Project

General

Profile

Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
68afc597 01/13/2022 06:43 PM Jim Pingle

Improve OpenVPN Data Cipher handling. Fixes #12677

(cherry picked from commit 78ce96a9af3b2ab5159ef6623078bfc4b15f8a89)

b8fd0558 01/11/2022 06:26 PM Steve Beaver

netgate-ca.pem is now in the base image at /usr/local/share/${product_name}/ssl/netgate-ca.pem

be84a4a4 01/06/2022 04:26 PM Jim Pingle

Improve solo weighted GW in Failover. Issue #12660

If there is only one gateway to add in a macro definition, there is
no point in repeating the string based on the gateway weight.

This is a potential contributing cause to issue #12660

283f9e8c 01/03/2022 06:40 PM Jim Pingle

Disable DNS Resolver recursion if the selected outgoing interfaces are not available. Fixes #12460

Originally-By: Viktor Gurov

1f3baf61 01/03/2022 06:31 PM Jim Pingle

Revert "Use OpenVPN async client-connect, clear stale rules, add option to limit connections per user. Implements #12407 and #12332 and #12267"

This reverts commit 7aaa20d95a345c4688e8786c755c7d0433451688.

8f2f85c3 01/02/2022 01:05 AM Luiz Souza

Update the Copyright year of the files owned by Rubicon/Netgate.

7034ac09 12/30/2021 08:01 PM Viktor Gurov

Create port forward rules for PPPoE Servers interface. Fixes #12452

49eba660 12/29/2021 09:53 AM Viktor Gurov

Fix SSH keys permissions on restore. Fixes #12637

1fa4c473 12/28/2021 12:50 PM Viktor Gurov

Do not update Dynamic DNS if the public IP address cannot be determined. Fixes #12617

c3474eef 12/27/2021 02:36 PM Viktor Gurov

Ignore DynDNS requestif for non-custom providers. Fixes #12631

ecfe0d28 12/22/2021 05:52 PM Viktor Gurov

Merge pull request #4550 from znerol-forks/fix/master/radvd-search-list

4bcd43b4 12/22/2021 05:50 PM Viktor Gurov

Merge pull request #4546 from olehfb/namedotcom_dyndns

3a973ba4 12/22/2021 06:56 AM znerol

Initialize searchliststring variable in every loop iteration

2fe32b3b 12/21/2021 03:32 PM Viktor Gurov

Add tag 1 to Captive Portal passthrough MAC table. Fixes #12615

070fb1a8 12/20/2021 03:16 PM Viktor Gurov

Do not update DNS RFC2136 if the public IP address cannot be determined. Fixes #12617

4dde40ec 12/17/2021 01:59 PM Viktor Gurov

Pushover notifications fix. Issue #12614

7054b63f 12/16/2021 07:06 PM Viktor Gurov

Use Trusted Store CAs for Dynamic DNS. Fixes #12589

da836151 12/16/2021 05:57 PM Christian McDonald

Bounce dipinger when bringing down interface that has a gateway

e7de40d5 12/15/2021 04:38 PM Viktor Gurov

One.com DDNS update. Issue #12352

(cherry picked from commit 9a84d3b0b5e4709a5bde99d3edf4f8e89524b602)

2fbbd164 12/14/2021 01:54 PM Jim Pingle

Init tracker ID before filter reload. Fixes #12588

6317d66d 12/13/2021 08:05 PM Kristof Provost

syslog: fix ridentifier retrieval when looking up by rule number

pf rules no longer include the ridentifier immediately after the rule
number but instead list it as a separate keyword like this:

@4(0) block drop in log inet all label "Default deny rule IPv4" ridentifier 1000105583...

8acd2c9e 12/13/2021 01:35 PM Kristof Provost

syslog: fix ridentifier retrieval

pf rules no longer include the ridentifier immediately after the rule
number but instead list it as a separate keyword like this:

@4(0) block drop in log inet all label "Default deny rule IPv4" ridentifier 1000105583

...

3e975038 12/08/2021 10:50 PM Kristof Provost

Rename 'tracker' to 'ridentifier'

FreeBSD has included our 'tracker' functionality, but calls it
'ridentifier' instead. Change the rule generating code to cope with
that.

2b6a3712 12/07/2021 07:21 PM Viktor Gurov

IPsec IKEv2 Retransmission options. Implements #12184

46bd32bb 12/07/2021 02:17 PM Steve Beaver

Revert "Certmanager mvc"

This reverts commit 033c3ae82d20ca5760ed483cf8d0c947764b2371

033c3ae8 12/07/2021 01:49 PM Steve Beaver

Certmanager mvc

af9fb265 12/07/2021 08:45 AM Viktor Gurov

IPsec on backup CARP group validation. Fixes #12566

6a9fe85f 12/06/2021 01:58 AM olehfb

Add dynamic DNS service provider Name.com, closes #12567

cd974f08 12/03/2021 02:21 PM Viktor Gurov

SNMP IPv6 support. Implements #12325

d6bbbf35 12/03/2021 02:21 PM Viktor Gurov

Input validation to prevent removing a gateway if it is still in use by DNS servers. Fixes #8390

dc22e511 12/03/2021 02:20 PM Viktor Gurov

Backup and Restore SSH Host Key(s). Feature #11118

332052b8 11/25/2021 07:30 PM Viktor Gurov

Static routes handling update. Fixes #11599 #11895 #7547

  • Confirmation box to apply static routes add/route/change
  • Reloading routes using aliases after changing the alias
  • Correct route updates after changing destination or gateway
76902a1a 11/22/2021 05:07 PM Viktor Gurov

Allow to select 3 (8s) NTP min poll value. Implements #9439

bbb3bbeb 11/16/2021 09:46 AM Viktor Gurov

DNS check improvements for fw check and ACB. Fixes #12141

7aaa20d9 11/15/2021 02:51 PM Marcos M

Use OpenVPN async client-connect, clear stale rules, add option to limit connections per user. Implements #12407 and #12332 and #12267

6a41d476 11/15/2021 02:47 PM Viktor Gurov

Port Forward checks for special interfaces and reflection type. Fixes #12452

0cfd0083 11/15/2021 02:13 PM Viktor Gurov

NTP Peer mode. Implements #11496

d1e65bb2 11/04/2021 03:06 PM Viktor Gurov

Automatic outbound NAT for Reflection IPv6 support. Fixes #12500

b3979f4a 11/02/2021 01:16 PM Viktor Gurov

Add Chelsio T6 CXGBE (cc) to ALTq capable list. Fixes #12499

4d016cc4 10/28/2021 08:59 AM Kristof Provost

Do not detach ng_ether from physical interfaces

There's no measurable performance impact1 of leaving an unused ng_ether
node attached to ethernet interfaces, so don't waste time trying to
ensure we only attach to interfaces where we expect to use netgraph....

66b1de4c 10/27/2021 08:46 PM Jim Pingle

IPsec SPD status updates. Implements #12397

  • Fix backend parsing of setkey data
  • Check for VTI vs tunnel mode
  • Output mode in GUI status, and VTI interface name if available
  • Make directionality of endpoints and arrow icon match in both the
    direction column and tunnel endpoints column.
c7a78ad6 10/22/2021 08:24 PM Viktor Gurov

Elliptic Curve 25519, 448 bit -> Elliptic Curve 448, 448 bit PH2 rename. Fixes #12350

a96a7151 10/21/2021 03:11 PM Viktor Gurov

Delete stale OpenVPN RADIUS ACL generated rules. Fixes #12481

aa1936ee 10/21/2021 01:27 PM Viktor Gurov

DNS check optimization for NDP diag page. Fixes #11512

6e889d88 10/20/2021 04:11 PM Viktor Gurov

Fix OpenVPN status page halt function when client_id=0. Issue #12416

2c702751 10/20/2021 04:05 PM Viktor Gurov

IPsec PC/SC daemon status / services page fix. Issue #12468

0b783d30 10/20/2021 01:50 PM Viktor Gurov

Remove stale captiveportal_online_users file on boot. Fixes #12455

dc883862 10/18/2021 03:14 PM Viktor Gurov

Reset CP DB on unclean shutdown if preservedb option is not enabled. Fixes #12355

661c23ea 10/18/2021 03:13 PM Viktor Gurov

GRE/GIF interface configure fix. Issue #12288

322ac50f 10/18/2021 03:13 PM Viktor Gurov

Elliptic Curve 25519, 448 bit -> Elliptic Curve 448, 448 bit rename. Fixes #12350

aabaad0a 10/18/2021 03:12 PM Viktor Gurov

Mute kernel messages on dummynet and thermal hardware modules load. Fixes #12454

67fedb90 10/17/2021 05:50 AM Viktor Gurov

Use proxy for DDNS Check IP Services. Feature #12342

fd331bdc 10/13/2021 05:46 AM Viktor Gurov

Dynamic DNS proxy option. Fixes #12342

b9fbc36a 10/13/2021 05:13 AM Viktor Gurov

Slack Notifications. Feature #12291

59724429 10/09/2021 07:35 AM Viktor Gurov

Do not check subnet overlapping on 6RD interfaces. Fixes #12371

e33311fe 10/08/2021 03:50 PM Viktor Gurov

DNS check optimization. Fixes #11512

1ab2ec0a 10/08/2021 03:49 PM Viktor Gurov

IPv6 Port Forwarding Proxy+NAT input validation. Fixes #12319

08ef78ac 10/08/2021 03:35 PM Viktor Gurov

Allow to halt OpenVPN client on status page. Issue #12416

ed1ff340 10/08/2021 03:34 PM Viktor Gurov

Do not show Configuring IPsec VTI interfaces message at boot if no VTIs are configured. Fixes #12419.

79b8b049 10/08/2021 03:30 PM Viktor Gurov

Remove unused function from pfsense-utils.inc. Todo #12406

0512975e 09/22/2021 12:39 PM Christian McDonald

Fixes redmine #12396

b9885720 09/20/2021 04:17 PM Luiz Souza

Bump up the config version to match a change in plus.

8e2de557 09/20/2021 12:29 AM Luiz Souza

Keep 'enableserial_force' in /conf when a factory reset is performed.

Ticket: #6880

dbe51a34 09/10/2021 03:50 PM Marcos M

additional fix #7801 Include IPsec P2 address type in vpn_networks

454cfb43 09/10/2021 02:12 PM Christian McDonald

Fix disk widget upgrade script assuming widgets always have an index

2de8b1f5 09/09/2021 11:08 PM Christian McDonald
  • Removes disk usage from system information widget
  • Adds Pfsense\Services\Filesystem\ library
  • Adds new disk widget
9dac41af 09/09/2021 03:08 PM Kristof Provost

captiveportal: fix ipfw rules

When we authorise a client we add it to the *auth(up|down) tables.
This means traffic will pass and not be forwarded, as piped traffic does
not pass through the firewall again (if net.inet.ip.fw.one_pass is set).

However, these rules are 'layer2', so when the traffic is passed it's...

dd155b32 09/08/2021 11:19 AM Viktor Gurov

IPsec Widget none/disabled tunnels fixes. Issue #12337

f7e2e6e1 09/03/2021 04:42 PM Viktor Gurov

Yandex PDD DDNS token fix. Issue #12331

e9705a77 09/02/2021 06:46 PM Jim Pingle

Use correct var f/OpenVPN IPv6 ACL. Fixes #12333

Fix variable name when referencing an OpenVPN IPv6 tunnel network while
creating a DNS Resolver ACL entry.

While here, also add a safety check to ensure we never attempt to add an
ACL with an empty address.

7f0d57f4 09/02/2021 12:12 PM Jim Pingle

Correctly resolve VTI remote addr. Fixes #12328

Use ipsec_get_phase1_dst() to resolve an IPsec P1 remote gateway
address rather than passing an FQDN directly to ifconfig

d582c5be 09/01/2021 01:31 PM Viktor Gurov

IPsec PH2 AH proposals order fix. Issue #12323

0a70f90a 08/31/2021 06:03 PM Jim Pingle

OpenVPN exit notify & inactive incompatibilities

  • Ignore exit notify in problematic cases. Fixes #12102
  • Ignore inactive seconds in problematic cases. Fixes #12219
  • Warn against using these options in problematic scenarios
  • Hide from the GUI in obvious incompatible scenarios
83314732 08/31/2021 02:09 PM Viktor Gurov

Cleanup and improve easyrule. Fixes #12151

4b8d710c 08/30/2021 09:02 PM Viktor Gurov

OpenVPN Aliases support. Implements #2668

336103c4 08/30/2021 06:19 PM Jim Pingle

Consider GWG in ipsec_force_reload. Fixes #12315

1394773d 08/27/2021 09:53 PM Luiz Souza

Rename a few missing Netgate devices.

Super Micro XG-1537 -> Super Micro 1537
Super Micro XG-1541 -> Super Micro 1541

2c393b55 08/27/2021 12:49 PM Jim Pingle

Add null check. Fixes #9092

If the value is undefined in config.xml this will be null, not an empty
string.

0ef2ff26 08/26/2021 03:38 PM Luiz Souza

Fix a typo in the Netgate 5100 name.

df945787 08/26/2021 03:21 PM Luiz Souza

Rename the Netgate devices.

XG-15xx -> 15xx
SG-5100 -> Netgate-5100

fe72327b 08/26/2021 01:03 PM Jim Pingle

Revert "Clean up some messy HTML in the cert/ca display code. Prep for future MVC changes."

This reverts commit 8d4fcd7ac1167894136e337fc619e63fa7200fa0.

7628b091 08/24/2021 01:33 PM Jim Pingle

Increase default RA intervals. Fixes #12280

a1eef308 08/24/2021 01:24 PM Jim Pingle

Increase default RA intervals. Fixes #12280

This code path was not included in the original diff.

99dfecb7 08/24/2021 01:12 PM Renato Botelho

radvd: Avoid empty AdvDNSSLLifetime (Fixes #12173)

Make sure $raadvdnsslifetime is defined on second foreach

dd8d9e23 08/23/2021 07:36 PM Jim Pingle

Disable newsyslog compression w/ZFS. Issue #12011

ZFS compresses /var/log by default. If the ZFS dataset /var/log has
compression enabled on the first boot post install or factory reset,
then set a flag to disable newsyslog compression unless the user
overrides the setting in the configuration....

953aba88 08/23/2021 01:52 PM Jim Pingle

Don't wait on manual IPsec actions. Fixes #12298

Use a timeout with swanctl --initiate, and use --force for swanctl
--terminate. This will allow the commands to succeed and return without
waiting on the remote to respond. The negotiation continues in the...

583062bf 08/20/2021 04:06 PM Viktor Gurov

IPv6 fix for setdefaultgateway(). Issue #12282

f873a4ef 08/20/2021 02:01 PM Jim Pingle

Update IPsec Filter Mode text. Implements #12289

VTI mode also works for transport mode (e.g. GRE), so note that as well.

762d3cc9 08/20/2021 05:20 AM Viktor Gurov

Increase default IPv6 router advertisement (RA) intervals and lifetime. Fixes #12280

923399be 08/19/2021 05:14 AM Viktor Gurov

Allow to use nested URL alias in URL alias. Fixes #11863

cf757a80 08/18/2021 08:11 PM Jim Pingle

Regex cleanup should also kill {}. Fixes #12257

It's not used often (and less in the GUI) and can be a source of
problems with large numbers of repetitions even outside of grouped
expressions.

a38556ff 08/18/2021 04:12 PM Jim Pingle

Use SHA512 to hash user password. Implements #10298

Original commit by Viktor Gurov

7be7d84e 08/18/2021 01:58 PM Jim Pingle

Ensure Unbound python script exists. Fixes #12274

Check to make sure a referenced python script exsits before attempting
to use it in the Unbound configuration. If the file does not exist,
Unbound will fail to start.

bca881c4 08/17/2021 01:12 PM Jim Pingle

Correct grep usage where needed. Fixes #12265

8cd3f92f 08/17/2021 01:11 PM Jim Pingle

Regex cleanup change. Fixes #12257

Rather than attempting to cleanup group repetition, just discard the
unwanted pattern.

3a0f6f36 08/17/2021 06:07 AM Viktor G

Move IPsec Mobile additional configuration attributes to strongswan.conf. Fixes #11447

4f04c78e 08/17/2021 06:05 AM Viktor Gurov

Fix IPsec PH1 with Remote Gateway 0.0.0.0 rules creation. Issue #12262

d57eab57 08/17/2021 06:05 AM Viktor G

VLAN/QinQ-only interface mismatch detection. Fixes #12170

57a737f1 08/16/2021 05:42 PM Jim Pingle

More route display changes. Fixes #12257

  • Move escape_filter_regex() from syslog.inc to util.inc since it will
    be used by things other than syslog.
  • Add some basic regex sanity and consistency check functions
  • Cleanup diag_routes.php route filter before use...
c5bda432 08/14/2021 05:33 AM Viktor G

Do not delete disabled routes. Fixes #10706