Activity
From 06/06/2022 to 07/05/2022
07/05/2022
-
06:17 PM pfSense Docs Todo #13342 (Pull Request Review): Correct BGP last-as description
- https://gitlab.netgate.com/docs/pfSense-docs/-/merge_requests/44
-
05:49 PM pfSense Docs Todo #13342 (Resolved): Correct BGP last-as description
- The following is incorrect:
https://docs.netgate.com/pfsense/en/latest/packages/frr/global/routemaps.html#bgp-as-p... - 04:45 PM Revision add6447b: Ensure we apply policy routing on whitelisted captive portal MAC addresses
- We cannot simply 'pass in quick' for the _patthru tagged packets,
because that means we don't process any subsequent ... -
02:56 PM Revision ad20a68b: Filter reload at end of rc.newwanip. Fixes #13228
-
01:51 PM pfSense Plus Bug #13338 (Pull Request Review): OpenVPN DCO panics with short UDP packets
-
12:59 PM pfSense Plus Bug #13338: OpenVPN DCO panics with short UDP packets
- That looks to be the result of a short UDP packet. Short enough that it doesn't contain an openvpn header.
https:/... -
10:31 AM pfSense Plus Bug #13338 (Resolved): OpenVPN DCO panics with short UDP packets
- If a UDP packet directed towards an active OpenVPN socket is received which is too short to contain an OpenVPN header...
-
01:46 PM pfSense Packages Bug #13332: HAProxy Broken after v22.05 and HAProxy v0.61_3
- Johannes Goldynia
Please open a new bug report for the HSTS / Cookie protection issue. -
07:59 AM pfSense Packages Bug #13332 (Rejected): HAProxy Broken after v22.05 and HAProxy v0.61_3
- There is no way the package can possibly track and warn about custom configuration directives. By definition it does ...
-
12:53 PM Bug #13341 (Not a Bug): IPSEC VTI Gateway Monitoring
- That is most likely a problem in your configuration or environment, VTI gateway monitoring is working fine in general...
-
12:14 PM Bug #13341 (Not a Bug): IPSEC VTI Gateway Monitoring
- Hello,
Gateway monitoring does not work on VTI gateways altough the tunnel is UP and traffic is passing succesfull... -
12:24 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
- I'm having a crack at this issue now. Is everyone experiencing this issue using unbound as a resolver by chance?
-
11:25 AM Feature #13340 (New): Option to change QinQ ethertype to Service VLAN Tag
- Currently, pfSense uses C-Tags (ethertype 0x8100) for QinQ interfaces. Ideally, it should keep C-Tags on existing con...
-
10:46 AM Bug #13339 (Not a Bug): Randomly DHCP interface detaches and attach automatically in pfsense 2.6.0
- This site is not for support or diagnostic discussion.
For assistance in solving problems, please post on the "Net... -
10:44 AM Bug #13339 (Not a Bug): Randomly DHCP interface detaches and attach automatically in pfsense 2.6.0
- I am facing issue on pfsense firewall CE 2.6.0 after upgrade on 2.5.0 to 2.6.0..,
-
10:05 AM Bug #13228 (Feedback): Recovering interface gateway may not be added back into gateway groups and rules when expected
- Applied in changeset commit:ad20a68bae86fff5660b02789a49618a6e71ae22.
-
09:42 AM Bug #9887: Rule separator positions change when deleting multiple rules
- This fails in a new/different way when applied. When attempting "test 2" from my original attachments, it puts the se...
-
09:36 AM Bug #13327: Valid OpenVPN client connections rejected due to extraneous output to ovpn_auth_verify
- I neglected to mention in the bug report and the forum thread that I'm on release 2.6.0, the current stable release. ...
-
07:35 AM Bug #13327 (Rejected): Valid OpenVPN client connections rejected due to extraneous output to ovpn_auth_verify
- There isn't enough information to go on here. This is working for us in the lab and for most if not all users of the ...
-
08:47 AM Regression #13323: Captive Portal breaks policy based routing for MAC address bypass clients
- I've applied the patch and it fixed the problem for me. Thanks a bunch!
-
08:11 AM Bug #13337 (Rejected): After upgrading from 22.01 to 22.05 unbound intermittently stops resolving until manually restarted
- There isn't enough information to go on here and it's working fine for thousands of others. It's possible it's relate...
-
03:37 AM Bug #13337 (Rejected): After upgrading from 22.01 to 22.05 unbound intermittently stops resolving until manually restarted
- Config haven't changed from 22.01 but after upgrade started having problems with dns resolver just timing out on reso...
-
08:09 AM pfSense Packages Bug #13336 (Rejected): BGP packets not being sent to OpenVPN cloud connections
- This is almost certainly a configuration problem with your OpenVPN setup and/or FRR settings. This site is not for su...
-
08:07 AM pfSense Packages Bug #13328 (Not a Bug): Wireguard Site-to-Site broken after upgrade to 22.05
- This is unlikely to be a bug, but something in your configuration or environment. It's working for many others in sim...
-
08:05 AM pfSense Docs Todo #12770 (Resolved): Feedback on Firewall — Configuring firewall rules
- Merged. Also fixed a couple small things I noticed after merging: https://gitlab.netgate.com/docs/pfSense-docs/-/comm...
-
07:56 AM pfSense Docs New Content #13270 (Resolved): OpenVPN client gateway is incorrect when the server does not push routes
- Merged.
I fixed a couple extra things I noticed after merging: https://gitlab.netgate.com/docs/pfSense-docs/-/comm... -
07:43 AM pfSense Plus Bug #12607 (Closed): Instability with Snort Inline with AWS Instances
-
07:41 AM Bug #13330 (Rejected): Traffic Shaper Wizard is broken
- Please open separate issues for each item, like you did for the second bullet point there ( #13329 )
The first bul... -
07:41 AM Bug #12747: Restarting the logging daemon during rotation also restarts ``sshguard``, leading to frequent log messages
- I'm having the same issue on 2.6.0 at every 1 minute:
Jul 5 09:33:00 sshguard 77002 Exiting on signal.
Jul 5 09:3... -
07:36 AM Bug #13318 (Resolved): Neighbor hostnames in the NDP Table on ``diag_ndp.php`` are always empty
-
03:26 AM Bug #5413: Reduce disruptions when changing DNS records from DHCP leases in Unbound
- Any progress on this as it causes lots of other DNS resolver issues not just short interruptions.
22.01 dns resolver...
07/04/2022
-
08:14 PM pfSense Packages Bug #13336 (Rejected): BGP packets not being sent to OpenVPN cloud connections
- Scenario:
OpenVPN cloud is utilized to connect two pfsense routers behind CGNAT to allow for site to site connectivi... -
03:23 PM Feature #13293: Option to set auth-gen-token in OpenVPN GUI
- It's unclear if the concerns mentioned on the following link have been addressed - best to keep this as a custom opti...
-
02:07 PM Regression #13323: Captive Portal breaks policy based routing for MAC address bypass clients
- If you'd like to test it and provide feedback, here's the patch - apply it with the System Patches package.
-
01:30 PM Regression #13323: Captive Portal breaks policy based routing for MAC address bypass clients
- Yes, that's internal. It'll turn up in the public tree once I find a victim to review it. That's going to take a day ...
-
01:00 PM Regression #13323: Captive Portal breaks policy based routing for MAC address bypass clients
- Kristof, the link you posted doesn't work. DNS_PROBE_FINISHED_NXDOMAIN
You probably linked to something internal tha... -
11:07 AM Regression #13323: Captive Portal breaks policy based routing for MAC address bypass clients
- The draft patch wouldn't work, but a similar fix does:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests... -
11:15 AM pfSense Plus Bug #13334 (Not a Bug): Configuration Auto Backup broken after v22.05 fresh install
- I was able to upload backups successfully. Likely a temporary service outage. If it continues to happen, I'd suggest ...
-
11:04 AM pfSense Packages Bug #11098 (Resolved): Backup Files and Directories plugin crashes firewall if /root specified as backup location
- I'll close this given that the original issue (crash) no longer happens. There's still the issue of the package locki...
-
10:48 AM Feature #13335: Allow NAT reflection to be limited to specific interfaces
- The NAT reflection mode default can be kept as @disabled@, while enabling it per NAT rule. I suppose having the featu...
-
02:08 AM Feature #13335 (New): Allow NAT reflection to be limited to specific interfaces
- I have a setup at home with a VLAN for guests, which doesn't have access to any internal resources. Because of this,...
-
10:32 AM pfSense Packages Bug #13333: PHP error when saving Suricata rulesets
- Marcos Mendoza wrote in #note-2:
> It happened a while ago as you can tell from the timestamp, unfortunately I don't...
07/03/2022
-
11:35 PM pfSense Packages Bug #11098: Backup Files and Directories plugin crashes firewall if /root specified as backup location
- my apologies, I did misunderstand the initial report
in case of specifying "/root/" as path, the backup button produ... -
07:25 PM Regression #13290: Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters
- For reference:
There's a redmine report for the policy routing issue here https://redmine.pfsense.org/issues/13323... -
07:23 PM Regression #13323: Captive Portal breaks policy based routing for MAC address bypass clients
- Potential fix here: https://redmine.pfsense.org/issues/13290#note-6
-
06:42 PM pfSense Packages Bug #13333: PHP error when saving Suricata rulesets
- It happened a while ago as you can tell from the timestamp, unfortunately I don't remember the exact details to repro...
-
04:14 PM pfSense Packages Bug #13333: PHP error when saving Suricata rulesets
- Can you add a little more detail for this statement: " _This was triggered when existing rules were auto-enabled by ...
-
12:59 PM pfSense Packages Bug #13333 (Resolved): PHP error when saving Suricata rulesets
- In some cases, @$enabled_rulesets_array@ in @suricata_rulesets.php@ may not be an array which results in the followin...
-
06:06 PM pfSense Plus Bug #13334 (Not a Bug): Configuration Auto Backup broken after v22.05 fresh install
- Multiple errors (30) generated with the same message:
3:33:24 An error occurred while uploading the encrypted confi... -
12:20 PM pfSense Packages Bug #13332: HAProxy Broken after v22.05 and HAProxy v0.61_3
- Hello,
updating the pass-trough rules to... -
02:58 AM pfSense Packages Bug #13328: Wireguard Site-to-Site broken after upgrade to 22.05
- After reading through here, I think this might be related to this
https://redmine.pfsense.org/issues/12808
I never h...
07/02/2022
-
11:34 PM pfSense Packages Bug #13332 (Rejected): HAProxy Broken after v22.05 and HAProxy v0.61_3
- If you are using HAProxy deprecated rspidel directive on your frontends or the option option httpchk on backends, HAP...
-
09:05 PM pfSense Plus Bug #12607: Instability with Snort Inline with AWS Instances
- This can likely be closed as I've seen zero complaints on newer Plus releases for Snort Inline in AWS. Likely these ...
-
09:01 PM Regression #12821: Intel e1000 driver (``em``, ``igb``) cannot pass packets tagged with VLAN ``0``
- FYI using the manually compiled, out-of-band driver still works fine on 22.05-RELEASE (as expected since the FreeBSD ...
-
08:50 PM Bug #13282: Alias content is sometimes incomplete if the firewall cannot resolve an FQDN in the alias
- Reid Linnemann wrote in #note-2:
> There must be something else to this than just the unresolvable host, I've tried ... -
08:41 PM pfSense Packages Bug #11098: Backup Files and Directories plugin crashes firewall if /root specified as backup location
- Jordan Greene wrote in #note-11:
> attempted creation of backup for "/" - after creating the entry and using the back... -
05:14 PM pfSense Packages Bug #11098: Backup Files and Directories plugin crashes firewall if /root specified as backup location
- attempted creation of backup for "/" - after creating the entry and using the backup button, I'm eventually given 504...
-
02:28 PM pfSense Docs New Content #13331 (New): FRR: Add documentation for RIP
RIP documents(configuration/example) need to be added under FRR package Docs.-
02:10 PM Feature #11927 (Resolved): Allow DHCP not to serve a gateway - small fix
resolved
22.05-RELEASE (amd64)
built on Wed Jun 22 18:56:13 UTC 2022
FreeBSD 12.3-STABLE-
11:33 AM Bug #13330 (Rejected): Traffic Shaper Wizard is broken
- I noticed multiple issues with the Traffic Shaper wizard using ALTQ Scheduler - HFSC type.
* Values defined in wiz... -
10:58 AM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- This fix doesn't work for me, I still can't get any logging of IP blocks, even though the dashboard counter shows it ...
-
09:11 AM Bug #13329 (New): Traffic shaping Wizard sets invalid values for qVoip queue
- No matter what I set in the Voice Over IP wizard step, when I finish the wizard the qVoip is set to 32Kb.
!clip... -
04:02 AM pfSense Packages Bug #13328 (Not a Bug): Wireguard Site-to-Site broken after upgrade to 22.05
- Hi,
I upgraded from 22.01 to 22.05. Everything went fine.
Plus home license on virtualized system
On Upgrade the... -
02:57 AM Bug #13318: Neighbor hostnames in the NDP Table on ``diag_ndp.php`` are always empty
- Seems it works.
!clipboard-202207021056-wabip.png!
07/01/2022
-
06:12 PM Bug #13327 (Resolved): Valid OpenVPN client connections rejected due to extraneous output to ovpn_auth_verify
- OpenVPN was observed rejecting client connections that were previously accepted and had not expired. Research lead to...
-
02:25 PM Bug #9887 (Pull Request Review): Rule separator positions change when deleting multiple rules
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/830
All tests in the original ticket worked as expecte... -
09:10 AM Bug #12959: dhcplease process wrongly update host file if client-hostname is empty
- Also unable to reproduce.
Tested on:
22.05-RELEASE (amd64)
built on Wed Jun 22 18:56:13 UTC 2022
FreeBSD 12.3-STABLE -
04:53 AM Regression #13290: Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters
- I believe the failure to apply policy routing on whitelisted mac addresses is due to rules like `pass in quick all fl...
06/30/2022
-
05:04 PM Bug #13282: Alias content is sometimes incomplete if the firewall cannot resolve an FQDN in the alias
- There must be something else to this than just the unresolvable host, I've tried several times to replicate this and ...
-
12:52 PM pfSense Packages Bug #13309 (Resolved): Cron validation prevents special strings such as @reboot
- Tested against the Cron package version 0.3.8_1
It works as expected.
I am marking this ticket resolved. -
12:35 PM pfSense Packages Bug #13261 (Resolved): Input validation rejects empty ``sudo`` command list, but GUI text says it can be empty
- Tested on 22.05, package version 0.3_7.
It works as expected. I am marking this ticket closed. -
12:00 PM Bug #13325 (Confirmed): System Information widget breaks with multiple instances
- I currently have 2 System Information widget displayed on a 3 Column Dashboard (First and 3rd Column). First System ...
-
11:46 AM Bug #13317: ``array_filter`` PHP Errors in ``interfaces.inc``
- I did indeed fix this in CE devel, I need to get the change merged into plus-devel today, if it hasn't already been m...
-
10:21 AM pfSense Docs Todo #13324 (Rejected): Remove Deprecated IPSec Remote Access VPN Guides
- L2TP is not insecure (it's protected by IPsec) it's just not well supported by clients.
They are all still valid j... -
10:18 AM pfSense Docs Todo #13324 (Rejected): Remove Deprecated IPSec Remote Access VPN Guides
- Several Configuration Recipes are often find by customers that are no longer recommended. While these guides had use...
-
09:21 AM Regression #13323 (Resolved): Captive Portal breaks policy based routing for MAC address bypass clients
- Relevant information about my network
LAN segment
VLAN for IoT and wifi devices
WAN1 is used as the default gate... -
08:41 AM Todo #10464: Don't change the current update repo when new releases are available
- Also worth noting, however this is handled, it should not suppress the list of packages and it *must* still allow the...
-
07:42 AM Regression #13290: Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters
- The 'bad switch' message originates in dummynet_send(), and the '21' is decimal, so 0x15. Representing PROTO_IPV6 | P...
-
07:06 AM Bug #13321 (Pull Request Review): dhcpleases handles duplicate hostnames incorrectly
-
06:45 AM Feature #13322: Define Packet Capture Protocol
- And EtherType
-
06:10 AM Feature #13322 (Closed): Define Packet Capture Protocol
- Any chance of adding the ability of allowing a user defined protocol to the Packet Capture.
I was trying to debug ... -
05:21 AM Bug #12747: Restarting the logging daemon during rotation also restarts ``sshguard``, leading to frequent log messages
- same here on 22.05
!clipboard-202206300621-7gjov.png!
-
03:18 AM Bug #12811: Services are not restarted when PPP interfaces connect
- ec73bb89489d830ec21c4e04ffa3ec401791b55d and c467ca2f35c102aae897424a2fda08e9b2ace673 actually solve the issue that t...
06/29/2022
-
11:57 PM Bug #13321: dhcpleases handles duplicate hostnames incorrectly
- Added pull request: https://github.com/pfsense/FreeBSD-ports/pull/1176
-
11:10 PM Bug #13321 (Pull Request Review): dhcpleases handles duplicate hostnames incorrectly
- --- Problem ---
If the 'dhcpd.leases' file parsed by dhcpleases contains an expired lease and non-expired lease for ... -
04:31 PM Bug #13228: Recovering interface gateway may not be added back into gateway groups and rules when expected
- I have this issue. Adding the filter_configure(); to the end, (while not removing the else block) does resolve this f...
-
02:03 PM pfSense Plus Bug #13320: IP aliases with a CARP VIP parent are not available as VIP choices for gateway groups
- Looks like it's because the group drop-downs filter based on the VIP interface and it sees the CARP VIP as the interf...
-
01:47 PM pfSense Plus Bug #13320 (Resolved): IP aliases with a CARP VIP parent are not available as VIP choices for gateway groups
- Configuration is an HA pair of 6100's with a failover gateway group, one ISP per gateway.
The intention is for IPs... -
12:59 PM Revision 8c9ab20e: Don't force DNS to use 4/6 here. Fixes #13318
- It's not trying to force communication with a
specific address family DNS server. -
12:16 PM Bug #13318: Neighbor hostnames in the NDP Table on ``diag_ndp.php`` are always empty
- Jim - just to let you know, applied this and seems to be working now. Thanks for such a quick response!
-
08:10 AM Bug #13318 (Feedback): Neighbor hostnames in the NDP Table on ``diag_ndp.php`` are always empty
- Applied in changeset commit:8c9ab20efe61161e30fe215166d8573c801b947d.
-
07:57 AM Bug #13318: Neighbor hostnames in the NDP Table on ``diag_ndp.php`` are always empty
- Looking at #11512 and commit:aa1936eefc251b5330e7392f3b1fbc23a006a400 where that was added, it isn't necessary. There...
-
07:50 AM Bug #13318: Neighbor hostnames in the NDP Table on ``diag_ndp.php`` are always empty
- Looks like for some reason @_getHostName()@ is forcing the DNS lookup to use @-6@ when it shouldn't, as that controls...
-
07:32 AM Bug #13318 (Resolved): Neighbor hostnames in the NDP Table on ``diag_ndp.php`` are always empty
- The NDP Table in the gui is not listing the hostname, while ndp -a from cmd line does.
See this thread.
https:/... -
10:01 AM Regression #13316 (Feedback): ``vmstat -m`` value for ``temp`` is accounted for incorrectly, resulting in underflows
- Looks like this happens as the value for @nvlist@ increases. Apparently already fixed in FreeBSD: https://cgit.freebs...
-
08:46 AM Regression #13316: ``vmstat -m`` value for ``temp`` is accounted for incorrectly, resulting in underflows
- Looks like the value of that entry is unsigned and trying to go negative, which results in an underflow (hits 0 then ...
-
09:20 AM Regression #13319: OpenVPN site2site with SSL/TLS doesn't apply the remote network route
- Jim Pingle wrote in #note-1:
> That is most likely a configuration problem. More likely related to how you changed t... -
09:15 AM Regression #13319 (Not a Bug): OpenVPN site2site with SSL/TLS doesn't apply the remote network route
- That is most likely a configuration problem. More likely related to how you changed the settings when moving from sha...
-
09:12 AM Regression #13319 (Not a Bug): OpenVPN site2site with SSL/TLS doesn't apply the remote network route
- I'm testing 2.7 DEV snapshot and I have two OpenVPN site2site client connections.
One (ovpnc1) uses sharedkey and th... -
08:06 AM Bug #13317 (Feedback): ``array_filter`` PHP Errors in ``interfaces.inc``
- Looks like Reid already fix this one. See commit:c5d786359cc4a15c81e1c4773ab271b3d49ed594
-
06:40 AM Bug #13317: ``array_filter`` PHP Errors in ``interfaces.inc``
- Do you have any more information about what was going on when the errors happened? Were you making a change in the GU...
-
02:16 AM Bug #13317 (Resolved): ``array_filter`` PHP Errors in ``interfaces.inc``
- Crash report begins. Anonymous machine information:
amd64
12.3-STABLE
FreeBSD 12.3-STABLE devel-12-n227385-38ca... -
07:53 AM Bug #13132 (New): Multiple ``<sshdata>`` or ``<rrddata>`` sections in ``config.xml`` lead to an XML parsing error during restore
- There is still some issue here as users are hitting this on 22.05 when restoring backups with two sections.
-
07:00 AM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- I just tested and your patch also works on the latest 2.7.0-DEVELOPMENT.
06/28/2022
-
09:01 PM Regression #13316: ``vmstat -m`` value for ``temp`` is accounted for incorrectly, resulting in underflows
- Just after a reboot the value is sane and the script works, so there is something else going on there.
I'd say the... -
08:43 PM Regression #13316: ``vmstat -m`` value for ``temp`` is accounted for incorrectly, resulting in underflows
- There is a line in @vmstat -m@ for @temp@ that is throwing off the output, it's gigantic...
-
08:29 PM Regression #13316 (Resolved): ``vmstat -m`` value for ``temp`` is accounted for incorrectly, resulting in underflows
- It works on 22.01, running it on 22.05 produces the following output:...
-
08:32 PM Revision c5d78635: get_interface_addresses: Silence array_filter warnings
-
06:09 PM Bug #13093: LDAP authentication fails with extended query and RFC2307 group lookups enabled
- @(&(DN_RETURNED_BY_INITIAL_SEARCH)(memberOf=cn=nextcloud,cn=groups,cn=accounts,dc=example,dc=com))@
That doesn't w... -
05:21 PM Bug #13093: LDAP authentication fails with extended query and RFC2307 group lookups enabled
- OK. It looks like it is combining the RFC2307 query and the extended query into something that cannot match when both...
-
02:20 PM Revision d9ff4a76: Clean up old repo files that are not needed any longer since we just template the one
-
01:14 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
- For reference, the patch to fix it is as follows:...
-
12:44 PM Revision 2a9f6b40: Clarify delegated IPv6 prefix source. Fixes #13310
- Indicates the tracked interface and prefix ID, which is more important
now that delegation works from multiple upstre... -
12:04 PM pfSense Plus Todo #13189 (Resolved): Input validation should reject the combination of DCO and P2P mode
-
12:04 PM pfSense Plus Regression #13183 (Resolved): ZFS module is loaded on systems without ZFS
-
10:28 AM pfSense Docs New Content #13311 (Resolved): Add troubleshooting tips for multiple disk boot issues
- https://docs.netgate.com/pfsense/en/latest/troubleshooting/boot-issues.html
It's possible that pfSense may mount a... -
08:22 AM pfSense Packages Bug #13309 (Feedback): Cron validation prevents special strings such as @reboot
- Fixed: https://github.com/pfsense/FreeBSD-ports/commit/68b6508b0454c6113e03c1fd84e20279310d0bef
-
07:55 AM Bug #13310 (Feedback): Each line in the NPt destination IPv6 prefix list also contains the network of the previous line when multiple choices are present
- Applied in changeset commit:2a9f6b409bdde67c065a0fa6b13296bbad6c6794.
-
07:16 AM Bug #13310: Each line in the NPt destination IPv6 prefix list also contains the network of the previous line when multiple choices are present
- This is also mentioned on #13240 but in the interest of only having one problem per issue we can keep this one and ch...
-
07:18 AM Bug #13240: User is forced to pick an NPt destination IPv6 prefix length even when choosing a drop-down entry which contains a defined prefix length
- Moving first point to #13310 - keeping this one for point 2.
06/27/2022
-
10:19 PM Regression #13290: Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters
- I've posted some additional info on the forums here: https://forum.netgate.com/topic/173061/captive-portal-broken-aft...
-
07:26 PM Regression #13290: Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters
- I've updated to pfSense+ 22.05 today and I'm seeing the same thing on the console when activating a captive portal.
-
06:32 PM Revision 60a2fa6b: Remove incorrectly restored code. Fixes #13308
-
06:28 PM Revision 2bf4167c: Set PKG_REPO_BRANCH_DEVEL to match the branch name
-
04:08 PM Bug #13310: Each line in the NPt destination IPv6 prefix list also contains the network of the previous line when multiple choices are present
- PR here: https://github.com/pfsense/pfsense/pull/4608
-
04:07 PM Bug #13310 (Resolved): Each line in the NPt destination IPv6 prefix list also contains the network of the previous line when multiple choices are present
- Destination IPv6 prefix list is not built properly due to wrongly placed string operator
-
03:52 PM pfSense Packages Bug #13309 (Resolved): Cron validation prevents special strings such as @reboot
- A recent change to the Cron package introduced field validation. Although the UI specifies time examples, some users ...
-
03:09 PM Bug #13308 (Resolved): The ``negate_networks`` table is duplicated in ``rules.debug``
- Tested patch on 22.05. The table is no longer duplicated.
-
01:50 PM Bug #13308 (Feedback): The ``negate_networks`` table is duplicated in ``rules.debug``
- Applied in changeset commit:60a2fa6b6f1a59f3f86933265fbb48e25f652bfc.
-
01:30 PM Bug #13308 (Resolved): The ``negate_networks`` table is duplicated in ``rules.debug``
- In #13049 the logic to generate the @negate_networks@ table changed ( commit:415a1b2083228030f200c8ea0eac3a8fc91f7142...
-
11:20 AM Bug #13307 (Resolved): PPP interface custom reset date/time Hour and Minute fields do not properly handle ``0`` value
- When configuring a custom PPP interface reset time on @/interfaces_ppps_edit.php@ *or* @interfaces.php@ the page mish...
-
10:56 AM Regression #13303 (Pull Request Review): DNSExit Dynamic DNS updates no longer work
-
10:45 AM pfSense Packages Todo #13306 (Resolved): Update NUT to version 2.8.0 to match FreeBSD Packages
- NUT in the FreeBSD repo has been updated to 2.8.0. Make a corresponding update in the pfSense Packages repo.
-
10:26 AM Feature #13305: Certificate Revocation page should show expiration date
- This would only be valid for imported CRLs, as internal CRLs are regenerated every time they are refreshed (e.g. Open...
-
10:07 AM Feature #13305 (New): Certificate Revocation page should show expiration date
- For external CAs, it would be helpful if the Certificate Revovation page showed the valid dates for the CRLs as is do...
-
09:50 AM Bug #11629: PPPoE WAN IP address different than expected when set static by ISP
- Dan Rice wrote in #note-23:
> We've installed 22.05 on our Netgate 2100 appliance and it's still assigning the wrong... -
07:42 AM pfSense Docs Todo #12770 (Pull Request Review): Feedback on Firewall — Configuring firewall rules
-
07:31 AM Bug #12947 (Pull Request Review): Old IPv6 addresses may continue to be used after DHCP or RA changes
-
07:27 AM pfSense Docs Correction #11223: Azure Marketplace links are invalid
- Looks like they were fixed in #13130 (2 months ago) and https://gitlab.netgate.com/docs/pfsense-platforms/-/commit/c3...
-
07:23 AM pfSense Plus Bug #11626: Google LDAP connections fail due to lack of SNI for TLS 1.3
- Not up to me, it'll need to be handled by Luiz or Brad once things start moving for 22.09 but it's already on the radar.
-
07:22 AM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
- Kris Phillips wrote in #note-10:
> The problem is that renegotiating the data channel key, in the default operation ... -
07:20 AM Bug #13301 (Duplicate): Bug #13239 = (?) = #12645 appease not fixed - ipv6 based ipsec vpn tunnel bug found with fqdn remote host
- I reopened the previous issue, no need for a new one.
-
07:20 AM Bug #12645 (New): ``filterdns`` does not monitor remote IPsec gateways for IPv6 address changes
-
07:19 AM pfSense Packages Bug #13261: Input validation rejects empty ``sudo`` command list, but GUI text says it can be empty
- Picked back to release branches.
-
12:09 AM Revision 17f81cb6: Fixing broken DNSExit implementation
06/26/2022
-
11:31 PM Feature #13304 (Resolved): ALTQ GUI support for Broadcom Netextreme II (``bxe``) interfaces
- Original support commit "freebsd-src: 4e40076":https://github.com/freebsd/freebsd-src/commit/4e4007688cf99b61408f5b60...
-
07:44 PM Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes
- I posted on the PR that since @rlinnemann has just deprecated pfSense_getall_interface_addresses(), this should proba...
-
07:18 PM Regression #13303 (Resolved): DNSExit Dynamic DNS updates no longer work
- The current implementation of DNSExit under DynDNS doesn't work anymore. In the logs it will show:
!clipboard-2022... -
02:47 PM Bug #7996 (Pull Request Review): Unnecessary link tag in login page
- https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/825
-
02:35 PM Bug #12544 (Closed): OpenSSH vulnerabilities
-
02:14 PM Regression #11870 (Not a Bug): Setting MTU on VLAN does not set MTU on parent interface in 2.5.1
- VLAN MTU _should_ be allowed to be set at the same or lower MTU as the parent. This issue can be re-opened if a case ...
-
12:54 PM pfSense Docs New Content #13270 (Pull Request Review): OpenVPN client gateway is incorrect when the server does not push routes
- https://gitlab.netgate.com/docs/pfSense-docs/-/merge_requests/41
06/25/2022
-
07:01 PM pfSense Docs Correction #11223 (Resolved): Azure Marketplace links are invalid
-
07:01 PM pfSense Docs Correction #11223: Azure Marketplace links are invalid
- Looks like this was fixed. The corrected links point to https://azuremarketplace.microsoft.com/en-us/marketplace/apps...
-
05:47 PM Bug #12544: OpenSSH vulnerabilities
- This bug report can be closed. pfSense Plus 22.05 comes with OpenSSH 8.8p1, which is not vulnerable to any of these ...
-
05:42 PM Bug #8207: 2.4 cannot boot as a Xen VM with more than 7 NICs
- Due to lack of confirmation, this bug report should be rejected unless it can be verified that there is a problem on ...
-
05:41 PM Bug #9626: When deny write permission is assigned to a user, there is no error feedback if the user tries to write something
- Can confirm this is still an issue in 22.05 of pfSense Plus. There is no visual feedback or an error notification du...
-
05:39 PM Bug #7996: Unnecessary link tag in login page
- This is still present in pfSense Plus 22.05.
-
05:38 PM pfSense Packages Bug #10602 (Resolved): Dashboard->Traffic Graphs bandwidth designations on hover pop-ups
- Tested this on pfSense Plus 22.05. Not sure when this was fixed, but this looks to be resolved. Closing out this bu...
-
05:34 PM pfSense Plus Bug #11626: Google LDAP connections fail due to lack of SNI for TLS 1.3
- Jim Pingle wrote in #note-15:
> Nudge this ahead so we have more time to ensure there aren't any regressions from th... -
05:30 PM pfSense Plus Feature #12546: Add 2FA Support to pfSense Plus Local Database Authentication
- Further expounding on this, it appears that Viscosity has native capability to add prompts in the client config.
... -
05:03 PM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
- Jim Pingle wrote in #note-9:
> Marcos Mendoza wrote in #note-7:
> > I created https://redmine.pfsense.org/issues/13... -
05:00 PM Bug #13003: Malicious Driver Detection event on ``ixl(4)`` driver
- Christoph Vieten wrote in #note-5:
> Kris Phillips wrote in #note-3:
> > Christoph Vieten wrote in #note-2:
> > > ... -
03:25 PM pfSense Docs Todo #12770: Feedback on Firewall — Configuring firewall rules
- Merge request:
https://gitlab.netgate.com/docs/pfSense-docs/-/merge_requests/42 -
10:59 AM pfSense Packages Bug #11572: Auto created firewall rules have IPv4 as protocol only - even for IPv6 lists.
- Still an issue in 2.6.0
Why not remove pfblockerNG from Repo if it's no more fixed and maintained anyway? Saves ti... -
05:41 AM Bug #13301 (Duplicate): Bug #13239 = (?) = #12645 appease not fixed - ipv6 based ipsec vpn tunnel bug found with fqdn remote host
- Hi,
I reported the bug earlier : https://redmine.pfsense.org/issues/13239#change-61632
ipv6 based ipsec vpn tun... -
05:33 AM Bug #12645: ``filterdns`` does not monitor remote IPsec gateways for IPv6 address changes
- tested on the latest built 22.05-RC (amd64) built on Fri Jun 17 06:34:36 UTC 2022
the bug is not fixed, Ipsec tunnel...
06/24/2022
-
10:10 PM Feature #13296: Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
- It's where the bug entries are for FreeBSD ports are, and where a feature request can be submitted.
-
04:16 PM Bug #9471 (Resolved): GIF tunnel not added to interface group after reboot
added GIF,LAN,PPPoE and GRE to the group of interfaces, GIF is added to the interface group after reboot
ifconfi...-
03:09 PM Revision 3222c70a: Omit VIPs from interface address selection. Fixes #11545
- Add function get_interface_addresses() which wraps around pfSense_get_ifaddrs() and
filters VIPs before selecting an ... -
02:50 PM pfSense Packages Bug #13261 (Feedback): Input validation rejects empty ``sudo`` command list, but GUI text says it can be empty
- Merged: https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/commit/a056c1984a174248da0a0f8c541d9441678a2339
-
01:23 PM pfSense Packages Bug #13261 (Pull Request Review): Input validation rejects empty ``sudo`` command list, but GUI text says it can be empty
- https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/251
-
11:31 AM pfSense Docs Correction #13300 (Resolved): Corrected Silabs driver URL
-
11:20 AM pfSense Docs Correction #13300 (Resolved): Corrected Silabs driver URL
- Current link in the Windows tab of the Connecting to the Console Port pages for Netgate firewalls (excluding 1100 and...
-
11:21 AM pfSense Packages Bug #13299 (Resolved): Cron package needs basic input validation and output encoding
- Tested and working as expected on...
-
10:18 AM pfSense Packages Bug #13299 (Feedback): Cron package needs basic input validation and output encoding
- Fixed: https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/commit/1a8a2f338592428dd46e543a884b1758b68198c9
-
10:09 AM pfSense Packages Bug #13299 (Resolved): Cron package needs basic input validation and output encoding
- The cron package does not validate its inputs nor does it encode its output. This can lead to a potential stored XSS....
-
10:25 AM Regression #11545: Primary interface address is not always used when VIPs are present
- I believe I have a fix for this issue. I created a variation on pfSense_get_interface_addresses() named pfSense_get_i...
-
10:15 AM Regression #11545 (Feedback): Primary interface address is not always used when VIPs are present
- Applied in changeset commit:3222c70aaf783336901f7b1225727b5973ba865a.
-
07:47 AM Bug #13298: Dynv6 Dynamic DNS client does not check the response code when updating
- PR: https://github.com/pfsense/pfsense/pull/4605
-
07:16 AM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
- Marcos Mendoza wrote in #note-7:
> I created https://redmine.pfsense.org/issues/13293 for that. Given that @auth-gen...
06/23/2022
- 08:49 PM Revision adfb1d2b: fix: Dynv6 checkIP
- Check return of update to release check IP
-
07:49 PM pfSense Packages Bug #8454: Arpwatch package break email notifications from other sources
- Is this still current as of 22.05? I just started playing with Arpwatch. What exactly does the "Disable Cron emails" ...
-
04:01 PM Bug #13298: Dynv6 Dynamic DNS client does not check the response code when updating
- *Testing*
Tested with https://dynv6.com -
03:58 PM Bug #13298 (Resolved): Dynv6 Dynamic DNS client does not check the response code when updating
- Check return of update to release check IP
-
12:04 PM Feature #13297 (New): Support for Gateway Groups as Static Route destinations
- It could be interesting to have the possibility to use a group of gateways with static routes in a failover scenario....
-
07:06 AM Regression #11316: Unbound crashes with signal 11 when reloading
- Why is this closed ??
All was ok for my pfsense until a power outage.
I have pfsense 2.6 up to date and it has been... -
01:31 AM Bug #13003: Malicious Driver Detection event on ``ixl(4)`` driver
- Kris Phillips wrote in #note-3:
> Christoph Vieten wrote in #note-2:
> > Same happened on 2.6.0 with Intel x710-T4 ...
06/22/2022
-
09:31 PM Feature #13296: Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
- @mmendoza was that last link you posted supposed to show something related? for me it just appears to be a list of ev...
-
05:54 PM Feature #13296: Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
- It's http://wide-dhcpv6.sourceforge.net/
See:
https://github.com/pfsense/FreeBSD-ports/tree/devel/net/dhcp6
http... -
04:47 PM Feature #13296: Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
- I'm still hazy on exactly which dhcp6c implementation is currently shipping. I _thought_ it was the "hrs-allbsd/wide-...
-
04:01 PM Feature #13296 (New): Add support for DHCP6 OPTION_PD_EXCLUDE (RFC 6603)
- Some ISPs are rolling out IPv6 and not directly providing a globally routable WAN address via DHCPv6. Instead, they a...
-
09:04 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- hello guys
Configurator (Scope):
Interfaces: WAN-DHCP4|WAN2-DHCP4
Gateway Group: Failover (WAN_DHCP Gateway: 192... -
06:06 PM Feature #13294: Change gateway name
- There's no functionality to rename the gateway/group and update all of the places where it could be used. That could ...
-
10:27 AM Feature #13294 (New): Change gateway name
- After clicking on a gateway on system_gateways_edit.php, which takes the user to e.g., system_gateways_edit.php?id=0,...
-
05:19 PM Revision d55e0d4b: fix func params for get_dpinger_status() call in gwlb.inc
-
04:15 PM Revision 7e9a12e9: Centralize the branches into builder_defaults.sh to simplify and eliminate overwriting the variables
-
12:26 PM Bug #13295 (Resolved): Incorrect function parameters for ``get_dpinger_status()`` call in ``gwlb.inc``
- There seems to be an error in @gwlb.inc@ around line 479. The call to @get_dpinger_status()@ has the @$action_disable...
-
02:12 AM Revision 5ecee3d7: scrubing -> scrubbing
06/21/2022
-
03:47 PM Revision 098cdb61: Add version config for use by pfSense-repo
-
02:37 PM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
- I created https://redmine.pfsense.org/issues/13293 for that. Given that @auth-gen-token@ handles the issue with frequ...
-
02:35 PM Feature #13293 (New): Option to set auth-gen-token in OpenVPN GUI
- This option is useful to avoid having to frequently manually re-authenticate when using MFA.
> --auth-gen-token [lif... -
12:06 PM pfSense Packages Feature #13292 (New): Separator
- It'd be really nice if there was a way to add a separator to the certificates list in the ACME package. Nothing fanc...
-
10:22 AM pfSense Docs Todo #13291 (Duplicate): Notification documentation
- I know there is documentation here on how to setup notification
https://docs.netgate.com/pfsense/en/latest/config/... -
01:00 AM Bug #13210: PPPoE server panics with multiple client connections
- Sorry, wanted to add it here for documentation purpose but forgot to make it yesterday:...
06/20/2022
-
06:01 PM Regression #13290 (Feedback): Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters
- There's not enough info here to troubleshoot this. Discussion of the issue may be continued on the forums: https://fo...
-
02:25 PM Regression #13290 (Resolved): Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters
- After upgrading from 2.6.0 to 2.7.0, my Captives Portal users are dropped randomly, having to re-authenticate... Ther...
-
04:20 PM Bug #13210 (Resolved): PPPoE server panics with multiple client connections
- Customer which was previously frequently hitting this issue reports it's been resolved after updating to the RC.
-
04:04 PM Bug #10352: RADIUS authentication fails with MSCHAPv1 or MSCHAPv2 when passwords contain international characters
- The issue is still present on 22.01-RELEASE
Any foreseen planning to fix this issue ?
Is someone working on it ? ma... -
01:03 PM Feature #13286: webConfigurator does not redirect to requested page after login
- I understand.
To be honest, one of my main reasons for wanting this merged was because my dashboard takes so darn l... -
12:52 PM Feature #13286: webConfigurator does not redirect to requested page after login
- Some pages require parameters to load the right view, so stripping the parameters isn't helpful.
It is not going t... -
10:18 AM Feature #13286: webConfigurator does not redirect to requested page after login
- But, again- nothing prevents a logged in user from bookmarking a page or recalling one from history that actions some...
-
10:15 AM Feature #13286: webConfigurator does not redirect to requested page after login
- Doesn't have to be an attack, they could also do it unintentionally by bookmarking or hitting a page from their histo...
-
10:07 AM Feature #13286: webConfigurator does not redirect to requested page after login
- Not sure I follow how this makes it any less secure than it already is. If a user is logged in already, they can stil...
-
08:49 AM Feature #13286 (Rejected): webConfigurator does not redirect to requested page after login
- This is done on purpose for security reasons. Until the entire GUI is purged of any page that takes action on GET, th...
-
08:34 AM Feature #13286: webConfigurator does not redirect to requested page after login
- PR: https://github.com/pfsense/pfsense/pull/4599
-
08:33 AM Feature #13286 (Rejected): webConfigurator does not redirect to requested page after login
- Something that has bugged me for a while now is that if you are logged out of pfSense, and request a "deep" page e.g....
-
10:46 AM Bug #13289 (Resolved): Attempting to restore a 0 byte ``config.xml`` prints an error that the file cannot be read
- When attempting to restore an empty config.xml file (0 bytes) the GUI prints an error saying the file cannot be read ...
-
10:36 AM Bug #13288 (New): Encode FreeRADIUS Custom Options
- Currently, fields in the FreeRADIUS package such as @varusersreplyitemsadditionaloptions@ are not encoded in config.x...
-
10:33 AM Feature #13287 (New): Encode OpenVPN Custom Options
- The @custom_options@ field for OpenVPN configurations is currently not encoded. This should be encoded in base64.
-
07:46 AM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
- Both @auth-gen-token@ and @reneg-sec@ are useful in different ways, we should expose and (optionally) use both. Thoug...
-
07:21 AM Bug #13285: Uncaught ArgumentCountError to function openvpn_kill_client()
- Okay, thank you Jim for test and quick feedback.
-
07:20 AM Bug #13285 (Duplicate): Uncaught ArgumentCountError to function openvpn_kill_client()
- There are no errors when terminating clients on the status page or widget on 22.05/2.7.0 snapshots.
-
07:11 AM Bug #13285: Uncaught ArgumentCountError to function openvpn_kill_client()
- Sorry, found https://redmine.pfsense.org/issues/12817 but it not mention status page, not sure 12817 also resolve Ope...
-
07:09 AM Bug #13285 (Duplicate): Uncaught ArgumentCountError to function openvpn_kill_client()
- Killing session for user using OpenVPN Dashboard Widget or using OpenVPN Status page do not works.
On Widget next er...
06/19/2022
-
11:11 PM Bug #5413: Reduce disruptions when changing DNS records from DHCP leases in Unbound
- Hey Netgate - I get the feeling this affects far more customers than you think.
Can this be assigned to someone to a... -
09:34 PM Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes
- Just updated "PR #4595":https://github.com/pfsense/pfsense/pull/4595 with the new mitigation changes. Testers & feedb...
-
12:20 PM Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes
- It appears we are out of luck on having @devd@ fire events for IP address changes. There is a commit: https://reviews...
-
06:42 PM pfSense Plus Bug #13283 (Not a Bug): PBR forcing traffic out one WAN and back into another WAN with NAT Reflection Fails
- Tested this.
With that PBR in place, even traffic that is being NAT'ed from the NAT Reflection rule will be caught... -
05:53 PM Bug #13243 (Pull Request Review): OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
-
02:18 PM Bug #13243: OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
- This fixes the original issue:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/821
Reiner Keller wr... -
05:52 PM Feature #12466: Option to Disable Renegotiation timer in OpenVPN Server
- It's better to implement @--auth-gen-token [lifetime]@
> --auth-gen-token [lifetime]
> After successful user/passwo... -
05:38 PM Feature #12982: Add support for RFC7499 in RADIUS library.
- So are you saying that pfsense/freeRadius will not be able to go more then 68 rules? any software you know would be ...
-
03:58 PM Feature #12982: Add support for RFC7499 in RADIUS library.
- I was able to replicate this with a simpler setup by adding a custom option to the @Additional RADIUS Attributes (REP...
-
12:10 PM pfSense Packages Feature #13284 (New): Option to define "Issuer" in OPT configuration.
- All QR codes are presently identifying as "FreeRADIUS(username).
Please add an optional variable in user->One-Time... -
11:11 AM Bug #13280: Entries for ``net.link.ifqmaxlen`` duplicated in ``/boot/loader.conf``
- I'm seeing this as well on a VM with @22.05.r.20220609.1919@....
06/18/2022
-
05:48 PM pfSense Plus Bug #13283 (Not a Bug): PBR forcing traffic out one WAN and back into another WAN with NAT Reflection Fails
- Assuming the following configuration:
2 WAN interfaces WAN1 and WAN2
One LAN interface with Host A and Host B.
H... -
02:34 PM Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries
- It seems this issue has gotten worse somewhere along the line similar to how others are describing it. Tables now lo...
-
02:25 PM Bug #13282 (Resolved): Alias content is sometimes incomplete if the firewall cannot resolve an FQDN in the alias
- If an invalid FQDN is present in an alias before a valid one, the entire table will be empty.
For an example, if...
06/17/2022
-
07:24 PM Bug #13281 (Duplicate): Crash Reporter
- Duplicate, and already fixed: #12817
-
06:49 PM Bug #13281 (Duplicate): Crash Reporter
- Crash report begins. Anonymous machine information:
amd64
12.3-STABLE
FreeBSD 12.3-STABLE plus-RELENG_22_01-n20... -
04:10 PM Revision 3f4ee315: Template the versions as well
-
03:31 PM Bug #13280 (Resolved): Entries for ``net.link.ifqmaxlen`` duplicated in ``/boot/loader.conf``
Using 22.05-RC 22.05.r.20220617.0613 Duplicate entries appear in /boot/loader.conf
Here are the contents of my loa...-
08:36 AM Bug #13243: OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display
- Additional to this "informal" bug the ruleset given by Radius parameter isn't stored and when the renegiotion is done...
-
07:34 AM Bug #13278 (Needs Patch): OpenVPN dynamic gateway created incorrectly when not pulling routes or server pushes no routes
- We're aware of this, but it's an OpenVPN bug, not a bug in our code. As you see, the variables are unpopulated even w...
-
01:10 AM Bug #13278: OpenVPN dynamic gateway created incorrectly when not pulling routes or server pushes no routes
- This appears to be happening because OpenVPN doesn't populate these environment variables when either option is selec...
-
07:09 AM Bug #13279 (New): DHCP config override affects Gateway installation.
- If you check Configuration Override on the interface in the DHCP Client Configuration section, then open Status => In...
-
07:02 AM Regression #13274 (Resolved): OpenVPN override IPv4 tunnel network field changing value improperly
- Working as expected on the latest build. The exact tunnel network address and mask remain, and the resulting @ifconfi...
06/16/2022
-
11:54 PM Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes
- @dem I believe I'm facing this exact issue, take a look at https://forum.netgate.com/topic/172849/rtsold-not-running-...
-
10:31 PM Bug #13278 (Needs Patch): OpenVPN dynamic gateway created incorrectly when not pulling routes or server pushes no routes
- IF: I configure OpenVPN client and set the "Don't pull routes" check box
OR
IF: I include the advanced option: pull... -
09:30 PM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
- +1 Also having this problem : 2.6.0-RELEASE (amd64)
-
07:50 PM Bug #13277 (Duplicate): IGMP Proxy webConfigurator Page Always Produces Error
- Whether your IGMP Proxy settings are correct or not, there is always an error stating "There was a problem applying t...
-
07:48 PM Bug #13276 (New): IGMP Proxy Error Message for Logging Links to System Log Instead of Routing Log
- If you try to apply a setting that won't apply in IGMP Proxy, it will state "There was a problem applying the changes...
06/15/2022
-
03:16 PM Revision 230b2303: Fix OpenVPN override TN handling. Fixes #13274
-
10:42 AM pfSense Docs New Content #13211: OpenVPN DCO Documentation
- Updates: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/989cfa8946010d913fddeebc8d8fe740ba409390
-
10:25 AM Regression #13274 (Feedback): OpenVPN override IPv4 tunnel network field changing value improperly
- Applied in changeset commit:230b23033a898633681ef0dde4df8f63a2b7258c.
-
10:13 AM Regression #13274 (Resolved): OpenVPN override IPv4 tunnel network field changing value improperly
- For an override on a subnet topology VPN, the mask on the tunnel network in the override has to reflect the subnet ma...
-
03:44 AM Bug #11629: PPPoE WAN IP address different than expected when set static by ISP
- We've installed 22.05 on our Netgate 2100 appliance and it's still assigning the wrong IP address to the WAN interfac...
06/14/2022
-
01:14 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
- That one change looks to have solved the issue for me.
Testing in:... -
01:04 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
- Well... seeing that would have saved me a bunch of debugging...
-
12:41 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
- For reference, the redmine for that issue is here:
https://redmine.pfsense.org/issues/13156 -
12:19 PM pfSense Packages Bug #13154: pfBlocker causing excessive CPU load
- The issue apparently stems from the output of "pfctl -vvsr" changing in 22.05. Due to the change in output, pfBlockNG...
-
11:07 AM Bug #13273 (New): dhclient can use conflicting recorded leases
- dhclient will attempt to use a previously successful recorded lease if it cannot contact a dhcp server.
However it w... -
08:00 AM pfSense Packages Bug #13180: High CPU Utilization with pfb_filter since pfBlockerNG update to devel 3.1.0_4
- Looks like a duplicate or related to #13154
-
06:53 AM Regression #13265 (Resolved): Authentication using Voucher cause SQLite3 syntax error
- No errors on the latest snapshot. Voucher is accepted, no PHP error, voucher shows in active users and active voucher...
06/13/2022
-
08:16 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- Even with changing the rule to use the pfBlockerNG aliases directly, the issue persists - that is I'm not seeing any ...
-
06:16 PM pfSense Packages Bug #13154 (Confirmed): pfBlocker causing excessive CPU load
- Still seeing this in 2.7/22.05 so it seems unlikely to be a symptom of #12827 which is mostly fixed there.
The CPU... -
02:04 PM Revision 8ba70cfc: Set CP pipeno consistently when null. Fixes #13265
-
11:29 AM Feature #12982: Add support for RFC7499 in RADIUS library.
- Ok, so do you know roughly when "someone" can look at this issue further?
-
10:37 AM Feature #12982: Add support for RFC7499 in RADIUS library.
- I can't find where @[ciscoavpair]@ is being set in the code - the only reference I could find was in @pear-Auth_RADIU...
-
11:11 AM Bug #13262 (Resolved): File browser on ``diag_edit.php`` does not encode filenames before display
- Tested on...
-
10:27 AM Bug #13272 (Pull Request Review): Voucher CSV output has leading space before voucher code
- MR: https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/818
Diff attached for wider testing.
-
10:14 AM Bug #13272 (Resolved): Voucher CSV output has leading space before voucher code
- When downloading a CSV file for a voucher roll, each voucher has a leading space, so when copying and pasting it gets...
-
09:33 AM Regression #13265: Authentication using Voucher cause SQLite3 syntax error
- Merged into Plus and CE master branches and picked back into 22.05.
-
09:10 AM Regression #13265 (Feedback): Authentication using Voucher cause SQLite3 syntax error
- Applied in changeset commit:8ba70cfcf6c86db2c52577bf543a6b72fc2da9e7.
-
08:11 AM Regression #13265 (In Progress): Authentication using Voucher cause SQLite3 syntax error
- It should be noted that the authentication succeeds and the user can get out, is listed on the active vouchers tab, b...
-
08:23 AM pfSense Packages Bug #12992 (Resolved): error: nbproc is not supported any more since HAProxy 2.5
-
08:17 AM pfSense Docs New Content #13270: OpenVPN client gateway is incorrect when the server does not push routes
- This has always been the case with OpenVPN. It doesn't populate the environment variables because it doesn't think it...
-
05:06 AM pfSense Packages Bug #13271 (Bogus): I got 'The WireGuard service is not running.' after I upgraded my pfSense VM from 22.05.r.20220604.1403 -> 22.05.r.20220609.1919
- I've got this issue on one of my pfSense VM after upgrade from 22.05.r.20220604.1403 -> 22.05.r.20220609.1919 ('upgra...
06/12/2022
-
10:32 PM Todo #13268: Dynamically adjust the interface name maximum width in the login banner
- I wanted to auto size the columns based on the terminal width, but the shell doesn't seem to export the @$COLUMNS@ va...
-
05:09 PM Todo #13268 (Resolved): Dynamically adjust the interface name maximum width in the login banner
- small change to add some width and better align things if interface names are longer than just "WAN", "WAN2" etc.
... -
07:14 PM pfSense Docs New Content #13270 (Resolved): OpenVPN client gateway is incorrect when the server does not push routes
- If @IPv4 Local network(s)@ is empty on the server (and no custom options exist to push routes), the client @ovpn-link...
-
02:48 PM Bug #13267 (New): dpinger continues to run on OpenVPN gateway after OpenVPN service is stopped.
- Tested on @22.05.r.20220609.1919@.
# Configure OpenVPN client on pfSense
# Assign an interface to the OpenVPN cli... -
01:44 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
- * removed @case 111)@
* consistency of single/double quotes
* removed a couple of stray @;@ s -
01:21 PM Bug #12920: Gateway behavior differs when the gateway does not exist in the configuration
- Updating OP with new symptoms.
-
01:00 PM Revision f185e661: a few updates for the console menu
- add full pathnames to all binaries (before some were and some weren't)
less forking for process checking, instead of ... -
11:22 AM Feature #12973: Playback script to perform a configuration upgrade on an arbitrary ``config.xml`` file
- Just noting for anyone looking, the script is named @upgradeconfig@ not @updateconfig@ as in Chris' OP.
-
11:14 AM pfSense Plus Bug #13074: AES-GCM with SafeXcel on Netgate 2100 causes MBUF overload
- I believe I have hit this as well, 2100 to 7100 GCM tunnel. Is there an upstream FreeBSD bugreport? I believe the fac...
-
11:11 AM Bug #13252: reduce frequency of php-fpm socket connection attempts from check_reload_status
- I may have also experienced this on an SG-2100 yesterday. Upgraded from 21.05.1 to 22.05-RC.
After the upgrade, CP... -
08:45 AM pfSense Packages Bug #12992: error: nbproc is not supported any more since HAProxy 2.5
- This should be closed since it's been merged
-
12:04 AM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- Pushed more updates to my "PR #4595":https://github.com/pfsense/pfsense/pull/4595 (see over there for details).
I...
06/11/2022
-
07:01 PM pfSense Plus Bug #13206: SG-3100 LED GPIO hangs
- Daniel Subert wrote in #note-2:
> Hi Jim,
>
> Thanks for the update.
>
> As this issue is already being tracked int... -
06:45 PM Revision 08e9bcfd: add waning infobox if duplicate IP is entered in DHCP staticmaps
-
05:43 PM Regression #13265: Authentication using Voucher cause SQLite3 syntax error
- Here is the crash report from my firewall:
Crash report begins. Anonymous machine information:
amd64
12.3-STA... -
05:41 PM Regression #13265: Authentication using Voucher cause SQLite3 syntax error
- I can confirm this issue is present in the RC3 build of 22.05.
-
05:08 AM Regression #13265 (Resolved): Authentication using Voucher cause SQLite3 syntax error
- Errors:
Crash report begins. Anonymous machine information:
amd64
12.3-STABLE
FreeBSD 12.3-STABLE plus-RELEN... -
05:43 PM Revision b707f4d8: fix log spew when deleting static DHCP maps not in arp table, redmine #13263
-
04:51 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
- Looks good to me.
-
01:50 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
- I pushed a revised version, looks like this now
!clipboard-202206111450-srubn.png!
-
02:17 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- BBcan177 . wrote in #note-3:
> There seems to have been a change in the pfctl -vvsr output.
>
> The patch below seem... -
09:11 AM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- Is there a particular reason for that? I'm using a custom alias to keep rule management easier, and to avoid filter l...
-
09:02 AM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- Marcos Mendoza wrote in #note-7:
> > @256 block drop in log quick on ixv5 inet from any to <h_blocklist:19320> label...
06/10/2022
-
10:47 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- > @256 block drop in log quick on ixv5 inet from any to <h_blocklist:19320> label "USER_RULE: pfb_blocklist" label "i...
-
07:49 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- Marcos Mendoza wrote in #note-4:
> Tested change on @22.05@ RC with pfBlockerNG-devel @3.1.0_4@; floating block rule... -
04:29 PM Feature #13264 (New): IPSec Phase2 select multiple PFS key groups
- A user can currently select multiple IPSec encryption and hash algorithms, so it would make sense to add the ability ...
-
12:56 PM Revision 1b5919c7: Encode filename browser.php. Fixes #13262
-
11:36 AM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- I've been running with the PR above for 2 days now, it's survived multiple reboots, and unplug/replug of the secondar...
-
11:18 AM Todo #13263: Reduce log spam when deleting a static DHCP entry
- I made and tested this small patch: https://github.com/pfsense/pfsense/pull/4597
-
10:55 AM Todo #13263 (Resolved): Reduce log spam when deleting a static DHCP entry
- This is not a huge priority, but when deleting static DHCP mappings for devices that are offline / not on network and...
-
10:18 AM Bug #13258 (Pull Request Review): Hidden menu option ``100`` incorrectly handles HTTPS detection
-
08:05 AM Bug #13262 (Feedback): File browser on ``diag_edit.php`` does not encode filenames before display
- Applied in changeset commit:1b5919c769ba736b44819f71ee1ddce06e2a50c5.
-
07:56 AM Bug #13262 (Resolved): File browser on ``diag_edit.php`` does not encode filenames before display
- The file browser on @diag_edit.php@ does not encode filenames before display.
A user who can create files with arb... -
03:39 AM pfSense Packages Bug #13261 (Resolved): Input validation rejects empty ``sudo`` command list, but GUI text says it can be empty
- The help text says, " By default the command is "ALL" meaning the user can run any commands. Leaving the commands fi...
06/09/2022
-
11:20 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- The patch works for me on LAN and WAN rules on 22.05 RC using pfBlockerNG-devel 3.1.0_4. I don't have floating rules ...
-
11:08 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- Tested change on @22.05@ RC with pfBlockerNG-devel @3.1.0_4@; floating block rule on tagged traffic with description ...
-
09:58 PM pfSense Packages Regression #13156: pfBlockerNG IP block stats do not work
- There seems to have been a change in the pfctl -vvsr output.
The patch below seems to fix the issue, but would be ... -
02:51 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
- Ok I updated the PR to bring back the hidden option 100 / links browser. I think this is good. Unfortunately when I t...
-
01:31 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
- I haven't used @links@ against in the GUI in quite some time so I'm not sure if it still works. If it does we may as ...
-
01:28 PM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
- PR: https://github.com/pfsense/pfsense/pull/4596
-
11:44 AM Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection
- I can't think of any benefit from fixing it; better to remove it.
-
02:07 PM Feature #10446: VIP address is not shown in firewall rules
- Marcos Mendoza wrote in #note-5:
> Better to stick with using aliases. VIPs are more for service bindings.
This wil... -
11:38 AM Feature #10446: VIP address is not shown in firewall rules
- Silmor Senedlen wrote in #note-4:
> Silmor Senedlen wrote in #note-2:
> > I think it would be nice to be able to ... -
02:04 PM Feature #13260 (New): Add support for OpenVPN static-challenge
- When using Multi Factor authentication most OpenVPN clients offer a static-challenge option to make the client ask fo...
-
01:32 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
- I wanted to make the warning display in a "Yellow Box" too but I looked through the code and couldn't see an easy way...
-
12:41 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
- I don't think we should change the default behavior/add extra steps to reach the current behavior.
Something that ... -
12:36 PM Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments
- Thank you for the contributions!
In general, it's best to avoid first/second person perspective. A yellowish warni... -
07:07 AM Regression #11570 (Pull Request Review): Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
-
01:42 AM pfSense Packages Bug #12765 (Resolved): AutoConfigBackup should ignore Lightsquid/lightparser cron changes
- I tested with Lightsquid version 3.0.6_9.
It works fine.
I am marking this ticket resolved.
06/08/2022
-
11:17 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- I submitted a PR: https://github.com/pfsense/pfsense/pull/4595 that may help some of the cases being hit here.
-
05:02 PM pfSense Packages Bug #13259 (Not a Bug): Reply-to rules are not created with wireguard 0.1.6_1
-
04:57 PM pfSense Packages Bug #13259: Reply-to rules are not created with wireguard 0.1.6_1
- Sorry, stupid mistake on my side, it is required to set an upstream gateway on the interface config in order for the ...
-
04:53 PM pfSense Packages Bug #13259 (Not a Bug): Reply-to rules are not created with wireguard 0.1.6_1
- Hello,
I have noticed that reply-to rules are not created for rules in a wireguard interface even if it is assigne... -
03:33 PM Feature #10446: VIP address is not shown in firewall rules
- Silmor Senedlen wrote in #note-2:
> I think it would be nice to be able to select VIP address from list(which autom... -
01:35 PM pfSense Packages Bug #12808 (Resolved): Wireguard Gateways disabled when Wireguard Service is Manually Restarted
-
10:02 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
- Cherry picked this commit to RELENG_2_6_0 ports tree. Look for a package update.
Edit: v0.1.6_2 is available in CE 2... -
09:31 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
- → luckman212 wrote in #note-13:
> @Valmor if you add the System Patches package and then add a patch using this url:... -
07:54 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
- @Valmor if you add the System Patches package and then add a patch using this url:
https://github.com/theonemcdona... -
07:46 AM pfSense Packages Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
- I have similar issue on pfSense 2.6.0-RELEASE.
Configured WireGuard tunnel and set a static route.
After reboot of ... -
12:40 PM pfSense Packages Bug #13050 (Resolved): ACME update EasyDNS inline api sign-up link
- It looks fine on Acme package version 0.7.1_1.
I am marking this ticket resolved. -
12:04 PM Bug #13258 (Resolved): Hidden menu option ``100`` incorrectly handles HTTPS detection
- I was poking around in @/etc/rc.initial@ to try to fix something else and I noticed a hidden menu item 100
This op... -
10:38 AM Bug #13257: Exporting a PKCS#12 file from the certificate manager does not use the intended encryption algorithm
- See also: #13255
-
10:35 AM Bug #13257 (Resolved): Exporting a PKCS#12 file from the certificate manager does not use the intended encryption algorithm
- In source:src/usr/local/www/system_certmanager.php#L198 or thereabouts it sets a parameter @encrypt_key_cipher@ inten...
-
09:54 AM Feature #13256 (Resolved): Better handling of duplicate IP addresses in static DHCP assignments
- summary:
In 2018 code that prevented duplicate IPs from being used as static DHCP mappings was removed. There are ... -
09:15 AM Bug #13088: Rapidly clicking certain options on OpenVPN Client Overrides can cause hide/show field behavior to invert
- I replicated the issue with inverted results when repeating clicks too quickly on 22.05.r.20220604.1403.
After app... -
08:52 AM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
- I reproduced the issue on 22.01 and 22.05.r.20220604.1403 with the same logs.
-
08:36 AM pfSense Packages Todo #13255 (Resolved): Set PKCS#12 algorithm when exporting OpenVPN ZIP or Windows bundles
- Currently when crafting a PKCS#12 archive the OpenVPN Client Export package does not set a specific encryption algori...
-
07:48 AM Bug #13254 (Resolved): DNS resolver does not update its configuration or reload during link down events
- How to reproduce:
1) Configure the interface with Static IPv4
2) Select this interface in the "Network Interfaces...
06/07/2022
-
08:55 PM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- Tested on 22.05 RC.
I was not able to replicate this initially with WAN1 as DHCP and WAN2 as static. After testing a... -
10:00 AM Regression #11570: Gateway monitoring services is not always restarted on interface events, which may prevent a WAN from recovering back to an online state
- I experienced this this morning, on 22.05.b.20220531.0600
- dpinger showed my DHCP6 gateway as "down"
- I ran @pgre... -
01:04 PM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
- +1 Having this issue since 16th May on two separate boxes CE. Upgraded to 2.6 and still the same. switch to DynDns an...
-
08:50 AM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
- +1 Also having this problem
-
12:25 AM pfSense Packages Bug #10436: softflowd no longer sends flow data after upgrade (v0.9.9_1 -> v1.0.0)
- I'm starting down a path that involves softflowd. Does anyone know if this issue persists with the latest snaps?
06/06/2022
-
11:17 PM Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error
- any updates on this? I am getting the same error too
-
06:55 PM pfSense Packages Feature #12963: Run nmap scans in the background
- I can't think of a privacy issue for either - both locations are readable by everyone. The Packet Capture page is in ...
-
02:55 PM pfSense Packages Feature #12963: Run nmap scans in the background
- Marcos Mendoza wrote in #note-24:
> Looks good from the testing I've done. Only suggestion I have is that the result... -
02:58 PM Bug #13253 (Resolved): ``dhcp6c`` is not restarted when applying settings when multiple WANs are configured for DHCP6
- After #6880 it seems that when applying settings on multiple WANs, @dhcp6c@ is not restarted so the new configuration...
-
02:55 PM Bug #13061 (Resolved): Gateway events for IPv6 affect IPv4 OpenVPN instances and vice versa
- Seems to be doing the right thing. IPv6 OpenVPN tunnel kept going when the IPv4 gateway went down and back up. We can...
-
02:35 PM Bug #12733 (Resolved): Value of ``net.inet.ip.dummynet.*`` OIDs in ``sysctl`` are ignored
- The code for @dummynet_load_module()@ in source:src/etc/inc/util.inc#L3937 ensures the module is loaded before popula...
-
01:06 PM Bug #13252 (New): reduce frequency of php-fpm socket connection attempts from check_reload_status
- When troubleshooting an issue, I discovered that my system logs were rotating every couple of minutes, due to many of...
-
12:45 PM Bug #13251: pfTop bugs - backspace key vs CTRL_H, states column, rnr not functional
- Ok, fair enough but I do wonder - does backspace work for _anyone_ in this case? Because it appears undefined or at l...
-
12:37 PM Bug #13251 (Not a Bug): pfTop bugs - backspace key vs CTRL_H, states column, rnr not functional
- backspace vs ^H is almost always a terminal issue with your client and what it sends. Some things send ^H for backspa...
-
12:32 PM Bug #13251 (Not a Bug): pfTop bugs - backspace key vs CTRL_H, states column, rnr not functional
- I am not 100% sure but I believe there are bugs in the currently bundled version of pfTop. I opened a thread about th...
-
07:32 AM Todo #13250 (Resolved): Clean up DHCP Server option language
- Several options on the page have awkward or inconsistent wording
* "Denied clients will be ignored rather than rej... -
07:03 AM Bug #12878 (Incomplete): Traffic shaping by interface, route queue bandwidth inbound, out by a large factor.
-
07:02 AM Bug #13249: Running playback comands multiple times results in PHP error
- That is known and expected, they aren't designed to run more than once in the same session the way you are doing it. ...
-
05:41 AM Bug #12645: ``filterdns`` does not monitor remote IPsec gateways for IPv6 address changes
- It's under IKE Endpoint Configuration ----> Remote Gateway (IPV6), to check if FQDN for AAAA record can be used to es...
-
04:17 AM Bug #12645 (Resolved): ``filterdns`` does not monitor remote IPsec gateways for IPv6 address changes
- Tested on 22.05-RC (built on Sat Jun 04 14:22:59 UTC 2022)
I'm not sure what to test here but there is no *add_hos...
Also available in: Atom