Project

General

Profile

Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
ff8affb4 09/28/2013 01:26 PM Richard Connon

Fix codel not being applied on non-priq queue types

931f3890 09/28/2013 01:26 PM Richard Connon

Fixed typo in CoDel wiki link

5205b0eb 09/25/2013 03:49 PM Jim Pingle

Make sure no extra spaces end up in the parsed IP, it can lead to issues in other places (Easy Rule, etc)

7786cd6e 09/23/2013 07:27 PM Jim Pingle

Add patch from Ermal to fix ifconfig error on gif in certain cases.

428ea19f 09/23/2013 02:01 PM Jim Pingle

Fix CP stats generation for concurrent users. Fixes #3225

baeb0599 09/19/2013 01:45 PM Xon

Alix 2D6 crashes upgrade process withou out of diskspace

Updating the the RRD graphs causes two copies of each RRD's XML file to be stored in /tmp.

On Nanobsd, the default /tmp size is 40mb. It doesn't require very many RRD XML dumps before this is exhausted.

78db4f1a 09/17/2013 07:12 PM Jim Pingle

Switch to rw mode before file operations on RFC2136 cache. Fixes #3201

bf2afff0 09/11/2013 10:12 PM Chris Buechler

s/BSDP/ESF/

b832d617 09/10/2013 03:08 PM Jim Pingle

This broke correct detection of primary/secondary -- the person in that thread may have had some other config issue, but this broke working/valid configurations. Revert "Correct check to match the right vip based on configured ip. Reported-by: http://forum.pfsense.org/index.php/topic,66234.0.html"...

a3d6166b 09/10/2013 03:07 PM Jim Pingle

Fix didn't help -- backing this out and the change that made it necessary. Revert "Correctly check the secondary/primary parameter setting on dhcp failover configuration"

This reverts commit 24670866827b4e2d7a4a05baaf6d09ee377ce7cb.

408ebb78 09/10/2013 01:06 PM Jim Pingle

Fix update URL so the -RELEASE version looks at the stable updates URL by default rather than the snapshots server.

c312ee8f 09/10/2013 12:15 PM Phil Davis

Update an existing cron entry for pppoe periodic resets

The array variable name was incorrect in the test, so the existing cron entry was not being matched. Fixes #3192

58fbb3f0 09/10/2013 09:26 AM Ermal LUÇI

Leave a trace that rtsold did fire the dhcp6c client so troubleshooting is easier

e4cf52ed 09/10/2013 09:22 AM Phil Davis

Do not include disabled OpenVPN in vpn_networks and negate_networks

24670866 09/10/2013 09:10 AM Ermal LUÇI

Correctly check the secondary/primary parameter setting on dhcp failover configuration

168a1948 09/10/2013 08:18 AM Ermal LUÇI

Correct typo that prevents dhcp rules from properly being generated.

b841bc23 09/09/2013 07:18 PM Jim Pingle

Fix errant display of "0 table deleted" during filter reload on console.

8571cdd5 09/06/2013 05:56 PM Jim Pingle

Remove failover peer IP settings from DHCPv6, DHCPv6 doesn't support failover the way that DHPv4 did. Fixes #3184

279c2f42 09/06/2013 04:59 PM Renato Botelho

Disable kill_states by default on upgrade, it fixes #3183

9e6043cc 09/05/2013 06:27 PM Jim Pingle

Allow for easier override on $g values if needed.

25f9f332 09/05/2013 12:39 PM Ermal LUÇI

Correct check to match the right vip based on configured ip. Reported-by: http://forum.pfsense.org/index.php/topic,66234.0.html

19d723d2 09/05/2013 12:28 PM Ermal LUÇI

Ticket #3181 do the state flushing only on down gateway detection rather than any time.

5aa44e98 09/05/2013 12:24 PM Ermal LUÇI

Revert "Revert back the behaviour to cleanup all states for 2.1 Fixes #3181 and related to Ticket #1629. This commit is only for 2.1 since on master development will continue for better alternatives"

A bit too excessive need to get right.

This reverts commit c59dd719e0a6d9ee8deecaa7bff0d6ee8c76e4ca.

0ec64bd2 09/04/2013 10:43 AM Ermal LUÇI

Actually the / here is not needed.

48085d0c 09/04/2013 08:19 AM Ermal LUÇI

Make the operation of saving old rule nearby the writing operation to be logical to spot

53ce7798 09/04/2013 08:12 AM Ermal LUÇI

Sprinkle some unsets to reduce footprint and correct some whitespaces

e8090840 09/04/2013 07:22 AM Phil Davis

filter_generate_port error log function name

Absolutely minor adjustment to make the error log message refer to the new function name.

c59dd719 09/03/2013 07:05 PM Ermal LUÇI

Revert back the behaviour to cleanup all states for 2.1 Fixes #3181 and related to Ticket #1629. This commit is only for 2.1 since on master development will continue for better alternatives

44f0f09b 09/03/2013 06:40 PM Ermal LUÇI

Fixes #3173 if any port information exists on the rule than put it on the NEGATE rule generated.

3cb55704 09/03/2013 06:19 PM Renato Botelho

Remove SPD when disable phase2, it fixes #2719

be40ce0b 09/03/2013 05:08 PM Chris Buechler

Merge pull request #796 from phil-davis/master

Traffic Shaper GUI text typos

0c1870ca 09/03/2013 05:04 PM Chris Buechler

Merge pull request #790 from shahidsheikh/RELENG_2_1

#3174 Added handling of gateway groups in openvpn_restart
96551a20 09/03/2013 05:03 PM Chris Buechler

Merge pull request #794 from phil-davis/RELENG_2_1

Backport get_memory changes to 2.1

c9d099d7 09/03/2013 04:52 PM Ermal LUÇI

Bring back static routes to fix issues reported on Ticext #3179

c59e21b5 09/03/2013 04:36 PM Renato Botelho

Fix #3004:

. Create a function to replace strings on deep associative arrays
. Use the recent created function array_replace_values_recursive to fix
VIP interface names instead of touch config.xml directly

7ca8bef4 09/03/2013 11:56 AM Renato Botelho

Make sure RRD data is restored from backup before upgrading data and a new backup is done after. It should fix #2159

a2ac3661 09/03/2013 07:15 AM Ermal Luçi

Merge pull request #792 from razzfazz/RELENG_2_1

add option to send prefix hint for requesting desired prefix length for ...

4a6f3d96 09/03/2013 07:06 AM Ermal Luçi

Merge pull request #791 from jean-m-cyr/RELENG_2_1

Dummynet does not require burst size specification

98c10c92 09/03/2013 06:43 AM Phil Davis

Use new names for get_memory parameters

68b253ad 09/03/2013 06:35 AM Phil Davis

Use hw.physmem when calculating pfsense_default_state_size

hw.physmem is the actual amount of memory that FreeBSD/pfSense can get its hands on, so use this for the calculation.
Backport to 2.1

ec532672 09/03/2013 06:26 AM Chris Buechler

touch up text, s/nat/NAT/

90652fbf 09/03/2013 12:34 AM Daniel Becker

add option to send prefix hint for requesting desired prefix length for delegation

This change adds an option on the interfaces page for sending a prefix hint for the selected delegation size. If enabled, a "prefix" field requesting :: with the appropriate prefix length (64 - dhcp6-ia-pd-len) is added to the "id-assoc pd" entry in the dhcp6c config file. This hint is required for requesting prefixes shorter than /64 from Comcast.

9880a11d 09/03/2013 12:10 AM Jean Cyr

Dummynet does not require burst size specification

Dummynet traffic shaper does not require burst size specification and
assumes 0 if not specified. Allow user to leave burst field blank, if
not blank the must be numeric

6eb6e720 09/02/2013 08:13 PM Shahid Sheikh

#3174 Handling of gateway groups in openvpn_restart()

If the underlying vip of a gateway group that an openvpn client is bound to is in backup mode then the client should not start.

414edd3e 09/02/2013 08:09 PM Shahid Sheikh

#3174 Added handling of gateway groups in openvpn_restart

0c3a7a05 09/02/2013 11:12 AM Phil Davis

Use updated get_memory var names

Backport to 2.1

7a6851df 09/02/2013 11:01 AM Renato Botelho

Fix #3172, return_gateway_groups_array() was returning the last vip since it was using wrong variable name on iteration

d613b9d5 09/02/2013 10:54 AM Phil Davis

Improve var names in get_memory

Backport from master

c53f1e0c 08/28/2013 01:00 PM Jim Pingle

Support the names used by the status page as well as those used internally by service entries.

e89c3caf 08/22/2013 07:14 PM Renato Botelho

Delete old route for remote gateway when its IP changes. It fixes #3155

35e125b4 08/21/2013 07:21 PM Jim Pingle

Fixup check for existing easyrule block rule to account for the ipproto and when the ipproto is blank.

8f61cb87 08/20/2013 05:39 PM Renato Botelho

Add scope to target when it is a link-local, it helps ticket #3150

bbd87523 08/19/2013 05:55 PM Jim Pingle

Attempt to recognize pfsync entries from pf logs.

31202953 08/17/2013 10:05 AM Chris Buechler

Fix selection of IPv6 target IP for IPv6 Outbound NAT rules.

This makes it possible (without source hacking) to do many:1 NAT of IPv6.

Some will rejoice. Some will curse.

This should really only be done in limited, specific circumstances. Don't develop the IPv4 NAT mentality with IPv6.

f8436649 08/16/2013 07:48 PM Ermal LUÇI

Ooops fix this to add only th einterface

7d3eaae2 08/16/2013 07:35 PM Ermal LUÇI

Add scope identifier to target when its link-local

f2999907 08/16/2013 03:00 PM Ermal LUÇI

Add also a special case so the correct ip is returned for the case when WAN is v4 PPP type and v6 is DHCP but with option fetch v6 info from v4.

d5707d33 08/16/2013 02:45 PM Ermal LUÇI

When using DHCPv6 and only requesting a prefix the communication on the WAN interface will be over link-local so return the link-local address of the interface in this case rather than nothing.

912e3f6f 08/16/2013 02:35 PM Ermal LUÇI

Optimize a bit to try and convrt back to friendly interface only when needed

90af1b8b 08/16/2013 02:33 PM Ermal LUÇI

Resolves #2627. When WANv4 is PPP and v6 is DHCP but the option get v6 info from v4 is ticked the real interface is different. For WANv4 is pppXX and for v6 is the real underlying interface. Take this into consideration during interface_bring_down to properly cleanup things

8b257982 08/16/2013 02:11 PM Ermal LUÇI

Correctly remove IPv6 addresses from the interface rather than just erroring out. The same trick that works for IPv4 of not specifying address does not work with v6

2391780c 08/16/2013 01:37 PM Ermal LUÇI

Even if called with wrong parameters try to do something rather than return here.

329acfb2 08/16/2013 10:42 AM Ermal LUÇI

Reduce diff with master

93d38614 08/16/2013 10:39 AM Ermal LUÇI

Handle link local addresses with embedded interface scope on is_ipaddrv6 and also on dnsmasq which is not yet there for these addresses

c6868a8f 08/15/2013 07:30 PM Ermal LUÇI

Unbreak limitrules and probably pfblocker errors. Spotted-by: Jim

b8131408 08/15/2013 05:51 PM Jim Pingle

When renaming or deleting a virtual server, clean up the old relayd anchor name. Otherwise the rules are still there and valid, and will cause problems as they will override the new VS settings. Also clear out the anchors when stopping relayd or starting fresh that way no old settings could conflict.

f7496377 08/14/2013 11:16 PM Ermal LUÇI

Cleanup some code that is not needed anymore

ed7edf07 08/14/2013 11:05 PM Ermal LUÇI

Use pfSense module functions for finding interface v6 addresses. The addresses will be not in friendly format as returned by getnameinfo

2a666130 08/14/2013 12:48 PM Jim Pingle

Remove prior CSC entry when cleaning up. Fixes #3143

37143833 08/14/2013 12:41 PM Jim Pingle

Declare globals as global before defining them in openvpn.inc

c6592f21 08/14/2013 10:56 AM Renato Botelho

Add a parameter, off by default, to expand all alias items, including hostnames

9a85884b 08/13/2013 08:10 PM Ermal LUÇI

Force apinger to write the status file before getting gateway status

7aae1866 08/13/2013 10:18 AM Ermal LUÇI

Ticket #3139 try to detect if the popen is closed from an error

afa76eff 08/12/2013 04:33 PM Jim Pingle

Fix interface selections on UPnP to show the customized descriptions entered by the user. While here, add an external interface selection knob. Fixes #3141

a2dc7392 08/08/2013 06:05 PM Renato Botelho

Fix #1047

  • When advanced options (LRO, TSO and CSUM) changes, enable capabilities
    again on interfaces
  • For lagg and bridge, check caps instead of encaps and enable flags
    when it's necessary for all members
  • Take in consideration Disable (LRO, TSO, CSUM) options from...
f5013fea 08/08/2013 06:05 PM Renato Botelho

Remove duplicate polling set

624660bc 08/06/2013 08:37 PM Jim Pingle

Show apinger as a service when active, and display its status on gateway-related pages.

b1ea7072 08/06/2013 02:05 PM Jim Pingle

Don't print this message for a mobile IPsec setup. It's normal for it to not have an endpoint, and not worth spamming the log about.

8629713e 08/06/2013 08:27 AM Ermal LUÇI

Try to do the loading operations as close as possible to avoid any issues coming from it

19b4f2c5 08/02/2013 02:34 PM Ermal LUÇI

Correct bandwidth assignment so the configuration is not reverted courtesy of ipfw(4) swapped arguments. Reported-by: http://forum.pfsense.org/index.php/topic,65069.0.html

cb9799d5 08/02/2013 02:04 PM Ermal LUÇI

Reload apinger now that we can rather than restarting. Related to Ticket #3119

e2967ba6 08/02/2013 02:57 AM Chris Buechler

fix text - s/occured/occurred/

dde3cae3 08/02/2013 02:42 AM Chris Buechler

the state type is required/valid for all specifications of protocol, not
just the ones formerly listed. For instance, sloppy is valid (and widely
used on 2.0.x and some older 2.1x) with "any" protocol.

d6be721e 08/01/2013 05:52 PM Ermal LUÇI

Resolves #3121. Fix the command so it does perform correctly

721ea6f4 07/31/2013 10:19 AM Phil Davis

Reorder reverse lookup overrides so user-specified ones are effective 2.1

If the user specifies a domain override for 10.in-addr.arpa and also specifies "Do not forward private reverse lookups" then the user-specified entry is not effective. But the code was supposed to allow users to specify individual reverse lookup domain overrides that took precedence....

32fb3392 07/30/2013 06:09 PM Jim Pingle

Fix up filter_pflog_start - optimize some code, and fix $retval so that it will be restarted correctly after killing it.

14266c3e 07/30/2013 04:46 PM Jim Pingle

Show the name of the unresolvable alias name as well as the rule description to avoid ambiguity.

6ed5c06b 07/30/2013 05:46 AM Daniel Becker

use correct domain names when registering static DHCP entries in DNS

When registering static DHCP entries in DNS, we first try to use the domain name configured for the static entry (if any), then the domain name configured in the DHCP server settings for the corresponding interface (if any), and as a last resort the system domain name....

eab652e4 07/28/2013 01:31 PM Renato Botelho

Fix #3113, fix multiple english spell errors s/seperet/separat/

4d814546 07/25/2013 01:13 PM Ermal LUÇI

Optimization has nothing to do with limits

4ff2b805 07/25/2013 12:29 PM Renato Botelho

Fix #3106, parse 'not' rules right on destination for port forward + reflection proxy rules

ee157757 07/24/2013 10:26 AM Phil Davis

Allow advanced options state-related parameters to be used for TCP, UDP and ICMP

Allows the state-related parameters to be specified for UDP and ICMP as well as TCP. Discussed in forum http://forum.pfsense.org/index.php/topic,64653.0.html

df198169 07/23/2013 11:54 PM N0YB

Update rrd.inc

Fix this error
php: rc.bootup: The command '/usr/bin/nice -n20 /usr/local/bin/rrdtool update /var/db/rrd/system-mbuf.rrd N:U:U:U:U:U' returned exit code '1', the output was 'ERROR: expected 4 data source readings (got 5) from N:U:U:U:U:U'

329024c8 07/23/2013 09:56 AM Ermal LUÇI

Implement an option to allow using the IPv4 connectivity interface for sending the dhcpv6 information. Usually useful for ppp[oe] type links and some ISP

f1c252cf 07/20/2013 12:15 AM N0YB

3652 days worth is a too much. Scale it back to more reasonable 1.25 x maximum used data (2284 days).

8e088ea5 07/19/2013 01:39 PM Jim Pingle

Handle IPv6 in ip_in_interface_alias_subnet()

166fc3cd 07/19/2013 01:18 PM Phil Davis

Minimize inclusion of bogonsv6

If "Allow IPv6" is on, but actually there is no enabled interface with "Block bogon networks" enabled, then we also do not need to include the bogonsv6 table into pf.
This allows some more flexibility for users to leave "Allow IPv6" checked, but still not use up memory for bogonsv6.

30adceda 07/18/2013 01:35 PM Jim Pingle

Disable the BEAST protection by default because the GUI will break if you use this and have a Hifn card installed. Others may break similarly. Change it into a checkbox option, off by default, and automatically disable it if a conflicting card has been detected.

dc3fc54a 07/17/2013 02:53 PM Jim Pingle

Don't blow up the config if someone enters int'l chars in an LDAP attribute/DN field. Ticket #2227

298020b2 07/17/2013 02:15 PM Jim Pingle

Add LDAP server options to control UTF8-encoding of parameters. Fixes #2227. While I'm here, add a checkbox to prevent the stripping of @ from the LDAP username if the user wants the full name transmitted.