Activity
From 04/19/2024 to 05/18/2024
05/18/2024
-
08:07 PM pfSense Plus Feature #15506 (Duplicate): GEOM mirrors from previous UFS installs break ability to install with ZFS RAIDZ1 "No Disks Available"
- This is similar to the problems with the offline installer as outlined here, but is also relevant to the netinstaller...
-
04:58 PM Revision 577cd0eb: Set correct value when toggling CARP maintenance
-
12:47 PM Bug #15449: IPsec VTI static routes may not be added after the system boots
- Another customer is experiencing related issues, see https://forum.netgate.com/topic/188214/vti-gateways-in-24-03 beg...
-
12:22 PM Bug #15449: IPsec VTI static routes may not be added after the system boots
- I used customer's status output file to create the same config on my lab (as Lev done) but I still wasn't able to rep...
-
12:01 PM pfSense Packages Bug #15505 (New): Traffic graphs inaccurate when using Limiters (FQ_CODEL)
- this has been ongoing for over a year now, i'm not sure what the issue is.
in short what happens is the traffic g... -
05:42 AM Feature #15504: PPPoE support for online installer
- Net installer with PPPoE support is under development.
-
04:27 AM Feature #15504 (Duplicate): PPPoE support for online installer
- The new installer requires internet access to function, but for some of us we rely on PPPoE in order to get a WAN con...
05/17/2024
-
09:13 PM pfSense Plus Bug #15196: AWS ena interfaces can become unstable/stop responding
- Chris W wrote in #note-15:
> HS# 2718685720 is a 24.03 guest which was upgraded from 23.09.1. Only when on 24.03 did... -
02:19 PM pfSense Plus Bug #15196: AWS ena interfaces can become unstable/stop responding
- new case #2733381806
client will run the script when able to -
02:04 PM pfSense Packages Feature #15501: Squid COSS filesystem
- Correction: per developer response
“Squid does not support COSS cache_dirs since v3.5. If Squid in question does ... -
01:30 PM Bug #15502 (Feedback): Proxy variables in ``crontab`` contents are improperly formatted
- Applied in changeset commit:45419ed469e182e97b72f534ff4a79b6f531b06e.
-
01:23 PM Bug #15502 (Pull Request Review): Proxy variables in ``crontab`` contents are improperly formatted
- MR: https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/1150
-
01:30 PM Bug #15471: Memory leak in pfSense module function ``pfSense_get_ifaddrs()``
- A quick test of the function looks good compared to my previous tests, but I'd prefer to keep this open for now until...
- 01:24 PM Revision 45419ed4: Add newlines to crontab proxy variables. Fixes #15502
-
01:23 PM Bug #15503: udp6_bind kernel panic
- I took a very quick look. The faulting code in6_pcbbind+0x360 translates to /var/jenkins/workspace/pfSense-CE-snapsho...
-
12:39 PM Bug #15503 (New): udp6_bind kernel panic
- We have seen a few reports of kernel panics with services attempting to listen for requests on link-local IPv6 addres...
-
08:31 AM Bug #15009: System>Update page menu uses incorrect internal URL
- I have the same issue after reboot the update menu is pointing again to the other location. https:/.../pkg_mgr_insta...
-
07:05 AM Bug #15366: Ethernet rules are not blocking the ARP inside the bridge
- I retested this with 24.03 with the Interface Bound States enabled, and the result was exactly the same.
05/16/2024
-
11:06 PM pfSense Packages Feature #15501: Squid COSS filesystem
- “The Cyclic Object Storage Scheme (costs) is an attempt to develop a custom file system for Squid.”
Ref: squid the... -
09:53 PM pfSense Packages Feature #15501 (Rejected): Squid COSS filesystem
- Hello Coss is missing from the new Squid package it is not listed as an option. This should work great with Squid 6.6...
-
10:06 PM Bug #15502 (Resolved): Proxy variables in ``crontab`` contents are improperly formatted
- On systems with an upstream proxy configured lines are added to the crontab so commands run there see the appropriate...
-
06:15 PM pfSense Plus Bug #15196: AWS ena interfaces can become unstable/stop responding
- HS# 2718685720 is a 24.03 guest which was upgraded from 23.09.1. Only when on 24.03 did the problem begin, however.
-
08:14 AM pfSense Plus Bug #15196: AWS ena interfaces can become unstable/stop responding
- There's still very little to go on here.
Let's start by seeing if we can identify what's causing the high CPU load... -
04:32 PM Bug #15500 (New): Hanging connections with failing over to high availability node when floating rule is matched in >= 2.7.1
- - Two freshly installed instances, both with identical hardware running pfSense 2.7.0
- Each with 3 interfaces ass... -
04:16 PM Bug #15066 (Duplicate): PHP allocation failure in pfsense-utils.inc
- The root issue here is probably #15471. The function @get_interface_info(@) ends up calling @get_interface_addresses(...
-
03:49 PM pfSense Packages Bug #7039: HAProxy backend configuration does not handle intermediate CAs properly
- almost 3 years later I have the same problem.
The PR does not seem to be in the current package versions (0.63_2). -
01:23 PM Bug #15471: Memory leak in pfSense module function ``pfSense_get_ifaddrs()``
- Was able to reproduce on 24.03 and 2.7.2 CE via calling the leaking function in endless loop.
tested on:
Version 2.8... -
11:32 AM Bug #15449 (Confirmed): IPsec VTI static routes may not be added after the system boots
05/15/2024
-
03:41 PM pfSense Plus Bug #15499: Manually verifying the boot environment makes config changes
- See: https://forum.netgate.com/topic/188179/24-03_1-traffic-graphs-does-not-keep-its-configuration
-
03:36 PM pfSense Plus Bug #15499 (New): Manually verifying the boot environment makes config changes
- If a user connects to the webgui before the automatic BE verification has run at boot they are presented with the man...
-
03:21 PM pfSense Docs Todo #15497: Add a bit more context to Gateway monitoring Action
- I agree that more details about gateway monitoring actions would be helpful.
Expanding on this, it would be helpfu... -
01:05 PM pfSense Packages Feature #15498 (Rejected): Add speedtest-cli to packages
- While some find it useful, it isn't a great metric and it is not a practice we want to encourage. Anyone that wants t...
-
03:28 AM Regression #14833: OpenVPN client process in bridged tap mode fails after 2.7.0 CE upgrade
- Confirm pfSense 2.7.2. I set up the Openvpn bridge on a clean configuration. When changing the parameters of the Open...
05/14/2024
-
10:10 PM pfSense Packages Feature #15498 (Rejected): Add speedtest-cli to packages
- I've been using the dashboard widget created by Leon Straathof on several pfSense instances and it works great.
http... -
09:42 PM pfSense Packages Feature #15397: Wazuh Agent
- Adding Wazuh to packages would be nice. I'm using it on several instances of pfSense with no issues.
-
06:26 PM Revision a976c08c: Reapply "Add zsh to the list of packages to build"
- This reverts commit 3d4cab4078a9276446d847612c97a52c328fd965.
The plist fix has landed and merged from upstream -
01:48 PM pfSense Docs Todo #15497 (Closed): Add a bit more context to Gateway monitoring Action
- https://docs.netgate.com/pfsense/en/latest/routing/gateway-configure.html
Section:Disable Gateway Monitoring Actio... -
01:39 PM pfSense Packages Bug #15496: Traffic Totals: empty Data Summary
- I've removed the database, and restarted vnstatd. After it obtained some data again I do get the Data Summary values ...
-
01:22 PM pfSense Packages Bug #15496: Traffic Totals: empty Data Summary
- Kristof Provost wrote in #note-4:
> The relevant package has been installed for a very long time, so it's not a lack... -
01:15 PM pfSense Packages Bug #15496: Traffic Totals: empty Data Summary
- The relevant package has been installed for a very long time, so it's not a lack of data at least.
Interestingly i... -
12:28 PM pfSense Packages Bug #15496: Traffic Totals: empty Data Summary
- I can't reproduce any issue here currently. Seems to be OK on Plus 24.03 amd64 and arm64, and CE 2.8 Snapshots (at le...
-
11:38 AM pfSense Packages Bug #15496: Traffic Totals: empty Data Summary
- This was observed on 24.03, on an 2100.
-
11:38 AM pfSense Packages Bug #15496 (New): Traffic Totals: empty Data Summary
- The traffic totals page (i.e. the vnstat output) shows the traffic graph (with what appears to be correct data), but ...
05/13/2024
-
10:10 PM pfSense Plus Bug #15196: AWS ena interfaces can become unstable/stop responding
- Another instance. HS# 2718685720
-
06:56 PM pfSense Packages Bug #15061 (New): acme.sh nsupdate with challengealias is failing in certain cases
- Change reverted.
-
09:21 AM pfSense Packages Bug #15061: acme.sh nsupdate with challengealias is failing in certain cases
- Hi.
For me, this was working for years and now it stopped.
See forum for more info: https://forum.netgate.com/top...
05/12/2024
-
02:47 AM Feature #15492: Test if storage/eMMC is actually writable underneath ZFS
- I can confirm that if the eMMC controller is alive, but the flash chips refuse to accept writes, there is no messages...
-
02:45 AM Regression #15030: Keymap Layout Options No Longer Provided
- Of note the Netgate Installer also is affected by this. Keyboard layout doesn't appear to be a prompted item, which ...
-
02:43 AM Regression #15430: Interface-bound state policy does not handle IPsec VTI traffic as expected when filtering on ``enc0`` interface
- I can confirm this behavior.
Given that VTIs under the default filter mode with the default firewall rules will ... -
02:40 AM pfSense Plus Bug #15303: dpinger service does not always switch from Pending to Online
- To summarize current ways this happens:
1. VTI tunnels
2. OpenVPN Client or Server interfaces that are assigned t... -
01:14 AM pfSense Plus Bug #14005: SFP Interfaces not available with Traffic Shaper in v23.01
- shaping may not be supported on that driver and/or additional 'tuning' could be required, intel based sfp's (ix drive...
-
12:53 AM pfSense Plus Bug #14401 (Feedback): Changing from Switchport to Discrete Interface in VGA/Serial Console Breaks Port Status Monitoring
- 7100 on 24.03, reassigning WAN or LAN to ix0/1 from the console appears correctly adjust the port monitoring such tha...
-
12:24 AM pfSense Plus Regression #15494 (Confirmed): Reinstall Packages button reports another instance of ``pfSense-upgrade`` is running
- I am seeing the same on...
-
12:06 AM Bug #15495 (Closed): Upgrade fails on upstream bectl bug
- System: Netgate 6100
Online upgrade to 24.03. (HS# 2584018971)...
05/11/2024
-
05:02 PM pfSense Plus Regression #15494 (Resolved): Reinstall Packages button reports another instance of ``pfSense-upgrade`` is running
- Diagnostics>Backup&Restore>Reinstall packages button, after hitting confirm, eventually displays "Another instance of...
-
04:40 PM Bug #15493 (New): Kea sometimes provides an IP from the DHCP pool despite static mappings
- Tested on...
-
04:07 PM Bug #14933: Traffic Graph widget displays bandwidth usage values which are half the actual usage amount
- Steve Wheeler wrote in #note-12:
> https://github.com/pfsense/pfsense/pull/4677
I tested the patch against the:
<pr... -
03:47 PM Bug #14083: Adding MSS and MTU values on a LAGG VLAN interface breaks connectivity
- That patch appears to have done the trick, we have successfully booted completely with MTU/MSS values in place.
-
12:16 AM Bug #14083 (Pull Request Review): Adding MSS and MTU values on a LAGG VLAN interface breaks connectivity
-
12:16 AM Bug #14083: Adding MSS and MTU values on a LAGG VLAN interface breaks connectivity
- The looping issue seems to be triggered when there are at least two assigned VLAN interfaces with a LAGG parent, and ...
-
03:19 PM Regression #15439 (Confirmed): Incorrect icon on collapsed dashboard widgets
- I can confirm this on:...
-
03:04 PM pfSense Packages Regression #15469 (Confirmed): RRD Graphs height is smaller than expected
- I can confirm this behavior on:...
-
07:39 AM pfSense Packages Bug #15385 (Confirmed): PHP crash when exporting Apple profile, while IPsec P1 authentication method set to "Mutual Certificate"
- I can replicate this issue.
Tested against:...
05/10/2024
-
10:54 PM pfSense Plus Bug #15472: potential bug with the ath driver
- Side note this does not occur when "only" 802.11A is running. Example using Channel 165
-
08:07 PM Feature #15492: Test if storage/eMMC is actually writable underneath ZFS
- And/or Netgate Installer can test this.
-
06:25 PM Feature #15492 (New): Test if storage/eMMC is actually writable underneath ZFS
- It seems ZFS allows users to think their storage is writable even if it isn't:
https://forum.netgate.com/topic/18795... -
08:02 PM Regression #15470 (Resolved): Port forward rules created by ``miniupnpd`` do not expire
- With the fix, port mappings correctly automatically expire and can be removed on client request.
-
07:20 PM Bug #14000: PHP error with xmlrpc
- Jim Pingle wrote in #note-1:
> This is from an external utility hitting XMLRPC, most likely the Home Assistant integr... -
06:12 PM pfSense Docs Todo #15491 (New): Document dynamic gateway creation
- One may wish to create a dynamic gateway before the link is provisioned. This is possible by creating a gatewway with...
-
05:09 PM pfSense Docs Todo #15479 (Closed): Feedback on DNS — Creating Wildcard Records in DNS Forwarder/Resolver
- That isn't quite true exactly as stated, but I added some text to clarify what is happening in those cases and how to...
-
05:00 PM pfSense Docs Correction #15473 (Closed): Feedback on pfSense® software Configuration Recipes — Blocking External Client DNS Queries: Firefox
- It's clear as is -- that's what the "by default" part of that sentence means -- but I added a little more text to mak...
-
04:38 PM Bug #15487 (Not a Bug): Unable to ping nodes in remote side of tailscale
- Doesn't seem like there is an actionable bug here. It may just not be compatible with tailscale in the way you're try...
-
04:35 PM Bug #15486 (Duplicate): Unable to run Packet Captures on a tailscale interface in GUI on 2.7.2
- It's already fixed in the repo, there is nothing more to fix. We could maybe add a patch for that to system patches f...
-
04:34 PM Feature #15488: Add link from "Tracking ID" when editing a firewall rule to firewall logs filtered for that ID
- N.B. whoever implements this, it would have to utilize @usepost@ so it properly submits the form data, it can't just ...
-
09:44 AM Feature #15488 (New): Add link from "Tracking ID" when editing a firewall rule to firewall logs filtered for that ID
- Dear Brilliant pfSense DevTeam!
IDEA
Click on “Tracking ID” value on Rule edit page lead to open *Status* / *Syst... -
04:26 PM Bug #15490: Sanitize RFC 2136 Dynamic DNS update keys in ``status.php`` output
- Specifically the tag is @<keydata>@ that should be sanitized. (@dnsupdates/dnsupdate/<idx>/keydata@)
-
03:53 PM Bug #15490 (Resolved): Sanitize RFC 2136 Dynamic DNS update keys in ``status.php`` output
- The keys inside the <dnsupdates> should be sanitized because restoring the client's config for test purposes can caus...
-
02:53 PM Feature #15489 (New): Login email notification
- Please consider adding a Login email notification option in System\Advanced
-
01:26 PM pfSense Plus Bug #15418: Incorrect links to edit static mapping and WOL on DHCPv6 leases (status_dhcpv6_leases.php). URL parameter values missing.
- I couldn't replicate this either:
I can see the correct URL parameters "if" and "id." ... -
05:32 AM Bug #15449: IPsec VTI static routes may not be added after the system boots
- I finally replicated the issue by restoring the config from the status output file, the root cause is still unknown h...
-
12:40 AM pfSense Plus Bug #15196: AWS ena interfaces can become unstable/stop responding
- Another customer in ticket 2706080899 with this issue.
05/09/2024
-
11:14 PM Revision 63419d38: Add a speedtest alternative written in go
-
09:39 PM Bug #15487 (Not a Bug): Unable to ping nodes in remote side of tailscale
Unable to ping IPs in remote side of tailscale if I selected the source IP address while it is working with automat...-
09:24 PM Bug #15486 (Duplicate): Unable to run Packet Captures on a tailscale interface in GUI on 2.7.2
while this issue was fixed in 24.03 , it is still appearing in 2.7.2
related to https://redmine.pfsense.org/iss...-
08:06 PM Bug #15413 (Feedback): Kernel panic in HA nodes when under high load
- What is hoped to be the fix has been merged to our branches.
-
08:05 PM Bug #15481 (Feedback): File descriptor leak in ``bsnmpd``
- And that's been merged to our branches.
-
12:16 PM Bug #15481: File descriptor leak in ``bsnmpd``
- Upstream fix: https://cgit.freebsd.org/src/commit/?id=f1612e7087d7c3df766ff0bf58c48d02fb0e2f6d
-
10:07 AM Bug #15481 (Resolved): File descriptor leak in ``bsnmpd``
- A user reports seeing an unusual increase in the number of running processes.
The extra processes are all kernel/net... -
08:03 PM pfSense Packages Todo #15484: Show more characters of the Description column in the WireGuard peer tables
- Also, if you must truncate the Description cells, then when I hover over a truncated Description cell, it should show...
-
07:41 PM pfSense Packages Todo #15484 (New): Show more characters of the Description column in the WireGuard peer tables
- When viewing the table of WireGuard peers, some columns are truncated to make them all fit. I think the most importa...
-
08:00 PM pfSense Packages Todo #15485 (New): Usability and consistency of the WireGuard peer tables
- Suggestions to make the WireGuard Peer tables a bit more usable:
1) Make the tables sortable. I have 30 Peers and... -
07:33 PM Bug #14083: Adding MSS and MTU values on a LAGG VLAN interface breaks connectivity
- Sorry, I didn't get notified of your latest post. I take it the patch did NOT resolve the issue then, but you've iden...
-
12:51 AM Bug #14083: Adding MSS and MTU values on a LAGG VLAN interface breaks connectivity
- Thanks for the feedback - hopefully we'll have some better luck reproducing the issue now. In the meantime if it's no...
-
05:59 PM pfSense Plus Bug #15196: AWS ena interfaces can become unstable/stop responding
- another ticket with this issue
#2694269097 -
01:39 PM Bug #15482 (Rejected): NTP logic
- What you're describing would need to be a change made in the NTP daemon behavior, which is out of our control. Probab...
-
12:58 PM Bug #15482 (Rejected): NTP logic
- it seems to be the case that NTP back end interface querying is hierarchical and if the first rule it encounters fail...
-
01:15 PM Todo #15483: Update Unbound to 1.22.0
- If you "read the details":https://nlnetlabs.nl/news/2024/May/08/unbound-1.20.0-released/ that isn't really a vulnerab...
-
01:10 PM Todo #15483 (Resolved): Update Unbound to 1.22.0
- Update Unbound to version 1.20.0, as this newest version contains a fix for the DNSBomb vulnerability CVE-2024-33655.
-
12:34 PM Feature #15478 (Duplicate): Rule Seperators for NAT Rules.
- Duplicate of #7781
-
12:33 PM Bug #15480 (Rejected): IX polling driver
- Polling was removed because it was no longer useful on modern hardware the way it worked in the OS, which is still tr...
-
02:13 AM Bug #15480 (Rejected): IX polling driver
- hello i tried searching for this but found little information
this polling man page
https://man.freebsd.org/cgi/... -
12:21 PM Regression #15470 (Feedback): Port forward rules created by ``miniupnpd`` do not expire
- I've updated miniupnpd to the latest version and adjusted the libpfctl patch in https://gitlab.netgate.com/pfSense/Fr...
-
12:19 PM Bug #15471 (Feedback): Memory leak in pfSense module function ``pfSense_get_ifaddrs()``
- We array_init() 'addr' (which causes PHP to allocate memory), but potentially
break out before adding 'addr'... -
07:07 AM Bug #15449: IPsec VTI static routes may not be added after the system boots
- I'm not able to replicate it on 24.03.
-
06:40 AM Bug #15449: IPsec VTI static routes may not be added after the system boots
- Ticket for reference #2703470963 the SOs and steps included.
-
12:57 AM pfSense Docs Todo #15479: Feedback on DNS — Creating Wildcard Records in DNS Forwarder/Resolver
- edit: oh it does mention it, but more so in the DNS MASQ section, when i was doing this for unbound
i wonder if th... -
12:54 AM pfSense Docs Todo #15479 (Closed): Feedback on DNS — Creating Wildcard Records in DNS Forwarder/Resolver
- *Page:* https://docs.netgate.com/pfsense/en/latest/services/dns/wildcards.html
*Feedback:*
can we suggest that ...
05/08/2024
-
11:46 PM Bug #14083: Adding MSS and MTU values on a LAGG VLAN interface breaks connectivity
- This behavior started for me when I moved to 23.05 and persists through 24.03, and is actually worse on 24.03 than it...
-
11:20 PM Bug #14083 (Feedback): Adding MSS and MTU values on a LAGG VLAN interface breaks connectivity
- Part of the issue here has been solved with #9453. Some situations remain where things can break - see: https://redmi...
-
11:30 PM Bug #9453: Reconfiguring a parent LAGG interface breaks its VLANs
- Correct, 7100. I have uploaded the status report as well.
-
11:25 PM Bug #9453: Reconfiguring a parent LAGG interface breaks its VLANs
- Presumably you're running into this issue on a 7100; I've reopened that one for additional feedback. It would be help...
-
10:51 PM Bug #9453: Reconfiguring a parent LAGG interface breaks its VLANs
- I don't even know how I would assign and disable the interface, my bug was actually https://redmine.pfsense.org/issue...
-
10:35 PM Bug #9453: Reconfiguring a parent LAGG interface breaks its VLANs
- @Steve N
Do you have the parent lagg interface assigned and disabled? See:
https://redmine.pfsense.org/issues/15452 -
11:10 PM Bug #15452: Unexpected/Undefined behaviour of disabled interfaces
- Some parent interfaces like LAGGs are configured separately from the assigned interfaces page. The undefined behavior...
-
10:26 PM Regression #15470: Port forward rules created by ``miniupnpd`` do not expire
- Steve Wheeler wrote:
> Testing in 24.03 on a 3100 I added some test values with a 3600s lifetime:
> [...]
>
> 15... -
10:07 PM Feature #15478 (Duplicate): Rule Seperators for NAT Rules.
- Just as there are options for Labeled & Colored rule separators for organization in the Firewall Rules Web UI, can we...
-
08:24 PM pfSense Plus Bug #15472: potential bug with the ath driver
- Compex WLE200NX
-
02:49 AM pfSense Plus Bug #15472: potential bug with the ath driver
- Attached is swap crash report
-
02:47 AM pfSense Plus Bug #15472: potential bug with the ath driver
- Support ticket 2701044255
-
02:46 AM pfSense Plus Bug #15472 (New): potential bug with the ath driver
- I am having crash and system panics when the ath driver goes full tilt. I didn’t notice it until recently with change...
-
08:22 PM pfSense Packages Feature #11837: Increase field length of FRR Networks in Access Lists and Prefix Lists
- Jim (or anyone from the team), can we get this fixed?
If I knew how to expand the windows in PHP (or even knew PHP)... -
04:32 PM Feature #15476 (New): Allow listing and switching repo branches from the CLI
- Currently you can only set the current update repo branch from the webgui. Since upgrades now require opting into the...
-
04:14 PM Bug #15449: IPsec VTI static routes may not be added after the system boots
- So on one of the 4200s running 24.03 I have done the following:
1. Deleted static route to 192.168.5.0/24
2. Deleted... -
04:11 PM Bug #15449 (Incomplete): IPsec VTI static routes may not be added after the system boots
-
06:56 AM Bug #15449: IPsec VTI static routes may not be added after the system boots
- I've tested on 23.09.1
- I've added disabled WAN gateway which is not in the same subnet as a real WAN subnet is
-... -
04:04 PM pfSense Docs New Content #15475 (Rejected): Connect to console index page on ddocs
- Create a "Connect to console" index page with instructions for all Netgate models and add it to the Net Installer page.
-
04:01 PM pfSense Plus Feature #15474 (New): Support for VRRP
- FreeBSD supports the VRRP protocol.
Would it be possible to have VRRP replace CARP as a FHRP(first hop redundancy pr... -
10:00 AM pfSense Docs Correction #15473 (Closed): Feedback on pfSense® software Configuration Recipes — Blocking External Client DNS Queries: Firefox
- *Page:* https://docs.netgate.com/pfsense/en/latest/recipes/dns-block-external.html
*Feedback:*
The pfSense docu...
05/07/2024
-
05:13 PM Bug #9453: Reconfiguring a parent LAGG interface breaks its VLANs
- Steve Wheeler wrote in #note-16:
> I can't replicate that in 24.03. Setting the lagg0 interface MTU (after assigning... -
03:32 PM Bug #15466 (Needs Patch): Kea does not send a subnet mask in its inform response when requested by a client that isn't requesting an address allocation
- As far as I can see this may be a bug in Kea itself you may need to report upstream. The configuration appears to be ...
-
03:21 PM Bug #15328 (Confirmed): Changes in Kea DHCP interface pools may invalidate lease database content
- This appears to be a known issue in Kea, their documentation even warns about it:
https://kea.readthedocs.io/en/ke... -
02:32 PM pfSense Packages Bug #15459 (Closed): Memory leak affecting ``lcdproc_client.php``, eventually hits PHP memory limit and crashes
- I made some optimizations to the LCDProc client code to help here but the memory leak issue is still the primary root...
-
02:30 PM Bug #15471 (Resolved): Memory leak in pfSense module function ``pfSense_get_ifaddrs()``
- Moving this over from #15459 since it does not appear to be a problem in LCDProc but in the base system pfSense PHP m...
-
01:42 PM Regression #15470 (Resolved): Port forward rules created by ``miniupnpd`` do not expire
- Testing in 24.03 on a 3100 I added some test values with a 3600s lifetime:...
05/06/2024
-
07:19 PM pfSense Packages Regression #15469 (Confirmed): RRD Graphs height is smaller than expected
- At some point between Plus 23.09.1 and 24.03 the height of RRD graphs shrank. Might be from the jQuery update but it'...
-
06:12 PM pfSense Packages Bug #15459: Memory leak affecting ``lcdproc_client.php``, eventually hits PHP memory limit and crashes
- Drilling down into the affected functions above, they all call @pfSense_get_ifaddrs()@ one or more (or many!) times a...
-
06:08 PM Feature #15461: Support GRE Tunnel Key
- Feature Request sent to FreeBSD: https://forums.freebsd.org/threads/feature-request-gre-tunnel-in-bound-key.93358/
-
05:33 PM Feature #15461: Support GRE Tunnel Key
- Ok, in fact I need mainly the outbound key. Can you implement it at least partly for now?
Thanks for the response. -
12:51 PM Feature #15461 (Needs Patch): Support GRE Tunnel Key
- Support for GRE keys is not complete in FreeBSD at this time. FreeBSD GRE allows configuring an outbound key but not ...
-
06:05 PM pfSense Packages Feature #15468 (New): IS-IS protocol support
- FRR supports IS-IS.
I assume the FRR version on pfSense already supports so we just need a PHP wrapper for the GUI.
... -
03:38 PM pfSense Docs Correction #15467 (Rejected): Feedback on pfSense® software Configuration Recipes — Configuring CoDel Limiters for Bufferbloat
- 1. There are many other protocols besides TCP/IP which can consume large amounts of bandwidth, such as ESP for IPsec....
-
02:36 PM pfSense Docs Correction #15467 (Rejected): Feedback on pfSense® software Configuration Recipes — Configuring CoDel Limiters for Bufferbloat
- *Page:* https://docs.netgate.com/pfsense/en/latest/recipes/codel-limiters.html
*Feedback:*
hi i would like to s... -
03:37 PM pfSense Plus Bug #15460: Kernel routing SPD Database gets “supenetted” wrong from multiple P2’s
- Hi Jim. I stand corrected for calling it a bug. Thanks for Clarifying how this actually works in the Kernel.
Reord... -
12:21 PM pfSense Plus Bug #15460 (Not a Bug): Kernel routing SPD Database gets “supenetted” wrong from multiple P2’s
- There are two things that could be a factor here and either one could be affecting it, but neither is a bug.
1. Th... -
02:50 PM Bug #15413: Kernel panic in HA nodes when under high load
- The backtrace address shows we're crashing in `if (PF_ANEQ(pd->src, &nk->addr[pd->sidx], pd->af) ||`. That likely mea...
-
01:22 PM Feature #14437 (Pull Request Review): Add DynDNS Provider - Hetzner
-
09:42 AM Bug #15466 (Needs Patch): Kea does not send a subnet mask in its inform response when requested by a client that isn't requesting an address allocation
- I am using a mac with macos 14.4.1 and pfsense 2.7.2.
When using DHCP on my mac, everything works fine. I do get t...
05/05/2024
-
04:58 PM Bug #14977: Kea fails to restart due to race between process termination and startup
- I just switched to kea and am seeing the service get marked as stopped while the process is still running. Same socke...
-
02:27 AM pfSense Packages Bug #14427 (Resolved): LLDPD & LADVD permissions with RAM Disks
- working in 24.03 :D
-
02:16 AM Bug #15366: Ethernet rules are not blocking the ARP inside the bridge
- With the new strict interface filtering in 24.03, has this been re-tested and confirmed to still exist?
-
02:03 AM pfSense Plus Bug #15463 (Closed): New admin user is not shown the console menu on SSH login
-
02:02 AM pfSense Plus Bug #15463 (Not a Bug): New admin user is not shown the console menu on SSH login
-
12:26 AM pfSense Plus Bug #15463: New admin user is not shown the console menu on SSH login
- Additional users will need to use sudo to perform actions with root privilege, and the sudo package can be installed ...
-
01:52 AM pfSense Packages Bug #15451: Cannot remove package
- start with the documentation, check the forums if you're still having issues....
https://docs.netgate.com/pfsense/...
05/04/2024
-
11:33 PM pfSense Plus Bug #15418: Incorrect links to edit static mapping and WOL on DHCPv6 leases (status_dhcpv6_leases.php). URL parameter values missing.
- Tested this with DHCPv6 upstream with a delegated prefix. I wasn't able to reproduce this on 24.03.
When adding... -
11:25 PM pfSense Plus Bug #15463: New admin user is not shown the console menu on SSH login
- Kris Phillips wrote in #note-1:
> This is expected behavior. Only the admin user account will have the pfSense menu... -
10:40 PM pfSense Plus Bug #15463: New admin user is not shown the console menu on SSH login
- This is expected behavior. Only the admin user account will have the pfSense menu present iself on login.
To la... -
05:42 PM pfSense Plus Bug #15463 (Closed): New admin user is not shown the console menu on SSH login
- A new admin user is not shown the console menu on SSH login.
The new admin user in question has the same effective p... -
10:33 PM Bug #15452: Unexpected/Undefined behaviour of disabled interfaces
- this can be triggered by changing MTU on disabled parent LAGG ala XG-7100 @ 24.03 and lower
-
09:16 PM Todo #15465 (Resolved): Update dnsmasq to version 2.90
- Apple (and likely others) are using a relatively new type of DNS record.
*Service binding and parameter specificat... -
07:04 PM Feature #15464: Allow Installer to install CE even if NDI detects as Plus
- +1
-
05:42 PM Feature #15464 (New): Allow Installer to install CE even if NDI detects as Plus
- Some people would prefer to revert to CE.
https://forum.netgate.com/topic/187943/what-happened-to-the-ce-downloads/8 -
04:53 PM pfSense Plus Feature #15462 (New): Feature request: Allow possibility of copying above separators when copying rules from one interface to another
- Allow possibility of copying above separators when copying rules from one interface to another.
-
04:44 PM Bug #13237: dhcp6c script cannot be executed safely
- I ran across this again in 24.03 when applying a save to the WAN interface. ...
-
02:51 PM Bug #14977: Kea fails to restart due to race between process termination and startup
- Jim Pingle wrote in #note-5:
>
> Any hints as to what might have led to it being in the broken state? I tried al... -
01:40 PM pfSense Packages Bug #15457: HAproxy disable zero copy forwarding
- This is fixed in HAProxy 2.9.2: https://github.com/haproxy/haproxy/issues/2395#issuecomment-1889864836
Currently 2.9... -
08:52 AM Bug #15116: Kea not working with UEFI HTTPBoot URL configured
- If I understand correctly there should be option 93 like ...
-
08:35 AM Feature #15461 (Needs Patch): Support GRE Tunnel Key
- Hello,
is it possible to implement GRE Tunnel Key according to RFC1701 ( https://datatracker.ietf.org/doc/html/rfc... -
07:41 AM Bug #14261 (Closed): Trim white space in a DHCP Leases page search field
- I can confirm it's working as Jim recommended.
Trim is applied only when the "IP Address," "MAC Address," or "Host... -
07:22 AM Bug #15130: Kea will not start with identical MAC address filters on multiple interfaces
- Tested against:...
-
04:49 AM Bug #15228: User manger fails to display certificate option for a new user in case of input error
- It is still the issue on 24.03
!clipboard-202405040849-pk7ae.png!
05/03/2024
-
10:23 PM pfSense Plus Bug #15460 (Not a Bug): Kernel routing SPD Database gets “supenetted” wrong from multiple P2’s
- I have confirmed this bud with multiple tests:
Scenario:
Two sites - both with proper internet connection.
IPS... -
09:04 PM pfSense Packages Feature #15393: Return to the ga version of NUT
- Thank you Jim!
-
05:43 PM pfSense Packages Feature #15393 (Feedback): Return to the ga version of NUT
- PR merged into devel, should be in snapshots when the next build happens.
-
07:24 PM pfSense Packages Bug #15459: Memory leak affecting ``lcdproc_client.php``, eventually hits PHP memory limit and crashes
- MR: https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/395
-
07:21 PM pfSense Packages Bug #15459 (Closed): Memory leak affecting ``lcdproc_client.php``, eventually hits PHP memory limit and crashes
- There is a memory leak affecting @lcdproc_client.php@ leading it to eventually running out of RAM and dying with a PH...
-
03:29 PM Bug #15456 (Not a Bug): KEA DHCP allows entering static mappings with no IP address defined
- Entries with a MAC address but not an IP address are valid. They define entries for "Deny Unknown Clients" which can ...
-
11:23 AM Bug #15456 (Not a Bug): KEA DHCP allows entering static mappings with no IP address defined
- After defining a static mapping without an IP address, the DHCP lease page will display two entries for that MAC addr...
-
02:59 PM Bug #14977 (New): Kea fails to restart due to race between process termination and startup
- Yuri Weinstein wrote in #note-4:
> I have experienced the same problem today 2 days after updating to 24.03-RELEASE
... -
12:14 AM Bug #14977: Kea fails to restart due to race between process termination and startup
- I have experienced the same problem today 2 days after updating to 24.03-RELEASE
In addition to all described abov... -
02:44 PM pfSense Packages Todo #15458: Convert Spamhaus DROP/eDROP to one list and JSON format
- https://forum.netgate.com/topic/187930/spamhaus-drop-edrop-list
-
02:42 PM pfSense Packages Todo #15458 (New): Convert Spamhaus DROP/eDROP to one list and JSON format
- The lists are combined and there is no eDROP list:
https://www.spamhaus.org/resource-hub/network-security/spamhaus-d... -
02:10 PM pfSense Packages Bug #15457 (Resolved): HAproxy disable zero copy forwarding
- See more details here:
https://forum.netgate.com/topic/187757/haproxy-100-cpu-usage
https://github.com/haproxy/... -
05:17 AM pfSense Plus Bug #15303: dpinger service does not always switch from Pending to Online
- In my case I am on 2.7.2 CE.
-
05:16 AM pfSense Plus Bug #15303: dpinger service does not always switch from Pending to Online
- I just got this on a IPv4 gateway DHCP WAN. Usually it works, but on powering up pfSense on this occasion it was stu...
05/02/2024
-
06:40 PM Bug #14591: Restoring with different interfaces (partially?) applies changes before reboot
- I ran into this again today, restoring a 3100 config to a 2100, both running 23.09.1. I deleted the OPT1 interface d...
-
06:28 PM Bug #14977: Kea fails to restart due to race between process termination and startup
- This issue was occurring for me too, and I have found a resolution. It manifests itself as a "ghost" kea process whi...
-
12:13 PM pfSense Packages Feature #15375 (Resolved): Update ntopng package
-
07:48 AM pfSense Plus Bug #15446 (Feedback): Kernel panic with pflow configured and active
- The relevant patch has been merged to our branches and will be part of the next build.
05/01/2024
-
11:32 PM pfSense Packages Feature #15393: Return to the ga version of NUT
- This is in PR 1368 (https://github.com/pfsense/FreeBSD-ports/pull/1368).
-
11:29 PM pfSense Packages Feature #15375: Update ntopng package
- This can be closed as complete. Thanks.
-
05:50 PM Bug #15454 (Resolved): Certificate Manager GUI inconsistency in Revocation tab titles
-
05:50 PM Bug #15454: Certificate Manager GUI inconsistency in Revocation tab titles
- tested, patch fixes the issue
-
01:00 PM Bug #15454 (Feedback): Certificate Manager GUI inconsistency in Revocation tab titles
- Applied in changeset commit:7cbbda697adeabca5eaad369099ea995a4c2cd42.
-
11:08 AM Bug #15454 (Resolved): Certificate Manager GUI inconsistency in Revocation tab titles
- Minor inconsistency in GUI sub-tab displayed naming:
in System -> Cetificate tab the sub-tab for "Revocation" change... -
03:48 PM Bug #15440 (Resolved): CA certificates are not added to the Trust Store
-
03:36 PM Bug #15440: CA certificates are not added to the Trust Store
- I stand corrected.
patch works, wait time around 3 mins after adding a cert to trusted -
12:47 PM Bug #15440: CA certificates are not added to the Trust Store
- Georgiy Tyutyunnik wrote in #note-3:
> tested the patch:
> seems like imported ca is correctly recognised post-imp... -
12:42 PM Bug #15440: CA certificates are not added to the Trust Store
- tested the patch:
seems like imported ca is correctly recognised post-import as trusted only if you manually re-run... -
03:34 PM Todo #15455 (New): Improve Package Manager behavior when the installed pfSense version differs from the selected update branch
- When a new version of pfSense is available, the "Current" branch version changes to match the new version. This cause...
-
12:58 PM Bug #15453 (Not a Bug): Assignment of OpenVPN port to an Interface shuts down OpenVPN access to Netgate 1100/2100
- After assigning an OpenVPN interface you must edit/save the OpenVPN instance to properly reinitialize the underlying ...
-
12:52 PM Revision 7cbbda69: Correct inconsistent CRL tab names. Fixes #15454
04/30/2024
-
11:43 PM Bug #15453 (Not a Bug): Assignment of OpenVPN port to an Interface shuts down OpenVPN access to Netgate 1100/2100
- I have a Netgate 2100 that is set up with an OpenVPN server. I can readily connect to it remotely with the SparkLabs ...
-
06:53 PM pfSense Docs Todo #15450 (Closed): Feedback on High Availability
- Info added.
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/b83e51d63a71013f568e8f7314993fcde182fd49 -
04:32 PM pfSense Packages Bug #15451: Cannot remove package
- Jim Pingle wrote in #note-1:
> There isn't nearly enough information here to go on, and this isn't the correct platf... -
12:15 PM pfSense Packages Bug #15451 (Incomplete): Cannot remove package
- There isn't nearly enough information here to go on, and this isn't the correct platform to diagnose the issue. Pleas...
-
12:06 AM pfSense Packages Bug #15451 (Incomplete): Cannot remove package
- The earlier issue I noticed where it wasn't sending information, I tried restarting the service, no change, so I went...
-
01:18 PM Feature #15422 (Resolved): Show current boot method in System Information Dashboard widget
-
11:48 AM Feature #15422: Show current boot method in System Information Dashboard widget
- works as expected
-
11:16 AM Feature #15261 (Closed): comcast DHCP issues
- not needed anymore
customer figured out the issue with ISP (Comcast) and works with them for resolution. -
08:45 AM pfSense Packages Bug #13444: zabbix_proxy : cannot open "/var/log/zabbix-proxy/zabbix_proxy.log": [13] Permission denied
- This problem still exists in the latest version of pfSense (2.7.2-RELEASE) with all Zabbix agent and proxy packages (...
-
12:33 AM Bug #13996: Limiters using the fq_pie scheduler no longer pass any traffic.
- Confirm the problem, it was working, I then adjusted the quantume, then traffic started going into blackhole, I chang...
-
12:15 AM Bug #15452: Unexpected/Undefined behaviour of disabled interfaces
- The first option there seems far more logical to me but I have always assumed that was the behaviour anyway. Anyone r...
-
12:14 AM Bug #15452 (New): Unexpected/Undefined behaviour of disabled interfaces
- Interfaces that are assigned but disabled can produce unexpected behaviour.
Setting an interface to disabled when ...
04/29/2024
-
10:22 PM pfSense Docs Todo #15450 (Closed): Feedback on High Availability
- *Page:* https://docs.netgate.com/pfsense/en/latest/highavailability/index.html
*Feedback:*
Somewhere in the docs ... -
05:26 PM Bug #9453 (Resolved): Reconfiguring a parent LAGG interface breaks its VLANs
- To reproduce the issue, the parent interface (@lagg0@) needs to be added to the configuration as disabled. When an in...
-
05:02 PM Bug #9453: Reconfiguring a parent LAGG interface breaks its VLANs
- I can't replicate that in 24.03. Setting the lagg0 interface MTU (after assigning it) in a 7100 results in a ~30s out...
-
05:22 PM Bug #15449: IPsec VTI static routes may not be added after the system boots
- Additional information.
The gateway that is disabled was originally used with a fiber provider's ONT/router which ... -
03:37 PM Bug #15449 (Resolved): IPsec VTI static routes may not be added after the system boots
- I have a pair of 4200s which were running 23.09.1
Both have an old gateway in a disabled state (see Disabled gateway... -
05:01 PM pfSense Packages Bug #15229 (Resolved): ACME DNS-Selfhost verification issues
- Fixed in ACME pkg v0.8
-
03:43 PM pfSense Packages Bug #15229 (In Progress): ACME DNS-Selfhost verification issues
-
05:01 PM pfSense Packages Bug #15061 (Resolved): acme.sh nsupdate with challengealias is failing in certain cases
- Fixed in ACME pkg v0.8
-
03:25 PM pfSense Packages Bug #15061 (In Progress): acme.sh nsupdate with challengealias is failing in certain cases
-
05:01 PM pfSense Packages Bug #14815 (Resolved): ACME.sh ingnores Certificates in Trust Store
- Fixed in ACME pkg v0.8
-
03:22 PM pfSense Packages Bug #14815 (In Progress): ACME.sh ingnores Certificates in Trust Store
-
05:00 PM pfSense Packages Bug #14796 (Resolved): ACME for domain registrar INWX in Germany
- Fixed in ACME pkg version ACME pkg v0.8
-
03:20 PM pfSense Packages Bug #14796 (In Progress): ACME for domain registrar INWX in Germany
-
04:17 PM pfSense Plus Bug #15446: Kernel panic with pflow configured and active
- Fix in https://cgit.freebsd.org/src/commit/?id=221d459fbc67e0c0565d6c6ea52fe8bbc5466fc7
I've not yet cherry-picked... - 04:10 PM Revision c0cacc1f: fix config.xml recovery
- Use bsddialog because dialog no longer exists.
-
03:28 PM pfSense Packages Bug #15414 (Rejected): Program Loops on invalid domains
- Looks like it's looping inside acme.sh and not code we maintain, so you'd need to report that upstream.
-
03:26 PM pfSense Packages Bug #15292 (Duplicate): Certificate renewal with 'dns_inwx.sh' not working: Error add txt for domain:_acme-challenge.foo.bar
- Likely a duplicate of #14796
-
03:18 PM pfSense Packages Bug #12623 (Closed): acme.sh package | DNS-ISPConfig settings
- This has been fixed for a long time now.
-
03:16 PM pfSense Packages Bug #7453 (Closed): DNS-ovh need to save or display consumer key
- This field has been in the GUI for years.
-
03:15 PM Feature #15422 (Feedback): Show current boot method in System Information Dashboard widget
- Applied in changeset commit:b891c3a33aff74f4ded6176a78b22ed84821036a.
-
03:07 PM Feature #15422 (In Progress): Show current boot method in System Information Dashboard widget
-
03:06 PM Revision b891c3a3: Add boot method to sysinfo widget. Implements #15422
-
01:44 PM pfSense Plus Bug #15421: Netgate 3100 boot loader lacks Lua support but is trying to read loader.conf.lua
- Kris Phillips wrote in #note-2:
> Oddly, I'm getting a similar, but not the same error message on an x86 KVM VM. Se... -
01:35 PM Bug #15448: ``miniupnpd`` lacks IGDv2 support
- The choice between v1 and v2 is a compile-time option so we can't make it a GUI selection, however, given the age of ...
-
06:32 AM Bug #15448 (New): ``miniupnpd`` lacks IGDv2 support
- The pfSense documentation "here":https://docs.netgate.com/pfsense/en/latest/services/upnp.html claims that miniupnpd ...
-
12:49 PM Bug #15442 (Resolved): CLI password check exits with a write access error when checking is a read-only operation
04/28/2024
-
01:25 AM pfSense Packages Bug #15447 (Closed): Wireguard not sending keep-alives according to configuration
- Closing this redmine, per request.
-
01:22 AM pfSense Plus Bug #15421: Netgate 3100 boot loader lacks Lua support but is trying to read loader.conf.lua
- Oddly, I'm getting a similar, but not the same error message on an x86 KVM VM. See attached. Not sure if this is re...
04/27/2024
-
11:43 PM Bug #15411: Hostname missing from logs in certain cases can cause the system log to display in an unexpected manner
- I hit this a few days ago but have yet to see it happen again since rebooting after initially encountering
-
10:38 PM Bug #15442: CLI password check exits with a write access error when checking is a read-only operation
no errors
[2.8.0-DEVELOPMENT][test@pfSense.home.arpa]/home/test: usermgrpasswd -c
Current password is OK.
...-
10:24 PM Bug #9453 (Confirmed): Reconfiguring a parent LAGG interface breaks its VLANs
- changing anything regarding the parent interface stops all communication...
-
06:37 PM Bug #11192: Using Limiters causes out of order packets within one TCP or UDP flow
- I think I may have been affected by this.
I have used limiters in two scenario, one to make my home broadband not ... -
06:23 PM pfSense Packages Bug #15420 (Confirmed): Incorrect error pfBlockerNG MaxMind message.
- The message remains consistent whether you have entered only the MaxMind Account ID or only the MaxMind License Key o...
-
12:57 PM pfSense Packages Bug #15447: Wireguard not sending keep-alives according to configuration
- Sorry, having though about this a bit longer I realise the Keepalive is only sent when there's no Transport data sent...
-
09:49 AM pfSense Packages Bug #15447 (Closed): Wireguard not sending keep-alives according to configuration
I have configured my wireguard peers with a 30s keep-alive interval. As I was viewing a packet capture in Wireshark...-
10:17 AM Todo #15358: Correct description in “System Information” widget
- Jim Pingle wrote in #note-1:
> There is no need to use both forms everywhere. The string is already long enough as i...
04/26/2024
-
07:59 PM Bug #15434 (Resolved): DNS Forwarder ignores "Use remote DNS Servers, ignore local DNS" setting
- dylan mendez wrote in #note-6:
> This patch seems to work, however, I had to manually re-save the config on the Gene... -
07:19 PM pfSense Plus Bug #15446 (Resolved): Kernel panic with pflow configured and active
- System: Netgate 4100
Version: 24.03-RELEASE
After switching the export protocol to Netflow v5, device is stable f... -
05:59 PM pfSense Packages Bug #15365 (Resolved): pfBlockerNG PHP error when editing a list
- PR merged, updated package should be available now on 24.03.
-
02:28 PM pfSense Packages Bug #15365: pfBlockerNG PHP error when editing a list
- ive added the fixes manually and confirmed all is well.
Any reason why this hasn't been pushed out via the repo? -
03:50 PM pfSense Docs Correction #15445 (Duplicate): Possible mistake in "WireGuard Site-to-Multisite VPN Configuration Example"
- Dear all,
i set up a Wireguard Site-to-Multisite VPN according to the pfSense configuration example.
Configurin... -
03:45 PM pfSense Plus Feature #15013: Speed Shift - Add Field to control lowest C-State
- Has been solved already and can be closed. Update 26.04: sry ignore my comment i confused it with another ticket - sry!
-
10:28 AM pfSense Packages Bug #15435: Long boot time when using FQDN for WireGuard VPN endpoint
- I bought a console cable and captured the reboot output (attached). It doesn't really show anything new. Most of the ...
-
04:01 AM pfSense Packages Bug #15444 (Duplicate): Since this update 24.03-RELEASE was installed, PFBlockerNG has not been functioning correctly.
-
02:41 AM pfSense Packages Bug #15444 (Duplicate): Since this update 24.03-RELEASE was installed, PFBlockerNG has not been functioning correctly.
- 24.03-RELEASE (amd64)
built on Wed Apr 24 10:38:00 PDT 2024
FreeBSD 15.0-CURRENT
Since this update was installed...
04/25/2024
-
11:50 PM pfSense Packages Bug #15443 (Duplicate): PHP Crash: pfBlockerNG/DNSBL/DNSBL Groups, attempt to add list
-
11:47 PM pfSense Packages Bug #15443: PHP Crash: pfBlockerNG/DNSBL/DNSBL Groups, attempt to add list
- Plus mark this as a dup of bug 15365 (and close I guess). I tried Christopher Cope's fix (two spots in the file) and...
-
11:12 PM pfSense Packages Bug #15443: PHP Crash: pfBlockerNG/DNSBL/DNSBL Groups, attempt to add list
- pfblockerng version 3.2.0_9. Same bug happens on a Netgate 1100 running 24.03_1 as well. Looks like duplicate of Bu...
-
09:34 PM pfSense Packages Bug #15443 (Duplicate): PHP Crash: pfBlockerNG/DNSBL/DNSBL Groups, attempt to add list
- Clicking Add to add a new list causes a PHP fatal error. Reproducible crash. Two copies of crash screenshots and PH...
-
08:35 PM pfSense Packages Feature #14706: Add Cloudflare tunnel pkg
- Vlad Saftoiu wrote:
> Could we get this added to the pfSense packages? This type of application is clearly meant to ... -
07:48 PM pfSense Docs Todo #15436 (Closed): Update notes for if-bound state policy
- I was thinking that but I wasn't certain if there was still some other issue hanging out there. I removed the note, i...
-
05:52 PM Regression #15439: Incorrect icon on collapsed dashboard widgets
- In source:src/usr/local/www/js/pfSenseHelpers.js#L486 the code that handles collapse/expand is adding/removing the fa...
-
12:36 PM Regression #15439 (Resolved): Incorrect icon on collapsed dashboard widgets
- A collapsed widget on the dashboard shows the '+' icon where the wrench icon should be.
This is a regression since... -
05:40 PM Bug #15440 (Feedback): CA certificates are not added to the Trust Store
- Applied in changeset commit:27fc5a3020fe981b7a5bc98fc9b1660e8773fc7d.
-
05:32 PM Bug #15440 (In Progress): CA certificates are not added to the Trust Store
- Looks like the behavior of @certctl rehash@ changed and now it wipes out the contents of that directory when it did n...
-
04:25 PM Bug #15440 (Resolved): CA certificates are not added to the Trust Store
- stopped working after upgrade to 24.03
details in
https://forum.netgate.com/topic/187658/24-03-stuck-at-not-re... -
05:36 PM pfSense Docs Todo #15441 (Rejected): Update "Security Gateway Manual SG-2100", chapter 7
- The current docs are already saying most of that -- the only new bits are the driver, which already says "if needed" ...
-
04:47 PM pfSense Docs Todo #15441 (Rejected): Update "Security Gateway Manual SG-2100", chapter 7
- The writeup on how to connect to the console via a Mac is out of date. Sonoma MacOS has the driver built in, no driv...
-
05:32 PM Revision 27fc5a30: Fix CA trust store custom entries. Fixes #15440
- certctl rehash behavior changed, so we need to write the CA files out
differently now so it picks them up. -
05:30 PM Bug #15442 (Feedback): CLI password check exits with a write access error when checking is a read-only operation
- Applied in changeset commit:90c4a2fe6db1bafc8bb4bc038cf3e3664ac6db47.
-
05:23 PM Bug #15442 (Resolved): CLI password check exits with a write access error when checking is a read-only operation
- When running @usermgrpasswd -c@ to check the current user password it exits with an error message saying the user lac...
-
05:24 PM Revision 90c4a2fe: Fix usermgrpasswd check for non-privileged users. Fixes #15442
-
05:19 PM Bug #12393: Priority of qOthersLow higher than default queues
- Still the same in 23.09.1.
-
02:56 PM pfSense Packages Bug #15365: pfBlockerNG PHP error when editing a list
- i dont know how to add the patch from the screen shot.
I am hoping it can be available through the package manager. -
01:29 PM pfSense Packages Bug #15365: pfBlockerNG PHP error when editing a list
- There are actually 2 spots where this can cause an error. The pull request addresses both. The patch attached reflect...
-
12:37 PM pfSense Packages Bug #15365: pfBlockerNG PHP error when editing a list
- I've tested the patch against the:...
-
10:09 AM pfSense Packages Bug #15365: pfBlockerNG PHP error when editing a list
- you can try system patch
-
01:32 PM pfSense Packages Bug #15419 (Duplicate): pfBlockerNG - Issue with Adding or Changing Ipv4 Addresses
-
12:13 PM pfSense Packages Bug #15419: pfBlockerNG - Issue with Adding or Changing Ipv4 Addresses
- This seems to be a duplicate of #15365
-
09:13 AM Bug #15438 (New): NDP Table can be very slow
- The NDP table from diagnostics menu become really slow with many link-local entries.
The ndp_diag.php script get the... -
06:46 AM Feature #15437: Use natural sorting when sorting interfaces
- Opened a PR on GitHub: https://github.com/pfsense/pfsense/pull/4683
-
06:44 AM Feature #15437 (Resolved): Use natural sorting when sorting interfaces
- When the option Interfaces Sort / Sort Alphabetically is enabled, Interfaces are sorted alphabetically instead of nat...
-
01:10 AM Bug #15434: DNS Forwarder ignores "Use remote DNS Servers, ignore local DNS" setting
- This patch seems to work, however, I had to manually re-save the config on the General Setup page for the changes to ...
04/24/2024
-
10:42 PM Regression #14773: Unable to boot pfSense after installation on Proxmox VE 8.x
- This is still an issue in 24.03. See: https://forum.netgate.com/topic/187667/uefi-vm-upgrade-failure
-
08:47 PM Feature #14483: Conditionally reconfigure IPsec VTI interfaces only when necessary while applying IPsec changes
- Hey Jim,
Is any hope in the fix coming to 24.07? -
08:38 PM pfSense Packages Bug #15365: pfBlockerNG PHP error when editing a list
- Any luck getting the PR merged?
I cant update any of my feeds without it. -
08:34 PM pfSense Packages Bug #15419: pfBlockerNG - Issue with Adding or Changing Ipv4 Addresses
- Ran into this today as well. Attempting to add a feed to aid in troubleshooting a download issue.
Crash repo... -
08:30 PM pfSense Docs Todo #15436 (Closed): Update notes for if-bound state policy
- https://docs.netgate.com/pfsense/en/latest/config/advanced-firewall-nat.html#interface-bound-states
> For systems wi... -
08:14 PM pfSense Packages Bug #15435: Long boot time when using FQDN for WireGuard VPN endpoint
- Just to document what I did, completely. To generate the first general timing trace of /etc/rc.bootup:
1. apply th... -
07:54 PM pfSense Packages Bug #15435 (New): Long boot time when using FQDN for WireGuard VPN endpoint
(Additional details in https://forum.netgate.com/post/1163707)
My reason for investigating this was boot times o...-
07:57 PM Regression #15430: Interface-bound state policy does not handle IPsec VTI traffic as expected when filtering on ``enc0`` interface
- I added notes about this to the docs about state policy in general (and in the release notes): https://docs.netgate.c...
-
07:53 PM Regression #15430: Interface-bound state policy does not handle IPsec VTI traffic as expected when filtering on ``enc0`` interface
- I have made the firewall a VTI/Routed IPsec gateway moving forward.
Considering this drawback is noted in the docum... -
01:43 PM Regression #15430: Interface-bound state policy does not handle IPsec VTI traffic as expected when filtering on ``enc0`` interface
- If you do not have **any** tunnel mode IPsec (no site to site tunnel mode P2s, no mobile IPsec) you could change the ...
-
01:38 PM Regression #15430: Interface-bound state policy does not handle IPsec VTI traffic as expected when filtering on ``enc0`` interface
- IPsec Filter Mode set to 'Filter IPsec Tunnel, Transport and VTI on IPsec tab'
-
01:31 PM Regression #15430: Interface-bound state policy does not handle IPsec VTI traffic as expected when filtering on ``enc0`` interface
- IPsec is fundamentally different in how it's handled compared to things like WireGuard/OpenVPN/OpenVPN+DCO. IPsec can...
-
01:15 PM Regression #15430: Interface-bound state policy does not handle IPsec VTI traffic as expected when filtering on ``enc0`` interface
- VTI mode for IPsec.
To reiterate, Wireguard VPN w/ BGP saw no issues. -
12:58 PM Regression #15430: Interface-bound state policy does not handle IPsec VTI traffic as expected when filtering on ``enc0`` interface
- What type of IPsec VPN, policy-based or VTI? Since you mention BGP, I'm guessing VTI, but it needs to be confirmed.
... -
07:50 PM Bug #15434 (Feedback): DNS Forwarder ignores "Use remote DNS Servers, ignore local DNS" setting
- Applied in changeset commit:247909ff5387200fb31c76f13e7702a8fbdc06f4.
-
07:43 PM Bug #15434 (In Progress): DNS Forwarder ignores "Use remote DNS Servers, ignore local DNS" setting
- OK, I can also reproduce this with the DNS Forwarder. I also have a fix coming. Looks like some parenthesis around th...
-
06:33 PM Bug #15434: DNS Forwarder ignores "Use remote DNS Servers, ignore local DNS" setting
- same behavior on my edge when switching to forwarder...
-
06:27 PM Bug #15434: DNS Forwarder ignores "Use remote DNS Servers, ignore local DNS" setting
- I can replicate this issue. It's present only when you disable unbound and enable the forwarder(dnsmasq).
*Use remo... -
05:31 PM Bug #15434 (Not a Bug): DNS Forwarder ignores "Use remote DNS Servers, ignore local DNS" setting
- I can't reproduce that here.
Before:... -
05:20 PM Bug #15434 (Resolved): DNS Forwarder ignores "Use remote DNS Servers, ignore local DNS" setting
- In General Setup if use option "Use remote DNS Servers, ignore local DNS" the DNS Forwarder still try to use local DN...
-
07:43 PM Revision 247909ff: Fix resolv.conf logic for DNS Forwarder. Fixes #15434
-
06:17 PM pfSense Docs Todo #15432 (Closed): Feedback on Installing and Upgrading — Online Network Installer
- This is corrected now, the document contains appropriate links to the relevant store pages.
-
04:02 PM pfSense Docs Todo #15432: Feedback on Installing and Upgrading — Online Network Installer
- Yes, that is due to be replaced. Things are still settling into their final places but I can put in the current locat...
-
03:25 PM pfSense Docs Todo #15432 (Closed): Feedback on Installing and Upgrading — Online Network Installer
- *Page:* https://docs.netgate.com/pfsense/en/latest/install/netinstaller.html
*Feedback:*
"insert URL here" should... -
06:16 PM pfSense Plus Regression #15433 (Resolved): ``smartmontools`` is not present on ARM builds (64 or 32 bit)
- Looks good here.
Users don't need to reinstall or re-upgrade, they can fix it a couple different ways:
Either t... -
05:53 PM pfSense Plus Regression #15433 (Feedback): ``smartmontools`` is not present on ARM builds (64 or 32 bit)
-
05:04 PM pfSense Plus Regression #15433 (Resolved): ``smartmontools`` is not present on ARM builds (64 or 32 bit)
- The @smartmontools@ package is not present on 64-bit ARM builds (1100, 2100) or 32-bit ARM builds (3100). It is still...
-
05:37 PM Revision df499955: Change sorting algorithm to natural sort in get_configured_interface_with_descr
-
01:02 PM Bug #15431 (Duplicate): Interface Bound Firewall State Policy Breaks IPsec VTI
- Usually states would only disappear like that if the traffic is not being matched in both directions and then times o...
-
05:51 AM Bug #15431 (Duplicate): Interface Bound Firewall State Policy Breaks IPsec VTI
- After upgrading to pfSense 24.03 IPsec VTI firewall states are broken. The scenario is:
A pfSense router A has a s... -
12:54 PM pfSense Plus Bug #15126 (Resolved): SG-1100 pfSense+ recovery results in non aligned disk slices
- This may not have been fixed specifically but happens to be handled better in the new installer from the start. The o...
-
10:04 AM pfSense Plus Bug #15126: SG-1100 pfSense+ recovery results in non aligned disk slices
- Quick update - it appears that the new pfSense+ 24.03 installer for SG-1100 (bundled in recovery image netgate-instal...
04/23/2024
-
10:36 PM pfSense Packages Bug #15419: pfBlockerNG - Issue with Adding or Changing Ipv4 Addresses
- I can replicate this easily on version 24.03 release.
-
10:22 PM Regression #15430 (Resolved): Interface-bound state policy does not handle IPsec VTI traffic as expected when filtering on ``enc0`` interface
- https://forum.netgate.com/topic/187632/24-03-frr-has-flapping-bgp-neighbors/3
In my set up there are two VPN types... -
05:51 PM Feature #15426: Add the ability to configure dynamic gateways even when they are offline
- Marcos - thank you for pointing that out, it is exactly what I was looking for!
I would suggest adding a note to t... -
05:35 PM Feature #15426: Add the ability to configure dynamic gateways even when they are offline
- If it's created using the would-be name (use @dynamic@ as the address). For further discussion, if needed, please pos...
-
03:18 PM Feature #15426: Add the ability to configure dynamic gateways even when they are offline
- I have a unit with 24.03 installed. Both WAN and WAN2 are DHCP. WAN is connected and has a valid IP configuration inc...
-
02:53 AM Feature #15426 (Closed): Add the ability to configure dynamic gateways even when they are offline
- This is already the case in 24.03 (dynamic gateways are saved to the config).
-
05:40 PM Todo #15429 (Resolved): Clarify descriptions for gateway recovery options
- I'm excited about the new gateway recovery behavior that's available in 24.03. However, I found that the [blog post[h...
-
04:11 PM Bug #15299 (Resolved): Old auto-added MAC addresses are not pruned for non-concurrent Captive Portal sessions
-
04:11 PM Bug #15156 (Resolved): Fragmented packets delayed by limiters are lost
-
04:11 PM Regression #15076 (Resolved): DHCP leases may not be restored from older configuration backups
-
04:11 PM Bug #15032 (Resolved): Kea DHCP sends wrong bootloader file for UEFI
-
04:11 PM Feature #14728 (Resolved): Support for CD/DVD drives in the External Configuration Locator (ECL)
-
04:11 PM Regression #14431 (Resolved): Sending IPv6 traffic on a disabled interface can trigger a kernel panic
-
04:11 PM Bug #14312 (Resolved): MSS clamping on VPN traffic does not work on IPsec IPv6 mobile VPNs
-
04:11 PM Bug #14290 (Resolved): ICMPv6 Path MTU Discovery breaks with NPT
-
04:11 PM Todo #13263 (Resolved): Reduce log spam when deleting a static DHCP entry
-
04:11 PM Bug #13090 (Resolved): OpenVPN NetBIOS Node Type and Scope ID options are not pushed to clients
-
04:11 PM Feature #13085 (Resolved): OpenVPN NBDD server options
-
04:11 PM Bug #12947 (Resolved): Old IPv6 addresses may continue to be used after DHCP or RA changes
-
04:11 PM Bug #12920 (Resolved): Gateway behavior differs when the gateway does not exist in the configuration
-
04:11 PM Bug #12673 (Resolved): Firewall Logs Dashboard Widget is slow and may fail to update
-
04:11 PM Bug #9453 (Resolved): Reconfiguring a parent LAGG interface breaks its VLANs
-
04:10 PM pfSense Plus Regression #15387 (Resolved): Boot failure detection tripping on config reset button during boot
-
04:10 PM pfSense Plus Feature #15280 (Closed): Boot Environments 2.0
- Closing, it's in the release, any issues can be opened separately going forward.
-
12:30 PM pfSense Packages Feature #15427 (Duplicate): Create file that can be imported into the Wireguard Apps (on the Android, Windows etc)
- Duplicate of #13469
-
03:18 AM pfSense Packages Feature #15427 (Duplicate): Create file that can be imported into the Wireguard Apps (on the Android, Windows etc)
- When setting up new peer for connecting to Wireguard, there is an option to import a file to create the tunnel on the...
-
12:29 PM Bug #15428 (Not a Bug): UI appears to put incorrect CARP parameters into the low level NIC configurations
- A skew of 254 indicates a problem in your setup not a problem with how the settings were applied. Either they are in ...
-
11:22 AM Bug #15428: UI appears to put incorrect CARP parameters into the low level NIC configurations
- First check to see if you have you have both nodes in CARP maintenance mode. If so, take them out of that mode and ch...
-
06:43 AM Bug #15428 (Not a Bug): UI appears to put incorrect CARP parameters into the low level NIC configurations
- it appears that there is a bug with the UI and supporting code, for v2.7.2-RELEASE, in regard to the way that the UI ...
-
12:19 AM Feature #15425: Add a description field to interfaces
- I realized that interfaces already have a field called "Description", but it's actually more like a "Name" field, as ...
04/22/2024
-
11:59 PM Feature #15426 (Closed): Add the ability to configure dynamic gateways even when they are offline
- For WAN interfaces set to DHCP, no gateway is created under System > Routing if the interface does not have a valid g...
-
11:23 PM Feature #15425 (New): Add a description field to interfaces
- Many areas of pfSense have a "Description" field that is simply for adding reference notes. This would be very useful...
-
10:30 PM pfSense Plus Regression #15424 (New): Image label file is incorrect.
- In the 24.03 recovery images the image label file is shown as:...
-
05:47 PM Bug #11192: Using Limiters causes out of order packets within one TCP or UDP flow
- It may be that due to the way dummynet works, packets will inevitably arrive out of order. Dummynet will let packets ...
-
04:45 PM Bug #15423 (Resolved): PHP error when applying interface settings if the ``/tmp/.interfaces.apply`` file is present but empty
- If the @/tmp/.interfaces.apply@ file is present but empty it can lead to a PHP error when applying interface settings...
-
03:34 PM Feature #10250: DHCP lease view by interface
- Jim Pingle wrote in #note-1:
> The leases are not tracked by interface, so this is not easily possible. Others have ... -
03:27 PM Feature #15422 (Resolved): Show current boot method in System Information Dashboard widget
- It would be helpful to include the contents of the @machdep.bootmethod@ sysctl in the System Information widget most ...
-
02:02 PM pfSense Plus Bug #15421 (Confirmed): Netgate 3100 boot loader lacks Lua support but is trying to read loader.conf.lua
- Confirmed. Does not prevent booting though. Or have any noticable impact since loader.conf.lua does not contain any ...
04/21/2024
-
06:21 AM pfSense Plus Feature #15412: Improve error feedback from pfSense-upgrade
- I encountered this on clean install to 4100 with: pfSense-plus-memstick-serial-24.03-RELEASE-amd64.img.
The error wa... -
01:33 AM pfSense Plus Bug #15421 (Confirmed): Netgate 3100 boot loader lacks Lua support but is trying to read loader.conf.lua
- When booting the Netgate 3100, there appears to be a bootloader syntax error present:
Booting from disk1s2a:
Load... -
12:32 AM Bug #9453: Reconfiguring a parent LAGG interface breaks its VLANs
- I'm still seeing these connectivity issues following manipulating anything about the parent LAGG interface on 24.03. ...
-
12:25 AM pfSense Plus Bug #15401: 23.09.1 to 24.03b update fails EFI with ZFS mirror
- my system is not EFI (XG7100) but have not been experiencing any issues with my mirrors updating along with bootcode
... -
12:13 AM Bug #14261: Trim white space in a DHCP Leases page search field
- Tested on...
-
12:01 AM Bug #14261: Trim white space in a DHCP Leases page search field
- same behavior as above using 24.03.r.20240416.0005, adding a space on either side removes any results when searching
-
12:06 AM Todo #13263: Reduce log spam when deleting a static DHCP entry
- I see the following when removing a static DHCP entry running 24.03.r.20240416.0005...
04/20/2024
-
11:09 PM pfSense Plus Bug #15303: dpinger service does not always switch from Pending to Online
- Tested on 24.03-RELEASE and this issue is still present.
-
11:08 PM Bug #15404: Captive Portal logo fails to load after authenticated redirect
- Tested in 24.03-RELEASE and this issue is still present.
-
05:58 AM pfSense Packages Bug #15420 (Confirmed): Incorrect error pfBlockerNG MaxMind message.
- WHERE
In “ MaxMind GeoIP configuration” section
ISSUE
Wrong error alerting message:
“ *pfBlockerNG MaxMind - M... -
02:18 AM pfSense Packages Bug #15419 (Duplicate): pfBlockerNG - Issue with Adding or Changing Ipv4 Addresses
- Hi PFsense+ Community,
I am running the 24.03RC version and have run into an issue with updating IPv4 lists in PFB...
04/19/2024
-
06:22 PM pfSense Docs Correction #15403 (Closed): openvpn client speciffic overrides, local networks clarification
- Info added: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/9011224272ea0934535d8530da838580f91c988b
-
02:39 PM pfSense Plus Regression #15407 (Resolved): pfSense-upgrade incorrectly creates 'unknown error' notice.
- Confirmed that this is no longer an issue on...
Also available in: Atom