.conf``
- I'm seeing this as well on a VM with @22.05.r.20220609.1919@....
06/18/2022
-
05:48 PM pfSense Plus Bug #13283 (Not a Bug): PBR forcing traffic out one WAN and back into another WAN with NAT Reflection Fails
- Assuming the following configuration:
2 WAN interfaces WAN1 and WAN2
One LAN interface with Host A and Host B.
H... -
02:34 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
- It seems this issue has gotten worse somewhere along the line similar to how others are describing it. Tables now lo...
-
02:25 PM Bug #13282 (Resolved): Alias content is sometimes incomplete if the firewall cannot resolve an FQDN in the alias
- If an invalid FQDN is present in an alias before a valid one, the entire table will be empty.
For an example, if...
06/17/2022
-
07:24 PM Bug #13281 (Duplicate): Crash Reporter
- Duplicate, and already fixed: #12817
-
06:49 PM Bug #13281 (Duplicate): Crash Reporter
- Crash report begins. Anonymous machine information:
amd64
12.3-STABLE
FreeBSD 12.3-STABLE plus-RELENG_22_01-n20... -
04:10 PM Revision 3f4ee315: Template the versions as well
-
03:31 PM Bug #13280 (Resolved): Entries for ``net.link.ifqmaxlen`` duplicated in ``/boot/loader.conf``
Using 22.05-RC 22.05.r.20220617.0613 Duplicate entries appear in /boot/loader.conf
Here are the contents of my loa...-
08:36 AM Bug #13243: OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
- Additional to this "informal" bug the ruleset given by Radius parameter isn't stored and when the renegiotion is done...
-
07:34 AM Bug #13278 (Needs Patch): OpenVPN dynamic gateway created incorrectly when not pulling routes or server pushes no routes
- We're aware of this, but it's an OpenVPN bug, not a bug in our code. As you see, the variables are unpopulated even w...
-
01:10 AM Bug #13278: OpenVPN dynamic gateway created incorrectly when not pulling routes or server pushes no routes
- This appears to be happening because OpenVPN doesn't populate these environment variables when either option is selec...
-
07:09 AM Bug #13279 (New): DHCP config override affects Gateway installation.
- If you check Configuration Override on the interface in the DHCP Client Configuration section, then open Status => In...
-
07:02 AM Regression #13274 (Resolved): OpenVPN override IPv4 tunnel network field changing value improperly
- Working as expected on the latest build. The exact tunnel network address and mask remain, and the resulting @ifconfi...
06/16/2022
-
11:54 PM Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes
- @dem I believe I'm facing this exact issue, take a look at https://forum.netgate.com/topic/172849/rtsold-not-running-...
-
10:31 PM Bug #13278 (Needs Patch): OpenVPN dynamic gateway created incorrectly when not pulling routes or server pushes no routes
- IF: I configure OpenVPN client and set the "Don't pull routes" check box
OR
IF: I include the advanced option: pull... -
09:30 PM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
- +1 Also having this problem : 2.6.0-RELEASE (amd64)
-
07:50 PM Bug #13277 (Duplicate): IGMP Proxy webConfigurator Page Always Produces Error
- Whether your IGMP Proxy settings are correct or not, there is always an error stating "There was a problem applying t...
-
07:48 PM Bug #13276 (New): IGMP Proxy Error Message for Logging Links to System Log Instead of Routing Log
- If you try to apply a setting that won't apply in IGMP Proxy, it will state "There was a problem applying the changes...
06/15/2022
-
03:16 PM Revision 230b2303: Fix OpenVPN override TN handling. Fixes #13274
-
10:42 AM pfSense Docs New Content #13211: OpenVPN DCO Documentation
- Updates: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/989cfa8946010d913fddeebc8d8fe740ba409390
-
10:25 AM Regression #13274 (Feedback): OpenVPN override IPv4 tunnel network field changing value improperly
- Applied in changeset commit:230b23033a898633681ef0dde4df8f63a2b7258c.
-
10:13 AM Regression #13274 (Resolved): OpenVPN override IPv4 tunnel network field changing value improperly
- For an override on a subnet topology VPN, the mask on the tunnel network in the override has to reflect the subnet ma...
-
03:44 AM Bug #11629: PPPoE WAN IP address different than expected when set static by ISP
- We've installed 22.05 on our Netgate 2100 appliance and it's still assigning the wrong IP address to the WAN interfac...
06/14/2022
-
01:14 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
- That one change looks to have solved the issue for me.
Testing in:... -
01:04 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
- Well... seeing that would have saved me a bunch of debugging...
-
12:41 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
- For reference, the redmine for that issue is here:
https://redmine.pfsense.org/issues/13156 -
12:19 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
- The issue apparently stems from the output of "pfctl -vvsr" changing in 22.05. Due to the change in output, pfBlockNG...
-
11:07 AM Bug #13273 (New): dhclient can use conflicting recorded leases
- dhclient will attempt to use a previously successful recorded lease if it cannot contact a dhcp server.
However it w... -
08:00 AM pfSense Packages Bug #13180: High CPU Utilization with pfb_filter since pfBlockerNG update to devel 3.1.0_4
- Looks like a duplicate or related to #13154
-
06:53 AM Regression #13265 (Resolved): Authentication using Voucher cause SQLite3 syntax error
- No errors on the latest snapshot. Voucher is accepted, no PHP error, voucher shows in active users and active voucher...
06/13/2022
-
08:16 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- Even with changing the rule to use the pfBlockerNG aliases directly, the issue persists - that is I'm not seeing any ...
-
06:16 PM pfSense Packages Bug #13154 (Confirmed): pfBlocker causing excessive CPU load
- Still seeing this in 2.7/22.05 so it seems unlikely to be a symptom of #12827 which is mostly fixed there.
The CPU... -
02:04 PM Revision 8ba70cfc: Set CP pipeno consistently when null. Fixes #13265
-
11:29 AM Feature #12982: Add support for RFC7499 in RADIUS library.
- Ok, so do you know roughly when "someone" can look at this issue further?
-
10:37 AM Feature #12982: Add support for RFC7499 in RADIUS library.
- I can't find where @[ciscoavpair]@ is being set in the code - the only reference I could find was in @pear-Auth_RADIU...
-
11:11 AM Bug #13262 (Resolved): File browser on ``diag_edit.php`` does not encode filenames before display
- Tested on...
-
10:27 AM Bug #13272 (Pull Request Review): Voucher CSV output has leading space before voucher code
- MR: https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/818
Diff attached for wider testing.
-
10:14 AM Bug #13272 (Resolved): Voucher CSV output has leading space before voucher code
- When downloading a CSV file for a voucher roll, each voucher has a leading space, so when copying and pasting it gets...
-
09:33 AM Regression #13265: Authentication using Voucher cause SQLite3 syntax error
- Merged into Plus and CE master branches and picked back into 22.05.
-
09:10 AM Regression #13265 (Feedback): Authentication using Voucher cause SQLite3 syntax error
- Applied in changeset commit:8ba70cfcf6c86db2c52577bf543a6b72fc2da9e7.
-
08:11 AM Regression #13265 (In Progress): Authentication using Voucher cause SQLite3 syntax error
- It should be noted that the authentication succeeds and the user can get out, is listed on the active vouchers tab, b...
-
08:23 AM pfSense Packages Bug #12992 (Resolved): error: nbproc is not supported any more since HAProxy 2.5
-
08:17 AM pfSense Docs New Content #13270: OpenVPN client gateway is incorrect when the server does not push routes
- This has always been the case with OpenVPN. It doesn't populate the environment variables because it doesn't think it...
-
05:06 AM pfSense Packages Bug #13271 (Bogus): I got 'The WireGuard service is not running.' after I upgraded my pfSense VM from 22.05.r.20220604.1403 -> 22.05.r.20220609.1919
- I've got this issue on one of my pfSense VM after upgrade from 22.05.r.20220604.1403 -> 22.05.r.20220609.1919 ('upgra...
06/12/2022
-
10:32 PM Todo #13268: Dynamically adjust the interface name maximum width in the login banner
- I wanted to auto size the columns based on the terminal width, but the shell doesn't seem to export the @$COLUMNS@ va...
-
05:09 PM Todo #13268 (Resolved): Dynamically adjust the interface name maximum width in the login banner
- small change to add some width and better align things if interface names are longer than just "WAN", "WAN2" etc.
... -
07:14 PM pfSense Docs New Content #13270 (Resolved): OpenVPN client gateway is incorrect when the server does not push routes
- If @IPv4 Local network(s)@ is empty on the server (and no custom options exist to push routes), the client @ovpn-link...
-
02:48 PM Bug #13267 (New): dpinger continues to run on OpenVPN gateway after OpenVPN service is stopped.
- Tested on @22.05.r.20220609.1919@.
# Configure OpenVPN client on pfSense
# Assign an interface to the OpenVPN cli... -
01:44 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
- * removed @case 111)@
* consistency of single/double quotes
* removed a couple of stray @;@ s -
01:21 PM Bug #12920: Gateway behavior differs when the gateway does not exist in the configuration
- Updating OP with new symptoms.
-
01:00 PM Revision f185e661: a few updates for the console menu
- add full pathnames to all binaries (before some were and some weren't)
less forking for process checking, instead of ... -
11:22 AM Feature #12973: Playback script to perform a configuration upgrade on an arbitrary ``config.xml`` file
- Just noting for anyone looking, the script is named @upgradeconfig@ not @updateconfig@ as in Chris' OP.
-
11:14 AM pfSense Plus Bug #13074: AES-GCM with SafeXcel on Netgate 2100 causes MBUF overload
- I believe I have hit this as well, 2100 to 7100 GCM tunnel. Is there an upstream FreeBSD bugreport? I believe the fac...
-
11:11 AM Bug #13252: reduce frequency of php-fpm socket connection attempts from check_reload_status
- I may have also experienced this on an SG-2100 yesterday. Upgraded from 21.05.1 to 22.05-RC.
After the upgrade, CP... -
08:45 AM pfSense Packages Bug #12992: error: nbproc is not supported any more since HAProxy 2.5
- This should be closed since it's been merged
-
12:04 AM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- Pushed more updates to my "PR #4595":https://github.com/pfsense/pfsense/pull/4595 (see over there for details).
I...
06/11/2022
-
07:01 PM pfSense Plus Bug #13206: SG-3100 LED GPIO hangs
- Daniel Subert wrote in #note-2:
> Hi Jim,
>
> Thanks for the update.
>
> As this issue is already being tracked int... -
06:45 PM Revision 08e9bcfd: add waning infobox if duplicate IP is entered in DHCP staticmaps
-
05:43 PM Regression #13265: Authentication using Voucher cause SQLite3 syntax error
- Here is the crash report from my firewall:
Crash report begins. Anonymous machine information:
amd64
12.3-STA... -
05:41 PM Regression #13265: Authentication using Voucher cause SQLite3 syntax error
- I can confirm this issue is present in the RC3 build of 22.05.
-
05:08 AM Regression #13265 (Resolved): Authentication using Voucher cause SQLite3 syntax error
- Errors:
Crash report begins. Anonymous machine information:
amd64
12.3-STABLE
FreeBSD 12.3-STABLE plus-RELEN... -
05:43 PM Revision b707f4d8: fix log spew when deleting static DHCP maps not in arp table, redmine #13263
-
04:51 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
- Looks good to me.
-
01:50 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
- I pushed a revised version, looks like this now
!clipboard-202206111450-srubn.png!
-
02:17 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- BBcan177 . wrote in #note-3:
> There seems to have been a change in the pfctl -vvsr output.
>
> The patch below seem... -
09:11 AM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- Is there a particular reason for that? I'm using a custom alias to keep rule management easier, and to avoid filter l...
-
09:02 AM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- Marcos Mendoza wrote in #note-7:
> > @256 block drop in log quick on ixv5 inet from any to <h_blocklist:19320> label...
06/10/2022
-
10:47 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- > @256 block drop in log quick on ixv5 inet from any to <h_blocklist:19320> label "USER_RULE: pfb_blocklist" label "i...
-
07:49 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- Marcos Mendoza wrote in #note-4:
> Tested change on @22.05@ RC with pfBlockerNG-devel @3.1.0_4@; floating block rule... -
04:29 PM Feature #13264 (New): IPSec Phase2 select multiple PFS key groups
- A user can currently select multiple IPSec encryption and hash algorithms, so it would make sense to add the ability ...
-
12:56 PM Revision 1b5919c7: Encode filename browser.php. Fixes #13262
-
11:36 AM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- I've been running with the PR above for 2 days now, it's survived multiple reboots, and unplug/replug of the secondar...
-
11:18 AM Todo #13263: Reduce log spam when deleting a static DHCP entry
- I made and tested this small patch: https://github.com/pfsense/pfsense/pull/4597
-
10:55 AM Todo #13263 (Resolved): Reduce log spam when deleting a static DHCP entry
- This is not a huge priority, but when deleting static DHCP mappings for devices that are offline / not on network and...
-
10:18 AM Bug #13258 (Pull Request Review): Hidden menu option ``100`` incorrectly handles HTTPS detection
-
08:05 AM Bug #13262 (Feedback): File browser on ``diag_edit.php`` does not encode filenames before display
- Applied in changeset commit:1b5919c769ba736b44819f71ee1ddce06e2a50c5.
-
07:56 AM Bug #13262 (Resolved): File browser on ``diag_edit.php`` does not encode filenames before display
- The file browser on @diag_edit.php@ does not encode filenames before display.
A user who can create files with arb... -
03:39 AM pfSense Packages Bug #13261 (Resolved): Input validation rejects empty ``sudo`` command list, but GUI text says it can be empty
- The help text says, " By default the command is "ALL" meaning the user can run any commands. Leaving the commands fi...
06/09/2022
-
11:20 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- The patch works for me on LAN and WAN rules on 22.05 RC using pfBlockerNG-devel 3.1.0_4. I don't have floating rules ...
-
11:08 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- Tested change on @22.05@ RC with pfBlockerNG-devel @3.1.0_4@; floating block rule on tagged traffic with description ...
-
09:58 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- There seems to have been a change in the pfctl -vvsr output.
The patch below seems to fix the issue, but would be ... -
02:51 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
- Ok I updated the PR to bring back the hidden option 100 / links browser. I think this is good. Unfortunately when I t...
-
01:31 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
- I haven't used @links@ against in the GUI in quite some time so I'm not sure if it still works. If it does we may as ...
-
01:28 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
- PR: https://github.com/pfsense/pfsense/pull/4596
-
11:44 AM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
- I can't think of any benefit from fixing it; better to remove it.
-
02:07 PM Feature #10446: VIP address is not shown in firewall rules
- Marcos Mendoza wrote in #note-5:
> Better to stick with using aliases. VIPs are more for service bindings.
This wil... -
11:38 AM Feature #10446: VIP address is not shown in firewall rules
- Silmor Senedlen wrote in #note-4:
> Silmor Senedlen wrote in #note-2:
> > I think it would be nice to be able to ... -
02:04 PM Feature #13260 (New): Add support for OpenVPN static-challenge
- When using Multi Factor authentication most OpenVPN clients offer a static-challenge option to make the client ask fo...
-
01:32 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
- I wanted to make the warning display in a "Yellow Box" too but I looked through the code and couldn't see an easy way...
-
12:41 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
- I don't think we should change the default behavior/add extra steps to reach the current behavior.
Something that ... -
12:36 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
- Thank you for the contributions!
In general, it's best to avoid first/second person perspective. A yellowish warni... -
07:07 AM Regression #11570 (Pull Request Review): Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
-
01:42 AM pfSense Packages Bug #12765 (Resolved): AutoConfigBackup should ignore Lightsquid/lightparser cron changes
- I tested with Lightsquid version 3.0.6_9.
It works fine.
I am marking this ticket resolved.
06/08/2022
-
11:17 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- I submitted a PR: https://github.com/pfsense/pfsense/pull/4595 that may help some of the cases being hit here.
-
05:02 PM pfSense Packages Bug #13259 (Not a Bug): Reply-to rules are not created with wireguard 0.1.6_1
-
04:57 PM pfSense Packages Bug #13259: Reply-to rules are not created with wireguard 0.1.6_1
- Sorry, stupid mistake on my side, it is required to set an upstream gateway on the interface config in order for the ...
-
04:53 PM pfSense Packages Bug #13259 (Not a Bug): Reply-to rules are not created with wireguard 0.1.6_1
- Hello,
I have noticed that reply-to rules are not created for rules in a wireguard interface even if it is assigne... -
03:33 PM Feature #10446: VIP address is not shown in firewall rules
- Silmor Senedlen wrote in #note-2:
> I think it would be nice to be able to select VIP address from list(which autom... -
01:35 PM pfSense Packages Bug #12808 (Resolved): Wireguard Gateways disabled when Wireguard Service is Manually Restarted
-
10:02 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
- Cherry picked this commit to RELENG_2_6_0 ports tree. Look for a package update.
Edit: v0.1.6_2 is available in CE 2... -
09:31 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
- → luckman212 wrote in #note-13:
> @Valmor if you add the System Patches package and then add a patch using this url:... -
07:54 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
- @Valmor if you add the System Patches package and then add a patch using this url:
https://github.com/theonemcdona... -
07:46 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
- I have similar issue on pfSense 2.6.0-RELEASE.
Configured WireGuard tunnel and set a static route.
After reboot of ... -
12:40 PM pfSense Packages Bug #13050 (Resolved): ACME update EasyDNS inline api sign-up link
- It looks fine on Acme package version 0.7.1_1.
I am marking this ticket resolved. -
12:04 PM Bug #13258 (Resolved): Hidden menu option ``100`` incorrectly handles HTTPS detection
- I was poking around in @/etc/rc.initial@ to try to fix something else and I noticed a hidden menu item 100
This op... -
10:38 AM Bug #13257: Exporting a PKCS#12 file from the certificate manager does not use the intended encryption algorithm
- See also: #13255
-
10:35 AM Bug #13257 (Resolved): Exporting a PKCS#12 file from the certificate manager does not use the intended encryption algorithm
- In source:src/usr/local/www/system_certmanager.php#L198 or thereabouts it sets a parameter @encrypt_key_cipher@ inten...
-
09:54 AM Feature #13256 (Resolved): Better handling of duplicate IP addresses in static DHCP assignments
- summary:
In 2018 code that prevented duplicate IPs from being used as static DHCP mappings was removed. There are ... -
09:15 AM Bug #13088: Rapidly clicking certain options on OpenVPN Client Overrides can cause hide/show field behavior to invert
- I replicated the issue with inverted results when repeating clicks too quickly on 22.05.r.20220604.1403.
After app... -
08:52 AM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
- I reproduced the issue on 22.01 and 22.05.r.20220604.1403 with the same logs.
-
08:36 AM pfSense Packages Todo #13255 (Resolved): Set PKCS#12 algorithm when exporting OpenVPN ZIP or Windows bundles
- Currently when crafting a PKCS#12 archive the OpenVPN Client Export package does not set a specific encryption algori...
-
07:48 AM Bug #13254 (Resolved): DNS resolver does not update its configuration or reload during link down events
- How to reproduce:
1) Configure the interface with Static IPv4
2) Select this interface in the "Network Interfaces...
06/07/2022
-
08:55 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- Tested on 22.05 RC.
I was not able to replicate this initially with WAN1 as DHCP and WAN2 as static. After testing a... -
10:00 AM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- I experienced this this morning, on 22.05.b.20220531.0600
- dpinger showed my DHCP6 gateway as "down"
- I ran @pgre... -
01:04 PM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
- +1 Having this issue since 16th May on two separate boxes CE. Upgraded to 2.6 and still the same. switch to DynDns an...
-
08:50 AM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
- +1 Also having this problem
-
12:25 AM pfSense Packages Bug #10436: softflowd no longer sends flow data after upgrade (v0.9.9_1 -> v1.0.0)
- I'm starting down a path that involves softflowd. Does anyone know if this issue persists with the latest snaps?
06/06/2022
-
11:17 PM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
- any updates on this? I am getting the same error too
-
06:55 PM pfSense Packages Feature #12963: Run nmap scans in the background
- I can't think of a privacy issue for either - both locations are readable by everyone. The Packet Capture page is in ...
-
02:55 PM pfSense Packages Feature #12963: Run nmap scans in the background
- Marcos Mendoza wrote in #note-24:
> Looks good from the testing I've done. Only suggestion I have is that the result... -
02:58 PM Bug #13253 (Resolved): ``dhcp6c`` is not restarted when applying settings when multiple WANs are configured for DHCP6
- After #6880 it seems that when applying settings on multiple WANs, @dhcp6c@ is not restarted so the new configuration...
-
02:55 PM Bug #13061 (Resolved): Gateway events for IPv6 affect IPv4 OpenVPN instances and vice versa
- Seems to be doing the right thing. IPv6 OpenVPN tunnel kept going when the IPv4 gateway went down and back up. We can...
-
02:35 PM Bug #12733 (Resolved): Value of ``net.inet.ip.dummynet.*`` OIDs in ``sysctl`` are ignored
- The code for @dummynet_load_module()@ in source:src/etc/inc/util.inc#L3937 ensures the module is loaded before popula...
-
01:06 PM Bug #13252 (New): reduce frequency of php-fpm socket connection attempts from check_reload_status
- When troubleshooting an issue, I discovered that my system logs were rotating every couple of minutes, due to many of...
-
12:45 PM Bug #13251: pfTop bugs - backspace key vs CTRL_H, states column, rnr not functional
- Ok, fair enough but I do wonder - does backspace work for _anyone_ in this case? Because it appears undefined or at l...
-
12:37 PM Bug #13251 (Not a Bug): pfTop bugs - backspace key vs CTRL_H, states column, rnr not functional
- backspace vs ^H is almost always a terminal issue with your client and what it sends. Some things send ^H for backspa...
-
12:32 PM Bug #13251 (Not a Bug): pfTop bugs - backspace key vs CTRL_H, states column, rnr not functional
- I am not 100% sure but I believe there are bugs in the currently bundled version of pfTop. I opened a thread about th...
-
07:32 AM Todo #13250 (Resolved): Clean up DHCP Server option language
- Several options on the page have awkward or inconsistent wording
* "Denied clients will be ignored rather than rej... -
07:03 AM Bug #12878 (Incomplete): Traffic shaping by interface, route queue bandwidth inbound, out by a large factor.
-
07:02 AM Bug #13249: Running playback comands multiple times results in PHP error
- That is known and expected, they aren't designed to run more than once in the same session the way you are doing it. ...
-
05:41 AM Bug #12645: ``filterdns`` does not monitor remote IPsec gateways for IPv6 address changes
- It's under IKE Endpoint Configuration ----> Remote Gateway (IPV6), to check if FQDN for AAAA record can be used to es...
-
04:17 AM Bug #12645 (Resolved): ``filterdns`` does not monitor remote IPsec gateways for IPv6 address changes
- Tested on 22.05-RC (built on Sat Jun 04 14:22:59 UTC 2022)
I'm not sure what to test here but there is no *add_hos...
06/05/2022
-
08:10 PM Bug #13249 (New): Running playback comands multiple times results in PHP error
- Using the console, enter option 12 then run @playback svc restart unbound@ twice. On the second run, the following is...
-
07:38 PM Regression #13248 (New): IPv6 Router Advertisements runs when config.xml does not contain an entry for the interface
- After installing @22.05.b.20220531.0600@, I noticed that the @System / Routing@ logs showed the following:
* @2001... -
07:09 PM pfSense Packages Bug #13247 (Confirmed): Open-VM-Tools service actions do not work
- Installing the package @Open-VM-Tools@ creates two entries under @Status / Services@: @vmware-guestid@ and @vmware-km...
-
06:51 PM pfSense Packages Feature #13246 (New): iperf3 service controls do not work
- After installing the @iperf3@ package, an entry is created under @Status / Services@ which includes @Start@, @Stop@, ...
-
06:17 PM pfSense Packages Feature #12963: Run nmap scans in the background
- Looks good from the testing I've done. Only suggestion I have is that the results file may be best placed in @/tmp@.
-
04:10 PM pfSense Plus Bug #12974: Typing anything into 1100/2100 recovery installer causes process to stop
- Marcos Mendoza wrote in #note-6:
> The wording has been addressed with NG 7431. This issue can be left open to track... -
08:23 AM Regression #12821 (Confirmed): Intel e1000 driver (``em``, ``igb``) cannot pass packets tagged with VLAN ``0``
06/04/2022
-
08:15 PM Regression #12821: Intel e1000 driver (``em``, ``igb``) cannot pass packets tagged with VLAN ``0``
- Tested ix interfaces as well. They are not subject to this bug. Based on the fact that Broadcom NICs and Intel ix/i...
-
07:54 PM Regression #11545: Primary interface address is not always used when VIPs are present
- This bug definitely doesn't just happen with PPPoE interfaces. It is also not consistent and seems to be an "orderin...
-
07:50 PM Bug #12878: Traffic shaping by interface, route queue bandwidth inbound, out by a large factor.
- Unless further feedback is provided on this redmine, it can likely be closed due to lack of information in Rejected s...
-
09:21 AM Feature #13245 (Resolved): Type column on Alias lists
- Small QoL addition that adds a Type column to the Alias list views. I was recently cleaning up my aliases and being a...
06/03/2022
-
01:50 PM Bug #12847: On startup "No routing address with matching address" might appear
- Replicated the issue on:...
-
01:08 PM Bug #12847 (Resolved): On startup "No routing address with matching address" might appear
- No sign of these errors on anything I'm seeing here, static or dynamic, with or without working IPv6 when configured ...
-
01:28 PM Bug #11692 (Resolved): ``fixup_default_gateway()`` should not remove a default gateway managed by a dynamic routing daemon
-
01:23 PM Bug #12606 (Resolved): ``devd`` is not configured to act on USB interface attach/detach events
- devd hooks are in place and fire as expected when plugging/unplugging a USB Ethernet dongle
-
01:09 PM Feature #13070 (Resolved): Allow auto prefix with manual prefix-length in NPt
-
01:01 PM Bug #13241: syslogd doesn't honor the Timezone set in the System/General Setup
- Here is the feature request:
https://redmine.pfsense.org/issues/13244 -
12:54 PM Bug #13241: syslogd doesn't honor the Timezone set in the System/General Setup
- Yeah right. It works fine after a reboot. I somehow omitted that part in the docs. Thanks!
However, adding the no... -
07:10 AM Bug #13241 (Not a Bug): syslogd doesn't honor the Timezone set in the System/General Setup
- That isn't a bug. Each daemon picks up the time zone change when it starts, that isn't up to @syslogd@. To fully acti...
-
03:43 AM Bug #13241: syslogd doesn't honor the Timezone set in the System/General Setup
- I am getting the same results on:...
-
03:08 AM Bug #13241 (Not a Bug): syslogd doesn't honor the Timezone set in the System/General Setup
- It shows the wrong time only in the Status/System Logs/System/General section.
I chose Europe/Belgrade Timezone. ... -
01:00 PM Bug #13133 (Resolved): OpenVPN ``client-connect`` file contains ``topology``
- Seems to be OK. No error in the client log now, client still gets a proper address using the correct topology
-
01:00 PM Feature #13244 (New): Add help text under Timezone settings in the GUI
- Adding the note from the docs in the GUI below the Timezone dropdown menu will be helpful....
-
12:57 PM Bug #12628 (Resolved): OpenVPN re-synchronization also synchronizes override entries unnecessarily in some cases
- It's not clear from the original description which specific cases were not necessary, but I'm seeing the CSC files up...
-
12:46 PM Bug #13145 (Resolved): Per-user ``route`` files are not removed from ``/tmp`` when they are no longer needed
- Routes file is no longer left behind.
-
12:42 PM Feature #12407 (Resolved): Use deferred client connections in OpenVPN
- This has been back in place for a while. No problems with auth that I've seen, local or RADIUS.
-
12:33 PM Bug #4287: Wrong display for ppp in Interfaces page
- Hi Marco,
I have the same problem like you, did you find a solution for it?
Karlo -
12:28 PM Bug #13243 (Resolved): OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
- When a user authenticates to an OpenVPN instance the OpenVPN status shows an info "i" icon in the actions to display ...
-
12:08 PM Bug #13099 (Resolved): Static routes to destinations at L2TP clients are not re-added after a client reconnects
- Looks good. Following the procedure above, the route goes away when the client disconnects and comes back when the cl...
-
11:22 AM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
- follow-up issue: https://redmine.pfsense.org/issues/13242
-
09:32 AM Feature #12687 (Resolved): Option to disable auto-addition of static routes for ``dpinger``
- This works OK as-is. As stated in the comments above it doesn't remove the routes, but the user can reboot or remove ...
-
07:51 AM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
- What's in now will have to be considered on its own -- any refinements should be done on a separate Redmine issue.
-
11:20 AM Feature #13242 (Pull Request Review): Enhancements to static route creation/deletion for dpinger monitor IPs
- related redmine: #12687 — (breaking out as requested by @jimp to a separate issue)
Th PR below adds some improveme... -
11:11 AM Todo #12619 (Resolved): Restart services on interface changes
- In general this seems to be working as expected from what I can see.
If there are issues with individual services ... -
10:51 AM Regression #12582 (Resolved): RADVD can be started on both HA nodes when configured with an IPv6 link-local address
- Seems to be OK. With radvd set to use an LL VIP I still only see radvd running on the node with master status on its ...
-
10:43 AM Regression #12961 (Resolved): CARP event storm when leaving persistent CARP maintenance mode
- I'm only seeing one event per VIP now as expected.
-
10:32 AM Bug #13076 (New): Marking a gateway as down does not affect IPsec entries using gateway groups
- This still isn't working properly. I marked a gateway as down and it has no effect on IPsec. The dynamic DNS entry ch...
-
07:41 AM Bug #12590 (Resolved): Dynamic DNS custom IPv6 service fails on 6rd tunnels
-
07:40 AM Bug #13097 (Resolved): PHP error when upgrading from before configuration revision 21.6, ``ipsec_create_vtimap()`` is undefined
- No PHP error on upgrade when coming from <21.6 now. Closing.
-
07:13 AM Bug #12612 (New): DNS Resolver is restarted during every ``rc.newwanip`` event even for interfaces not used in the resolver
- The code looks like it should be right but we can debug it for the next release, it's not a blocker for 22.05.
-
01:55 AM Bug #12612: DNS Resolver is restarted during every ``rc.newwanip`` event even for interfaces not used in the resolver
- Tested...
-
02:41 AM Bug #12609 (Resolved): IGMP Proxy server is restarted during every ``rc.newwanip`` event
- Tested...
06/02/2022
-
10:38 PM Bug #13127 (Resolved): DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
- I've tested again on a fresh image and I cannot get it to repeat the blank interface name, the interface name changes...
-
03:30 PM Bug #13127: DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
- It's just blank, the table data for the cell is empty. I'll get a chance to have a further look at it in the next few...
-
03:24 PM Bug #13127: DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
- @rlinnemann : Can you send a screenshot of that rendered page with the blank ifname? I looked again at the code and i...
-
10:33 PM Bug #13048 (Resolved): Explicit PPPoE disconnect of a WAN Gateway Group member may not restore a default route
- Default gateway switches away and back as expected when disconnecting and reconnecting.
-
10:06 PM Bug #11629 (Resolved): PPPoE WAN IP address different than expected when set static by ISP
- Following the stated procedure I can't reproduce the problem on 22.05 now. I see the interface go down, and when it c...
-
09:52 PM Bug #12975 (Resolved): IKEv2 Mobile IPsec clients do not receive ``INTERNAL_DNS_DOMAIN`` (value ``25``) attribute
- The new attribute is present in the configuration, the rest is up to clients at this point.
-
09:42 PM Bug #11984 (Resolved): Automatic Outbound NAT mode can create incorrect rules in some cases
- I can't find any way to reproduce the original issue here, but the code in the change is solid, the scope is removed ...
-
09:41 PM Bug #13230: Floating rules on VPN interfaces
- That’ll be my issue then, thanks. I did wonder if that was the case.
-
09:31 PM Bug #13240 (Resolved): User is forced to pick an NPt destination IPv6 prefix length even when choosing a drop-down entry which contains a defined prefix length
- Following on from #4881
There are two minor issues in the NPt GUI when dealing with dynamic choices:
1. When t... -
09:27 PM Feature #4881 (Resolved): Allow NPt to use dynamic IPv6 networks
-
09:27 PM Feature #4881: Allow NPt to use dynamic IPv6 networks
- Two minor issues:
1. When there are multiple available entries the list isn't cleared and each line also contains ... -
09:10 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- I saw this bug on 22.05-Devel and now on 22.05-Beta. The rules are working, but are not logged.
-
08:55 PM Regression #12862 (Resolved): Some ``sysctl`` OIDs in ``loader.conf.local`` are silently removed
- The value of @net.link.ifqmaxlen@ in @loader.conf.local@ is retained across multiple reboots on 22.05
-
08:16 PM Regression #13162 (Resolved): Upgrade does not work when using only IPv6 DNS servers
- Seems to be fixed. On 22.01 if I set only IPv6 DNS and tell the GUI to only use remote DNS, the update check does fai...
-
08:10 PM Bug #12721 (Resolved): IPv6 gateway group using link local addresses incorrectly logs a gateway change because it not including interface scope properly
- Seems to be OK on the latest snapshot. I can't reproduce the problem there. Failover group with two IPv6 tiers, both ...
-
08:02 PM Bug #6880 (Resolved): Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
- This looks excellent on the latest snapshot.
On 22.01 each interface has a separate configuration and only one of ... -
06:17 PM Bug #12611 (Resolved): SNMP daemon is restarted during every ``rc.newwanip`` event
-
03:24 PM Bug #12527 (Resolved): DHCPv6 server does not skip interfaces configured with invalid ranges
- Works on latest internal test snapshot.
-
09:13 AM Bug #12527: DHCPv6 server does not skip interfaces configured with invalid ranges
- The patch did the job.
Tested:... -
08:51 AM Bug #12527: DHCPv6 server does not skip interfaces configured with invalid ranges
- If nobody else offers feedback before 22.05 releases, this is OK to close. The change appears to be solid but I'd lik...
-
08:38 AM Bug #12527: DHCPv6 server does not skip interfaces configured with invalid ranges
- Patch was tested successfully by multiple people internally, including several dynamic and static systems in my lab. ...
-
08:35 AM Bug #12527 (Feedback): DHCPv6 server does not skip interfaces configured with invalid ranges
- Applied in changeset commit:3dc73d391eff61f490798696af78a4cdbeeeaf18.
-
08:29 AM Bug #12527: DHCPv6 server does not skip interfaces configured with invalid ranges
- MR: https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/814
Patch is attached and fixes it for me here in ... -
07:56 AM Bug #12527 (Assigned): DHCPv6 server does not skip interfaces configured with invalid ranges
- This caused a regression where it's skipping dhcp6 for delegated prefixes.
-
03:23 PM Regression #13238 (Resolved): WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
- Works on latest internal test snapshot.
-
08:58 AM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
- I have picked this back into the 22.05 branch and it will be included in the release.
-
07:56 AM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
- The dhcpd problem appears to be a regression from #12527 and is unrelated to this.
-
03:07 PM Bug #13139 (Resolved): Stale ``sshdkeys.dirty`` lock file prevents generating SSH server keys
-
02:07 PM Revision b79dff5b: Disable distclean to prevent removing distfiles that are still in use
-
02:02 PM Bug #12613 (Resolved): DNS Resolver does not restart during link up/down events on a static IP address interface
- Based on the original problem description and steps to reproduce it sounds like this specific request is fixed. For t...
-
01:56 PM Bug #12613: DNS Resolver does not restart during link up/down events on a static IP address interface
- Tested...
-
01:08 PM Revision 3dc73d39: dhcp6 range check/tracked prefix. Fixes #12527
-
11:22 AM Regression #12949 (Resolved): The ruleset is not regenerated after assigning an interface
- Confirmed this no longer happens in current 2.7 snapshots. The running ruleset is updated immediately when re-assigni...
-
09:34 AM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
- @Flole please test with the updated version of this patch if you have the time: https://github.com/pfsense/pfsense/pu...
-
07:13 AM Bug #13239 (Duplicate): ipv6 based ipsec vpn tunnel bug found with fqdn remote host
- Appears to be the same as #12645 which is already fixed in 22.05/2.7.0 snapshots.
-
03:14 AM Bug #13239: ipv6 based ipsec vpn tunnel bug found with fqdn remote host
- https://forum.netgate.com/topic/171869/ipsec-vpn-bug-found?_=1654156661373
-
03:13 AM Bug #13239 (Duplicate): ipv6 based ipsec vpn tunnel bug found with fqdn remote host
- Hi I would to report the bug, related to ipsec vpn
In the settings of Phase 1 (ike v2)
under:
IKE Endpoint...
06/01/2022
-
10:29 PM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
- Jim Pingle wrote in #note-3:
> I think I've spotted the problem here. In #6880 the scripts were changed around a bit... -
08:35 AM Regression #13238 (Feedback): WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
- Applied in changeset commit:7b9fdf030fbe4e1d5051bf6d8962f365aeb1b69a.
-
08:22 AM Regression #13238 (Pull Request Review): WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
- I think I've spotted the problem here. In #6880 the scripts were changed around a bit and the withoutra path isn't ge...
-
12:14 AM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
- Hayden Hill wrote in #note-1:
> I am having the same issue in the development versions of 22.05. "Do not wait for RA... -
10:03 PM Revision 90c1f864: Switch to hping3 since hping has been EoLed and removed upstream
-
07:10 PM Bug #12003 (Resolved): Pie and ``fq_pie`` are missing options and do not handle floating point number input correctly
-
06:35 PM Revision 4d287e88: Merge pull request #4590 from luckman212/fix-omission-of-pr4551
- 06:11 PM Revision 9c822e62: Merge branch 'pfsense:master' into fix-omission-of-pr4551
-
05:54 PM Revision 44132b27: oops. forgot to actually process the dpinger_dont_add_static_routes flag
-
04:41 PM Bug #12986 (Resolved): DHCP network boot filename can be incorrectly placed in DHCP Pool Options
-
01:46 PM Feature #12687 (Feedback): Option to disable auto-addition of static routes for ``dpinger``
-
01:37 PM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
- Needed one more fix: https://github.com/pfsense/pfsense/pull/4590
That may not make it into 22.05 at this point. I... -
01:18 PM Revision 7b9fdf03: Always use rstold script header. Fixes #13238
-
01:01 PM Bug #12095: Memory leak in pcscd
- Update: looks like the PCSC maintainer has fixed the mem leak: https://github.com/LudovicRousseau/PCSC/issues/55#issu...
-
01:01 PM Bug #12468: Stopping IPsec daemon on the Status / Services page lead to log files flooding if pcscd daemon is enabled
- Update: looks like the PCSC maintainer has fixed the mem leak: https://github.com/LudovicRousseau/PCSC/issues/55#issu...
-
11:20 AM Bug #13237: dhcp6c script cannot be executed safely
- I get it once every time after saving/applying WAN interface. When I looked at the code, the files get created before...
-
07:55 AM Bug #13237: dhcp6c script cannot be executed safely
- The real question here is why it works most of the time then suddenly fails. I'm guessing something is removing the f...
05/31/2022
-
09:01 PM Bug #13210: PPPoE server panics with multiple client connections
- https://github.com/pfsense/FreeBSD-src/commit/5e816cde27af3cd6e46ea0ffb2d167804899bebd
https://forum.netgate.com/top... -
05:50 PM Bug #13210 (Feedback): PPPoE server panics with multiple client connections
-
05:46 PM Bug #13210: PPPoE server panics with multiple client connections
- Pushed fixes:
> Author: Mateusz Guzik <mjg@netgate.com>
> Date: Tue May 31 22:43:37 2022 +0000
>
> pf: fix a... -
07:30 PM Bug #13127: DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
- Hmm weird, I didn't experience that on my systems. What's the name of your interface?
-
06:35 PM Bug #13127 (Assigned): DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
- When I test this, the interface name becomes an empty string.
-
06:12 PM Bug #13127 (Resolved): DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration
-
06:06 PM Feature #12982: Add support for RFC7499 in RADIUS library.
- Hello Marcos, after using your patch, I took the log as requested. It seems it loaded 63 rows and stopped.
-
01:34 PM Feature #12982: Add support for RFC7499 in RADIUS library.
- Hello Marcos, I sent you an email on the result, but It seems it is not outputing the information you need. Not sure...
-
05:56 PM Bug #13148 (Assigned): Traffic passed by Captive Portal cannot use limiter queues on other rules
- This appears to still be broken.
-
05:53 PM pfSense Docs Todo #13236: Document link speed limitations with igc and ix on 6100/4100
- Which makes this language on the pfSense interface config pages, though correct, probably in need of some adjustment ...
-
04:31 PM pfSense Docs Todo #13236: Document link speed limitations with igc and ix on 6100/4100
- It's been tested by a customer, along with SW and CL.
At best, the ix and igc ports on *both* the 6100 and 4100 wil... -
07:44 AM pfSense Docs Todo #13236: Document link speed limitations with igc and ix on 6100/4100
- Has that been tested and confirmed? I remember some discussion around that back when the driver was first brought in,...
-
05:34 PM Bug #12811 (New): Services are not restarted when PPP interfaces connect
-
05:31 PM Bug #13215 (Assigned): Allowed MAC/IP/Hostname traffic counts for authorized users
-
05:29 PM Bug #13215 (New): Allowed MAC/IP/Hostname traffic counts for authorized users
- The change here was backed out, so needs to be revisited next version
-
05:27 PM Regression #13193 (Resolved): Deleting a host entry fails to remove dummynet pipes
-
05:25 PM Bug #12998 (Resolved): Wireless interface WPA configuration fields are always visible
- Appears to be correct on current snapshot
-
05:19 PM Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
- I am having the same issue in the development versions of 22.05. "Do not wait for RA" seems to be the culprit as well.
-
05:07 PM Regression #13238 (Resolved): WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set
- My specific situation is the following:
ISP requires the following settings:
Request only an IPv6 prefix
Do no... -
05:19 PM Bug #13204 (Resolved): Captive Portal reserves four (instead of two) pipes for client
-
05:18 PM Bug #12649 (Closed): Allowed IP/Hostname "Direction" option is never used
-
05:14 PM Regression #12999 (Resolved): Duplicate wireless interfaces are created at boot
- No problem on current snapshot
-
05:12 PM Regression #12937 (Resolved): Traffic Shaper wizard can produce an invalid ruleset when configured with an IPv4 upstream SIP server
- Works now
-
05:08 PM Bug #11764: IPv6 link local gateway default status not indicated in GUI
- Jim Pingle wrote in #note-14:
> The problem here as exactly stated is solved. If we can reproduce a different (albei... -
04:45 PM Bug #11764: IPv6 link local gateway default status not indicated in GUI
- Hayden Hill wrote in #note-13:
> Hayden Hill wrote in #note-12:
> > I might be having the same issue here. 22.05/2.... -
03:17 PM Bug #11764 (Resolved): IPv6 link local gateway default status not indicated in GUI
- The problem here as exactly stated is solved. If we can reproduce a different (albeit similar) problem along a separa...
-
04:59 PM Bug #13004 (Resolved): ``write_rcfile()`` does not create ``rc_restart()`` entry
- Works now
-
04:58 PM Regression #13025 (Resolved): Some services won't start - wrong syntax in autogenerated rc.d scripts
- Works now
-
04:53 PM Bug #13092 (Resolved): PPPoE WANs fail to reconnect after parameter negotiation failure
-
03:39 PM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
- We have tested internally here and can't reproduce any problems with SHA384 or SHA512. In each case so long as both s...
-
08:00 AM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
- That isn't what the P2P limitation is. The GUI selection for "peer-to-peer SSL/TLS" is fine, it's OpenVPN's internal ...
-
03:38 PM Bug #13216 (Resolved): Switching nomacfilter option does not change autorized users rule format
-
03:33 PM Regression #13056 (Resolved): OpenVPN ``remote_cert_tls`` option does not behave correctly when enabled and later disabled
- Option toggles correctly now. I can enable it and the option goes into the config. Disable it and it comes out.
-
03:32 PM Bug #11941 (Resolved): Many ``exec()`` functions do not use full path to executable files
-
03:28 PM Bug #12141 (Resolved): Lack of DNS or Internet connectivity causes GUI to be slow
-
03:27 PM Feature #12267 (Resolved): OpenVPN option to limit concurrent connections per user
-
03:27 PM Bug #12332 (Resolved): OpenVPN does not clear old Cisco-AVPair anchor rules in some cases
-
03:25 PM Bug #12771 (Resolved): Automatic filter reload with OpenVPN client gateway uplink happens too soon or not at all
-
03:24 PM Regression #12884 (Resolved): OpenVPN status display for TAP mode services shows peer-to-peer instead of client list in certain cases
-
03:18 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- Sage Badolato wrote in #note-34:
> I cannot test 22.05, I'm on community edition.
You can try a recent 2.7.0 snap... -
03:01 PM Bug #12691 (Resolved): Support encrypted ``config.xml`` files when restoring during install
- Latest commit works well. I get the prompt for the password, I can enter the password and it successfully decrypts an...
-
01:08 PM Bug #12691 (Feedback): Support encrypted ``config.xml`` files when restoring during install
- MR merged.
-
01:04 PM Bug #12691 (Pull Request Review): Support encrypted ``config.xml`` files when restoring during install
- MR: https://gitlab.netgate.com/pfSense/FreeBSD-src/-/merge_requests/88
That MR has the proposed changes inside. -
12:56 PM Bug #12691: Support encrypted ``config.xml`` files when restoring during install
- Two problems here:
* It may not be reading the password properly. It would be better to use @dialog@ than a text p... -
11:12 AM Bug #12691 (Assigned): Support encrypted ``config.xml`` files when restoring during install
- Unfortunately, this does not look to be working for me.
This is what I get when I try to decrypt using the install... -
02:59 PM Bug #12672 (Resolved): GleSYS Dynamic DNS responses are not parsed properly
- No access to provider, no feedback. Closing.
-
02:58 PM Feature #12744 (Resolved): IPv6 support for DNSimple Dynamic DNS
- No access to provider, no feedback. Closing.
-
02:58 PM Feature #12752 (Resolved): Support wildcard Dynamic DNS records on DigitalOcean
- No access to provider, no feedback. Closing.
-
02:58 PM Bug #12754 (Resolved): Google Domains Dynamic DNS responses are not parsed properly
-
02:58 PM Bug #12761 (Resolved): Input validation prevents configuring wildcard Dynamic DNS records on Google Domains
-
02:49 PM Bug #12721: IPv6 gateway group using link local addresses incorrectly logs a gateway change because it not including interface scope properly
- How to verify that this change is working:
1) Create gateway group "WAN_IPv6" which contains:
Tier 1: WAN1 (m... -
02:31 PM Bug #12721: IPv6 gateway group using link local addresses incorrectly logs a gateway change because it not including interface scope properly
- It lacked an assignee before, mostly it's for tracking who fixed the issue.
Ideally we'd like feedback from someon... -
02:28 PM Bug #12721: IPv6 gateway group using link local addresses incorrectly logs a gateway change because it not including interface scope properly
- I see you have assigned this back to me, but I am unsure of what further action is needed on my part. I can verify a...
-
02:12 PM Bug #12749 (Resolved): Uninitialized array in ``array_remove_duplicates()``
-
02:10 PM Todo #13100 (Resolved): Transition Captive Portal from IPFW to PF
- The work here is complete, any issues we find can be raised separately.
-
02:09 PM Bug #12801 (Resolved): User password hashes pseudo-random number generator may return insecure salt value
- The correct function is in place now and working properly.
-
02:06 PM Bug #13116 (Resolved): OpenVPN client ``tls-client``/``client`` configuration directive not handled properly
- This appears to be correct and consistent now.
-
02:00 PM Regression #13155 (Resolved): Rule labels in pftop output are not correct
- All good now. Proper labels are shown in pftop label view and it didn't negatively impact the firewall log view.
-
01:55 PM Todo #13149 (Resolved): Remove unnecessary trailing colon after Outbound NAT "Automatic Rules" section header
- The trailing colon is gone.
-
01:55 PM Todo #13129 (Resolved): OpenVPN status page improvements
- The new changes are present and working well.
-
01:50 PM Todo #12701 (Resolved): Reorganize CARP status page
- Looks great now
-
01:49 PM Feature #12092 (Closed): Utilize new ``pfctl`` abilities to kill states
- This has been working well for a while now. Any issues we hit from here can be addressed separately.
-
01:48 PM Regression #13163 (Resolved): Incorrect variable in package error message results in "Array" being printed instead of package name
-
01:42 PM Regression #13178 (Resolved): Incorrect usage of DSCP hex value
- This is OK as-is for now. We could consider the other change as a separate request for the next release if needed.
-
01:28 PM Bug #9263 (Resolved): Incorrect ICMP reply when using limiters
- Assigning to Kristof since it was likely fixed along the way when moving dummynet and such info PF
-
01:19 PM Feature #12687 (Resolved): Option to disable auto-addition of static routes for ``dpinger``
- That would have to wait for the next release, make a new feature request issue with a link back to this one to track ...
-
12:46 PM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
- I have a new PR almost ready that dynamically adds/removes the static routes when the checkbox is changed without req...
-
12:04 PM Feature #12687: Option to disable auto-addition of static routes for ``dpinger``
- This tested OK to me. Note that I only tested the checkbox in on the gateway, since it looks like the other subjects ...
-
01:05 PM Regression #13142 (Resolved): PHP shell ``pfanchordrill`` script produces errors on captive portal tables
- The contents of nested captive portal anchors are now displayed as expected.
-
12:58 PM Bug #13237: dhcp6c script cannot be executed safely
- You're right, I misread it. It's likely what you're thinking.
-
12:42 PM Bug #13237: dhcp6c script cannot be executed safely
- Setuid on a shell script? That doesn't seem appropriate. And I don't think that lines up with the checks.
The checks... -
12:26 PM Bug #13237: dhcp6c script cannot be executed safely
- The checks done for this are
* no setuid
** setuid'ed execution not allowed
** lstat failed
* the file must be owned ... -
10:49 AM Bug #13237 (New): dhcp6c script cannot be executed safely
- *22.05 Plus Beta on system boot*
When the "Do not wait for a RA" option is selected on the WAN interface, /var/etc... -
12:23 PM Regression #13192 (Resolved): Default pipe rate limits are applied to allowed mac/ip/host entries
-
12:22 PM Regression #13191 (Resolved): Deleting a passthru mac entry fails to remove pf rules and dummynet pipes associated with the passthru mac
-
12:21 PM Bug #13169 (Resolved): captiveportal_ether_delete_entry() does not delete anchors/pipes
-
12:18 PM Regression #13147 (Resolved): Captive Portal: Idle timeout does not see activity
-
12:18 PM Feature #12945 (Resolved): Implement missing ipfw equivalents in libpfctl necessary for captiveportal
-
12:15 PM Regression #12834 (Resolved): Only TCP traffic is passed outbound through IPFW
- Closing, ipfw is out of the mix for 2.7.0/22.05
-
11:42 AM pfSense Docs Todo #12756: Add information on correct MTU to use with WireGuard
- https://lists.zx2c4.com/pipermail/wireguard/2017-December/002201.html...
-
07:58 AM pfSense Docs Todo #12756: Add information on correct MTU to use with WireGuard
- @viktor or @cmcdonald — What should the MTU be set to? 1420?
I recently spent a few hours troubleshooting a slow s... -
10:55 AM pfSense Docs New Content #13205: ZFS Boot Environment documentation
- Added docs for the new option to disable automatic BE creation during upgrade: https://gitlab.netgate.com/docs/pfSens...
-
10:37 AM Bug #13175: PHP error on MAC entry add/edit
- Use the revision ID linked in the comment after that.
https://github.com/pfsense/pfsense/commit/b7ddc1b810f16c827c... -
09:33 AM Bug #13175: PHP error on MAC entry add/edit
- Viktor Gurov wrote in #note-2:
> fix:
> https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/787
The link... -
07:55 AM Bug #13230 (Not a Bug): Floating rules on VPN interfaces
- From the general description it sounds like when using rules on assigned VPN interfaces you get reply-to so traffic r...
-
07:37 AM Bug #13235 (Not a Bug): URL in firewall rule hover does nothing
- It's listing the contents of the alias. As that is a URL type alias, that is the content of the alias.
Linking the... -
07:29 AM Bug #13231 (Not a Bug): OpenVPN custom options may fail after save/restore
- OpenVPN directives are to be separated by semicolons, not newlines. That's stated in the text above the box and in th...
-
07:20 AM Bug #13093 (In Progress): LDAP authentication fails with extended query and RFC2307 group lookups enabled
- OK, we'll nudge this forward for now and proceed once we have more detail.
-
02:13 AM pfSense Packages Feature #10818: UDP Broadcast Relay
- Hey guys thanks for the shout out, but I have NO clue how to make this a package.
All I was able to do was build a... -
02:02 AM pfSense Packages Feature #10818: UDP Broadcast Relay
- Thank you for the information.
Let's hope @Garth Kirkwood sees this then
05/30/2022
-
04:59 PM Bug #13093: LDAP authentication fails with extended query and RFC2307 group lookups enabled
- Extended query works.
RFC2307 groups work.
Authentication fails when both are enabled.
The site I'm testing ... -
04:57 PM Bug #13093: LDAP authentication fails with extended query and RFC2307 group lookups enabled
- I think this is probably still not right.
-
04:02 PM Bug #12923 (Resolved): DHCP "Ignore denied clients" option with MAC Deny list set causes DHCP server to not start
- Working correctly on...
-
03:54 PM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
- Thanks for pointing out the RA-only restriction. I see that stephenw10 has replied in the original forum string that...
-
09:32 AM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
- Try to reproduce it with OpenVPN Server in Remote Access mode, Peer-to-Peer is not supported - see https://redmine.pf...
-
12:28 PM pfSense Plus Bug #13074: AES-GCM with SafeXcel on Netgate 2100 causes MBUF overload
- I mean to say it's not a SafeXcel issue specifically. Thank you for confirming it's only on the 2100 (ARM) platform.
-
12:15 PM pfSense Plus Bug #13074: AES-GCM with SafeXcel on Netgate 2100 causes MBUF overload
- Marcos Mendoza wrote in #note-3:
> Note that the issue may not be specific to SafeXcel - e.g. it could happen with In... -
11:06 AM pfSense Plus Bug #13074: AES-GCM with SafeXcel on Netgate 2100 causes MBUF overload
- Note that the issue may not be specific to SafeXcel - e.g. it could happen with Intel QAT as well.
-
12:25 PM Feature #12982: Add support for RFC7499 in RADIUS library.
- The issue needs to be narrowed down further. Apply the following patch, reproduce the issue, then submit the /tmp/_DE...
-
10:56 AM pfSense Packages Regression #12140 (Closed): DNSBL https webserver not working
- Could not reproduce on 22.05 with pfBlockerNG-devel 3.1.0_4. The no logging of IP addresses has already been resolved...
-
10:40 AM pfSense Packages Feature #10242 (New): E2guardian Web filtering package
-
10:29 AM pfSense Packages Regression #12476 (Resolved): Suricata 6.0.3_3 Pass List ignores all single IPs
-
03:30 AM pfSense Packages Feature #11385 (Resolved): Add WireGuard tunneled networks to vpnaddresses list
- Tested on 22.01 and on 22.05-BETA (built on Fri May 27 06:21:09 UTC 2022)
When I created Pass List with 'VPN Addre... -
02:00 AM pfSense Packages Bug #11892 (Resolved): WireGuard: dpinger does not start correctly on a WireGuard gateway at boot
- Tested on 21.05_2, 22.01 and on 22.05-BETA (built on Fri May 27 06:21:09 UTC 2022)
I saw no issue with dpinger and...
05/29/2022
-
10:57 PM Feature #12982: Add support for RFC7499 in RADIUS library.
- Any new update?
-
08:31 PM Bug #13230 (Feedback): Floating rules on VPN interfaces
- More information is needed to understand the issue. Is this occurring with an OpenVPN Server or Client configuration ...
-
07:56 PM pfSense Plus Bug #13233: OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
- Hopefully this will be reproducible:
1. Set up Non-DCO OpenVPN server and client with follwing config options: pe... -
06:31 PM pfSense Plus Bug #13233 (Feedback): OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
- Tested on @22.05.b.20220524.0600@.
I was unable to reproduce this issue using OpenVPN RA TLS+User auth. Taking an ... -
07:00 PM Bug #12878 (Feedback): Traffic shaping by interface, route queue bandwidth inbound, out by a large factor.
- Please test 22.05 BETA when possible and let us know if the issue persists. Details on the Traffic Shaping config and...
-
06:56 PM Bug #12877 (Feedback): Cloudflare DynDNS fails to update more than two addresses
- If possible, please re-test after applying the available patch found with the System_Patches package.
-
06:49 PM pfSense Plus Bug #13041 (Closed): DNS resolution of internal network names when logged in via OpenVPN requires workaround
-
06:38 PM pfSense Plus Bug #13232 (Duplicate): Restoring Config with OpenVPN Custom Options Removes Carriage Returns
- This seems more like a feature than a bug, considering that the description and documentation both say to separate wi...
-
06:17 PM Bug #13234 (Not a Bug): Separator locations pushed down when pfSense is rebooted
- pfBlockerNG's auto rule creation will affect the placement of separators - this is likely what's happening. If you di...
-
10:29 AM Bug #13234 (Not a Bug): Separator locations pushed down when pfSense is rebooted
- This happens when I place a separator at the top of the floating rules and reboot the router. I have not checked othe...
-
05:34 PM Feature #8173: dhcp6c - RAW Options
- Please let us have these features added to pfSense. Half of france is using OPNsense because nothing happens on this ...
-
02:09 PM pfSense Docs Todo #13236 (Resolved): Document link speed limitations with igc and ix on 6100/4100
- > The I225 built-in phy doesn't support fixed operation, so a speed/duplex setting is emulated by selecting that sing...
-
12:09 PM pfSense Packages Feature #10818: UDP Broadcast Relay
- There's no GUI for it, but it can be installed on 22.05/2.7:...
-
11:21 AM pfSense Packages Bug #13153 (Resolved): Static routes bound to WireGuard interfaces are not restored after down / up events
- Tested on 22.01 and on 22.05-BETA (built on Fri May 27 06:21:09 UTC 2022)
I wasn't able to reproduce this issue. A... -
11:07 AM Bug #13235 (Not a Bug): URL in firewall rule hover does nothing
- There is URL present in the modal box you get when you hover over a rule. This URL does nothing.
* Should this URL... -
06:38 AM pfSense Packages Bug #12251 (Resolved): Wireguard 0.1.5 - ignores "KeepAlive" parameter if empty (instead of disabling)
- Tested on 22.01
When I used empty 'Keep Alive' field, I got in config: _*PersistentKeepalive = 0*_
When I tried... -
03:49 AM pfSense Packages Feature #12719 (Resolved): add igc(4) to the list of INLINE mode (iflib/netmap) supported cards
- Tested on 22.01
Interface *igc* was added into 'Supported drivers' list: _Supported drivers: bnxt, cc, cxgbe, cxl, e... -
03:48 AM pfSense Packages Feature #11560 (Resolved): add ena(4) to the list of INLINE mode (netmap) supported cards
- Tested on 22.01
Interface *ena* was added into 'Supported drivers' list: _Supported drivers: bnxt, cc, cxgbe, cxl, e...
05/28/2022
-
07:16 PM pfSense Plus Bug #13233 (Feedback): OpenVPN DCO connection fails with Auth Digest Algorithm set to SHA512
- OpenVPN DCO configurations specifying an auth digest algorithm of SHA512 fail to connect. Changing the algorithm to ...
-
06:50 PM Bug #12875: Import zabbix-agent6 and zabbix-proxy6 from FreeBSD Ports
- Discussed with engineering. This will get brought over in the next repo sync.
-
03:19 PM pfSense Plus Bug #13232 (Duplicate): Restoring Config with OpenVPN Custom Options Removes Carriage Returns
- If you back up a config on one device and then restore it in another, if you have an OpenVPN client (potentially serv...
-
03:06 PM Regression #12821: Intel e1000 driver (``em``, ``igb``) cannot pass packets tagged with VLAN ``0``
- Tested this on igc interfaces and it appears this only affects e1000-based NICs. Other Intel NICs would seem to be f...
-
02:13 PM pfSense Docs New Content #13211: OpenVPN DCO Documentation
- Much more clear to me, thanks!
-
02:10 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- I cannot test 22.05, I'm on community edition.
-
01:13 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- I suggest testing on 22.05 BETA if possible. If the issue persists there, it may be related to https://redmine.pfsens...
-
02:01 PM Regression #13203 (Resolved): Floating rules without an interface are not loaded
-
01:47 PM pfSense Plus Bug #12974: Typing anything into 1100/2100 recovery installer causes process to stop
- The wording has been addressed with NG 7431. This issue can be left open to track the behavior issue itself, as it sh...
-
01:14 PM Bug #13228: Recovering interface gateway may not be added back into gateway groups and rules when expected
- May be related to https://redmine.pfsense.org/issues/12920.
-
12:59 PM Bug #13231 (Not a Bug): OpenVPN custom options may fail after save/restore
- Sometimes after restoring a backup XML file, custom options get formatted improperly. That prevents the OpenVPN servi...
-
12:45 PM Feature #4259 (Resolved): Port forward NAT rules with "any" protocol
-
12:45 PM Feature #4259: Port forward NAT rules with "any" protocol
- Tested:...
-
06:03 AM pfSense Packages Feature #10818: UDP Broadcast Relay
- Hi.
Any news on this?
Eagerly awaiting this one
05/27/2022
-
11:54 PM Bug #13230 (Not a Bug): Floating rules on VPN interfaces
- With floating rules on OpenVPN and WireGuard interfaces, matching traffic doesn’t seem to return with rules that pass...
-
09:44 PM pfSense Packages Feature #12658: Adding prometheus metrics to darkstat
- I think the package is in the FreeBSD ports:...
-
07:31 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- I can also confirm that I can replicate this exact issue on my PFSense. Both as a VM and as bare metal.
Using a H... -
03:04 PM pfSense Docs Todo #13229 (Feedback): Update documentation for IPFW to PF transition for Limiters and Captive Portal
- Relevant commits:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/47dd08cc24bb4ffbd476b2d4aebacdb6ccbce895
... -
02:59 PM pfSense Docs Todo #13229 (Resolved): Update documentation for IPFW to PF transition for Limiters and Captive Portal
- Adding for tracking.
Docs are updated to reflect that IPFW is no longer used, it's all in PF now. -
01:59 PM pfSense Docs New Content #13223 (Feedback): Document new gateway state killing behavior
- This should complete the relevant updates (and then some):
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/7... -
01:15 PM Revision e5d97d7c: Update CARP status state sync note. Fixes #12701
-
10:58 AM Bug #13228 (Resolved): Recovering interface gateway may not be added back into gateway groups and rules when expected
- When an interface/gateway recovers and rc.newwanip runs, the gateway may not end up in the ruleset in groups or rules...
-
10:15 AM pfSense Plus Feature #13227: Group-based Mobile IPsec Virtual Address Pool assignment via RADIUS
- I Should mention you can use my modifcation afterwards by creating the groups identifier and IP pool needed, by creat...
-
10:09 AM pfSense Plus Feature #13227 (Resolved): Group-based Mobile IPsec Virtual Address Pool assignment via RADIUS
- Currently you cannot create additional Virtual IP Pools to assign mobile users IP addresses from, if you are using EA...
-
08:55 AM Todo #12701 (Feedback): Reorganize CARP status page
- Applied in changeset commit:e5d97d7ce8bd3346ef8fa6f5477182331d2174b4.
-
08:03 AM Todo #12701 (In Progress): Reorganize CARP status page
- This could use one small change, to add a note/link in the info block saying the user can set a custom filter host ID...
-
08:01 AM Todo #12701 (Resolved): Reorganize CARP status page
-
05:12 AM Todo #12701: Reorganize CARP status page
- Tested....
-
08:00 AM Regression #11545 (New): Primary interface address is not always used when VIPs are present
- That other issue could solve it for PPP type interfaces but it's happening on systems without PPP interfaces and thos...
-
02:53 AM Regression #11545 (Feedback): Primary interface address is not always used when VIPs are present
-
02:52 AM Regression #11545: Primary interface address is not always used when VIPs are present
- Should be fixed in #11629
Please re-test on the latest 22.05/2.7 snapshots. -
06:29 AM Bug #13226 (Confirmed): Disconnecting a user from Captive Portal may allow previously established connections to continue
- Able to reproduce.
It looks like @pfSense_kill_status()@ and @pfSense_kill_src states()@ are successfully kill TCP... -
05:11 AM Bug #13226: Disconnecting a user from Captive Portal may allow previously established connections to continue
- It looks like @pfSense_kill_states()@ and @pfSense_kill_srcstates()@ does not work properly:
https://github.com/pfse... -
05:02 AM Bug #13226 (Resolved): Disconnecting a user from Captive Portal may allow previously established connections to continue
- Steps to reproduce:
1. Connect to the network through the CP portal.
2. Establish OpenVPN forcing all traffic thr... -
05:25 AM Bug #13218: GIF-based interface MTU is assigned to parent interface on boot when parent interface is a LAGG
- I've applied it and it looks to do the job. I will keep an eye on it and throw in a couple of reboots over the weeken...
-
02:59 AM Bug #13218: GIF-based interface MTU is assigned to parent interface on boot when parent interface is a LAGG
- Graeme Bragg wrote in #note-3:
> Thanks for looking at this so quickly. Please let me know if you need/want me to te... -
05:21 AM Bug #13225: Bridges with QinQ interfaces not properly set up at boot
- fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/810 -
03:14 AM Bug #13225 (Resolved): Bridges with QinQ interfaces not properly set up at boot
- We have a setup that includes several OpenVPN tunnels, some of them using QinQ. When system is configured using WebUI...
-
01:58 AM Bug #13224 (Duplicate): Email notification flood when UPS (NUT) and WAN send notifications
- When my UPS (monitored with NUT) and one of my WAN (PPPoE) both send email notifications close to each other, it star...
Also available in: Atom