Project

General

Profile

Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
9cf1dbff 04/20/2015 07:04 PM Stuart Wyatt

Remove duplicate 'ppp' case in switch statement

7a747654 04/20/2015 06:53 PM Ermal Luçi

Allow to configure new modes for phase1 according to RFC 5903 by manually merging pull request #1501 partially. While here preserve style.

0fa9acb7 04/20/2015 06:34 PM Ermal Luçi

Merge pull request #1617 from Gertjanpfsense/master

0608bd3c 04/18/2015 08:34 AM Ermal Luçi

Implement make bofre break feature avaliable on strongswan 5.3.0 useful for IKEv2. Fixes #4626

a0f190a2 04/17/2015 02:46 PM Renato Botelho

Do not try to add package tabs info to config

Remove broken code that was supposed to add packages tabs entries to
config.xml. Since tag['name'] doesn't exist, it only adds the first item
of first installed package, and in the end this is not used at all since...

6b394e1c 04/17/2015 02:36 PM Ermal Luçi

Merge pull request #1620 from ibauersachs/newipsecdns-eap-radius

e115bd22 04/17/2015 12:25 PM Renato Botelho

Fix php module names since check is case sensitive

1d75a92f 04/17/2015 08:08 AM Ingo Bauersachs

Make auth_get_authserver_list available to vpn.inc

This is a follow-up to PR #1612 and avoids a crash in this script at random times.

ea6cbc39 04/17/2015 06:50 AM Gertjan KROEB

Update voucher.inc

As https://redmine.pfsense.org/issues/4625

abaa7feb 04/16/2015 06:17 PM Ermal Luçi

Fixes #4625 correct disconnection of users especially when called from xmlrpc code.

2bc08de4 04/16/2015 05:42 PM Ermal Luçi

Merge pull request #1612 from ibauersachs/ipsec-mobile-eap-radius

0545a75e 04/16/2015 05:37 PM Chris Buechler

Always do a filter reload in vpn_ipsec_configure to ensure the ruleset is
updated where necessary in every IPsec change scenario.

eee053fe 04/16/2015 03:13 PM Renato Botelho

Remove boot_serial='yes' from loader.conf when serial is disabled, error introduced by me on commit 986e77a2eab

9b837c5d 04/16/2015 06:44 AM Phil Davis

Fix unbound warning when dnsallowoverride off and forwarding on

Reported in forum: https://forum.pfsense.org/index.php?topic=92437.0

The $ns array was being used further down, but if dnsallowoverride was off, the array never got created.

563771b1 04/15/2015 01:06 PM Renato Botelho

Define var_path global key since it is being used in interfaces.inc, but it was not being declared anywhere

cb377516 04/15/2015 12:28 PM Ingo Bauersachs

Add support for EAP-RADIUS to IKEv2 Mobile Clients

fc70ad87 04/15/2015 12:24 PM Renato Botelho

Merge pull request #1601 from phil-davis/check-overlapping-subnets

457e7e34 04/15/2015 03:51 AM Chris Buechler

Re-enable verification for selfhost since their chain issue is resolved. Ticket #4545

decb0b11 04/15/2015 02:52 AM Chris Buechler

set forcesync to 1 by default for now, testing potential impact for Ticket #4523.

53bc8504 04/15/2015 02:52 AM Chris Buechler

Revert "Make forcesync default to the same behavior as freebsd rather than as intended for cf cards. People with issues on CF can enable the tunable"

This reverts commit 34dced26198480d7b02e80578df40336fef89043.

34dced26 04/14/2015 09:20 PM Ermal Luçi

Make forcesync default to the same behavior as freebsd rather than as intended for cf cards. People with issues on CF can enable the tunable

cd5084d5 04/14/2015 06:50 PM Renato Botelho

Remove redundant/unused call to kldstat

f74636b6 04/14/2015 06:48 PM Renato Botelho

Fix operator

5d6e9640 04/14/2015 06:48 PM Renato Botelho

Fix typo in variable name

67335f40 04/14/2015 01:17 PM Renato Botelho

Merge pull request #1603 from phil-davis/patch-1

460610b2 04/14/2015 12:53 AM Chris Buechler

Don't remove all of /usr/local/libdata as obsolete files. User-installed
package contents may live there, factory default configs live there.

561b76b5 04/13/2015 01:58 PM Renato Botelho

Merge pull request #1605 from Robert-Nelson/issue-4603

52f67967 04/13/2015 01:57 PM Renato Botelho

Merge pull request #1600 from Robert-Nelson/remove-obsolete-logging

6587e2af 04/12/2015 04:18 PM Robert Nelson

Only initialize package's log if it doesn't exist

e27bc6cf 04/11/2015 12:43 PM Phil Davis

Fix OpenVPN server listening on associated IPv6 address

As reported in forum https://forum.pfsense.org/index.php?topic=92174.0
If the ordinary interface is selected for an OpenVPN server and an IPV6 protocol is selected (e.g. UDP6) then al is good, the "local" line in the server1.conf is written with the primary IPv6 address of the interface....

986e77a2 04/10/2015 07:21 PM Renato Botelho

Setup ADI boards to boot only using serial to avoid duplicated output when VGA redirection is enabled

3490b8dd 04/10/2015 12:14 PM Phil Davis

Check for overlapping subnets when saving interface addresses

This checks if a static IP address entered for an interface has a subnet
that overlaps with any other configured subnet. e.g.:
LAN is IPv4 10.10.12.1/24
Then try to set OPT1 to 10.10.13.1/23 - it overlaps with LAN because...

5d655e26 04/09/2015 08:48 PM Robert Nelson

Remove obsolete logging code which is duplicated in system_syslogd_start()

5fba3e95 04/09/2015 12:21 PM Renato Botelho

Merge pull request #1467 from PiBa-NL/php_errorlog

5274ecf0 04/09/2015 05:30 AM Chris Buechler

Skip reflection rdrs where the interface doesn't have an IP. Ticket #4564

b48f6580 04/09/2015 02:43 AM Chris Buechler

Allow disabling the APIPA block via hidden config option. Very rarely necessary or desirable, but Amazon VPC VPNs use that as their tunnel subnet with BGP setups.

7c0c6355 04/08/2015 11:47 PM Chris Buechler

Only restore rrd.tgz where platform is appropriate, or RAM disk being
used, otherwise you're restoring a probably old backup file. Ticket #4531

bc09b90a 04/06/2015 06:23 PM Renato Botelho

Add Super Micro C2758 to the list of known platforms

9f6d592f 04/06/2015 12:43 PM Renato Botelho

Merge pull request #1595 from dneuhaeuser/patch-1

05391c58 04/06/2015 12:41 PM Renato Botelho

Merge pull request #1597 from phil-davis/Common-typos

b3f2f476 04/05/2015 04:47 PM Pi Ba

php error logging should 're-fix' with less side effects for now.. https://redmine.pfsense.org/issues/4143

cf3904bd 04/05/2015 09:45 AM Phil Davis

Code style

Couple of spaces for new code merged from an old repo/branch

75f163f0 04/05/2015 02:48 AM Chris Buechler

Un-screw-up merge

686e53c0 04/05/2015 01:37 AM Chris Buechler

Include additional subnets for RAs in radvd.conf. Ticket #4468

Conflicts:
etc/inc/services.inc

0a9e6c85 04/05/2015 12:50 AM Chris Buechler

Fix up Ticket #4504 implementation. Match config style with other areas. Use a config setting to disable, rather than enable, this functionality since it's enabled by default so the tag isn't necessary in the default config. Remove now unnecessary config upgrade code.

c01f5dac 04/05/2015 12:36 AM Chris Buechler

fix type. Ticket #4504

d6fa899d 04/04/2015 05:23 PM Phil Davis

Few minor text typos

Note that advertise is spelt with an "s" in other places in the GUI, so
making it consistent in services_ntpd - but maybe Americans do spell it
"advertize" these days?

5e8e558c 04/04/2015 05:24 AM Chris Buechler

add etc/inc/array_intersect_key.inc to obsoletedfiles

3ab15aaf 04/04/2015 05:18 AM Chris Buechler

shouldn't need this as its own inc anymore, but only changing in master since 2_2 nearing release

e4dcbe49 04/04/2015 05:11 AM Chris Buechler

uploadbar dir no longer needed

91957c42 04/03/2015 08:01 PM Chris Buechler

verify certs by default here

f6f11800 04/03/2015 06:32 PM Ermal Luçi

Prevent empty addresses for being put in the ruleset. Ticket #4564

8206b2d9 04/03/2015 06:11 PM Ermal Luçi

Ticket #4504 actually make it correct

74eaabbb 04/03/2015 06:10 PM Ermal Luçi

Upgraded configurations should keep the default configuration of bypassing lan from ipsec. Ticket #4504

755b75c7 04/03/2015 06:08 PM Ermal Luçi

Fixes #4504 Provide a newline to generate proper config

0887e836 04/03/2015 05:59 PM Ermal Luçi

Fixes #4504 Allow the bypass policy for LAN to be enabled and prevent traffic sent to lan ip to go to the ipsec tunnel

92c27873 04/03/2015 05:39 PM Dennis Neuhaeuser

small correction of relative paths to icons

8b760d4b 04/03/2015 08:09 AM Chris Buechler

Only use mobile clients PFS config with mobile ph2ent. Ticket #4538

Conflicts:
etc/inc/vpn.inc

3dac50ab 04/03/2015 07:34 AM Chris Buechler

disable SSL validation for selfhost since it fails. Ticket #4545

db9e5154 04/03/2015 03:59 AM Chris Buechler

enable ike_name for daemon facility as well, to add connection identifiers to logs.

717fc06b 04/03/2015 12:46 AM Chris Buechler

Use real interface here for dhcrelay v6. Ticket #4572

6d457361 04/03/2015 12:10 AM Chris Buechler

Don't omit hosts specified as "0". Ticket #4573

e57f0e33 04/02/2015 04:39 PM Renato Botelho

Merge pull request #1594 from phil-davis/patch-1

80e47bb0 04/01/2015 01:35 AM Chris Buechler

call this RCC-VE rather than C2358

0b34a56c 03/31/2015 08:22 PM Chris Buechler

Add a check for whether IPsec is enabled, so it doesn't spit out "IPsec
daemon not running or has a problem!" when IPsec isn't enabled.

1d433e01 03/31/2015 05:44 PM Phil Davis

Bug #4566 Only route-to a gateway if it is not force_down

When generating policy-routing rules there was no check if a gateway had force-down set, so gateway with force_down set would still get policy-routing rules written for it, even if skip_rules_gw_down was enabled.

0ca36ca3 03/31/2015 02:03 PM benny benny

Fix IPsec Advanced Settings uniqueids. It was neither set in strongswan config, nor picked up correctly in the UI.

14a6c356 03/28/2015 02:16 PM Phil Davis

Fix brackets

that I broke - sorry, I did test on a 2.2.1 system but then had to make my changes into a master version to submit the pull request. Obviously I missed this!
Chris noticed it it 2.2-RELENG branch already with commit https://github.com/pfsense/pfsense/commit/e593bac7e025eaec50e2591557c76fe27c254b32

56effb56 03/28/2015 05:10 AM Chris Buechler

Remove wireless cards from ALTQ-capable interfaces, since ALTQ is broken on wlandev in FreeBSD 10.x at the moment. Ticket #4406

45c15a59 03/27/2015 06:59 PM Renato Botelho

Merge pull request #1572 from jlduran/no-server-header

2c657294 03/27/2015 06:53 PM Renato Botelho

Merge pull request #1578 from Robert-Nelson/rfc2136_ignore_ipv4_ipv6

62dc93d1 03/26/2015 09:47 PM Chris Buechler

Include net.key.preferred_oldsa in the sysctl list, set to 0 (disable) so
it doesn't fall through to the default (1).

ea08d2b2 03/26/2015 06:48 PM Robert Nelson

Change to Record Type with A and AAAA as values.

7db3d1c7 03/26/2015 04:24 PM Robert Nelson

Use address types instead of addresses.

ad20e46d 03/26/2015 04:19 PM Robert Nelson

Merge branch 'master' into rfc2136_ignore_ipv4_ipv6

86feced0 03/26/2015 03:58 PM Renato Botelho

Merge pull request #1586 from phil-davis/patch-6

9afdc939 03/26/2015 02:22 PM Renato Botelho

Merge pull request #1584 from phil-davis/patch-2

a5bc12f0 03/26/2015 02:13 PM Renato Botelho

Merge pull request #1575 from k-paulius/misc-dhcp6c

a110a0cb 03/26/2015 12:51 AM Phil Davis

Always include general setup DNS servers in unbound.conf

when forwarding mode is on.
The General Setup setting "Allow DNS server list to be overridden by DHCP/PPP on WAN" has always been used in dnsmasq to ADD DHCP/PPP provided DNS servers to the list, while also keeping the DNS servers specified in General Setup. That behavior is needed if:...

2400f545 03/26/2015 12:43 AM Jose Luis Duran

Disable lighttpd server header

Set the `server.tag` to an empty string to prevent lighttpd from
displaying the version number in the header.

4ad1ddf2 03/25/2015 06:14 PM Phil Davis

Only list nameservers once in resolv.conf

I was on a test system and had an upstream DNS server IP specified in System-General Setup. WAN was setup with a static IP and a gateway to that upstream device. All good.
Then I also checked "Allow DNS server list to be overridden by DHCP/PPP on WAN" and changed WAN to be DHCP. It received by DHCP the same DNS server IP that already happened to be in General Setup (and the same gateway IP - not the issue here)....

a3cecbc3 03/25/2015 02:40 PM Jim Pingle

Eliminate the "this_device" test from the resync check in rc.openvpn.
It is not necessary to check, as the only times a gateway event should trigger the VPN to restart are when the current and new devices differ.
This also allows us to simplify the code a bit and eliminate some single-use variables....

4aefcf91 03/24/2015 06:09 PM Jim Pingle

The logic of this test seems to be incorrect.
If the interface is the same, this test will fail, and that's the one case that should not need a resync.
The logic in this test has been flipped and reversed a few times over the years and without comments it's difficult to discern its true purpose.

9329ec08 03/23/2015 09:32 PM k-paulius

Supress errors when opening custom DHCP config file and check if content was successfully retrieved. Prevents PHP from throwing error in case file does not exist.

fc1f2003 03/23/2015 09:13 PM k-paulius

Log to syslog and get rid of useless variable.

52cbfd45 03/23/2015 06:20 PM Robert Nelson

Use radio buttons to select between IPv4, IPv6 or Both.

a3fb1412 03/23/2015 02:34 PM Phil Davis

Be consistent about Unbound service descriptive name

Forum: https://forum.pfsense.org/index.php?topic=91075.0

For DNS Forwarder (dnsmasq)
1) dnsmasq is the name of the service
2) DNS Forwarder is the text description

Make Unbound consistent with that, so that menu names and services status display and... work in the same way:...

6fdf663b 03/22/2015 11:28 PM Robert Nelson

Add option to not register IPv4 and/or IPv6 addresses.

90e5c03a 03/20/2015 07:03 PM Renato Botelho

Merge pull request #1486 from jlduran/patch-1

db0ec10e 03/20/2015 04:12 AM k-paulius

Remove old dhcp6c and rtsold config scripts when bringing down interface.

f31052c7 03/20/2015 03:47 AM k-paulius

Supress errors when opening custom DHCP6 config file and check if content was successfully retrieved.
Prevents PHP from throwing error in case file does not exist.

ddd1f864 03/20/2015 03:26 AM k-paulius

A mix of literal tabs, spaces and \t is used in dhcp6c config file code. Convert evertyhing to use \t.

dd5d1a24 03/20/2015 03:05 AM k-paulius

DHCP6 config file override, advanced and basic settings override each other so put them in single
if/else statement rather than always generating all three setting types.

d325e908 03/19/2015 04:55 AM Chris Buechler

Add option for wireless standard "auto", to omit "mode" entirely from ifconfig. This shouldn't be necessary, but specifying mode has proven to trigger driver problems that don't exist if it's left unspecified (such as FreeBSD PR 198680). Chosing "auto" fixes ath(4) BSS mode issues otherwise preventing it from connecting.

106f3451 03/18/2015 05:47 PM Jose Luis Duran

Use `none` instead of a whitespace in sshd_config

Use the `none` keyword instead of a whitespace to disable the FreeBSD version in sshd_config.

e5549707 03/16/2015 11:19 AM Renato Botelho

Merge pull request #1564 from phil-davis/patch-2

44b9fbdc 03/14/2015 02:39 PM Phil Davis

Use subnet address in OPT net rules

Example: LAN IP 10.0.1.1/24 OPT1 IP 10.0.2.1/24
Rules with SRC or DST LANnet correctly have 10.0.0.0/24 (the subnet base address) in /tmp/rules.debug
Rules with SRC or DST OPT1net have 10.0.2.1/24 (the OPT1 IP address with OPT1 net mask) in /tmp/rules.debug...

a08d5055 03/13/2015 08:45 AM Phil Davis

Update get_possible_traffic_source_addresses returned array format

With this change it looks to me like the way it is intended to be, based
on what was done to get_possible_listen_ips()
Please review and check if this is what was intended for the code. With...

f2f34088 03/13/2015 08:16 AM Chris Buechler

txpower was disabled for good reason it would appear, it triggers syntax errors in some configurations. Disable it again since it's been disabled for years, and comment out the user-facing config portion for now since it doesn't do anything. Ticket #4516

664aef0b 03/13/2015 03:05 AM Chris Buechler

correct missing == in ipsec.inc