Project

General

Profile

Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
97af9f20 03/10/2021 07:10 PM Viktor Gurov

Put OpenVPN route-nopull option after custom options. Fixes #11448

(cherry picked from commit 969574b6dbb124e98595ca537c0d176d908707d0)

523f931b 03/10/2021 07:09 PM Viktor Gurov

Use set_curlproxy() function for cURL proxy configuration. Issue #11476

(cherry picked from commit 8b424bca02372246210fba3cf36045a704c11ae3)

1fa63e8d 03/10/2021 07:09 PM Steve Beaver

Fixed #11464 by adding proxy configuration to web service calls

(cherry picked from commit 2cb3c56db2366c9cadb04757bd3143ea0d7e7378)

b656061a 03/10/2021 07:06 PM mschiegl

Fix openssl digest algorithm param in openvpn.inc

At least in OpenSSL 1.1.1i-freebsd, used by pfsense 2.5, there is no longer a "list-message-digest-algorithms" parameter. It has been replaced by "list -digest-algorithms".
The old parameter results in an error 'Invalid command 'list-message-digest-algorithms'; type "help" for a list' and may even cause an endless loop on startup/migration....

82690894 03/10/2021 07:06 PM Viktor Gurov

Set correct DHCP failover peer IP on XMLRPC sync. Fixes #11519

(cherry picked from commit 490b5b480f1b46a6f93e0ba99fff578a61f3293c)

85799d56 03/10/2021 07:05 PM Viktor Gurov

Restart unbound on interface recover. Fixes #11547

(cherry picked from commit a1fe814421904ca00b6a04431d62ba18dcebf607)

f1864df6 03/10/2021 07:04 PM Viktor Gurov

IPsec peer ID Any fix. Issue #11555

(cherry picked from commit 4a51b9cd8fd58b26c5c30784b0736cc5757e86fc)

6cba83ab 03/10/2021 07:02 PM Viktor Gurov

Cisco AVPair parse {clientip}. Fixes #11561

(cherry picked from commit f4d883dadee6e339997b29f5b4623a88b190b840)

3dc01871 03/10/2021 07:01 PM Dmitry Bashkarev

Fixed bug parsing netmask cisco acl

(cherry picked from commit 321fbbdb5bffe5d331aea5330241d42b0ab8d250)

d76f5796 03/10/2021 07:00 PM Jim Pingle

Use correct parameters when adding WG IPv6 tunnel addr. Fixes #11618

(cherry picked from commit 8579d26bfb0dea0386c61008ade222c0ea29aa98)

6140f34e 03/10/2021 06:58 PM Jim Pingle

Correct rsort_log_filename() behavior. Fixes #11639

(cherry picked from commit b9c1679dae94fb2d406cfc386f667eed2378b6d2)

644a5333 03/10/2021 06:57 PM Jim Pingle

Fix handling of renewing cert w/o SAN. Fixes #11652

(cherry picked from commit 09d3fe621a56292817a85a54916e8b99e2b26c00)

73a1434a 03/10/2021 01:16 PM Renato Botelho

Welcome pfSense CE 2.5.1-RELEASE

b6aec58f 03/09/2021 07:21 PM Renato Botelho

Report full product version, including -pN

(cherry picked from commit feefcc31b78c1ef99ffd9deb509b05ccdb1e61ef)

89b1338a 03/03/2021 09:24 PM Jim Pingle

Fix typo

(cherry picked from commit 361ad87b85fdc0f97a2d7f3dcb6ec439e105e320)

e85c56b3 03/03/2021 07:53 PM Renato Botelho

Add missing break

(cherry picked from commit f26a816b7080f0ef45a8cb3938cfd878dbaef71e)

f731957f 02/24/2021 07:23 PM Jim Pingle

Correct location and config for Strict CRLs in IPsec. Fixes #11526

(cherry picked from commit 9a5bde87ce9fd0fad3a7f41750782b2dccce38d8)

3987c45b 02/23/2021 10:04 PM Jim Pingle

Improve CA/Self-Signed serial handling. Fixes #11514

(cherry picked from commit 4aa7c7aefc273464b8e66e6176a860b0246f8ee9)

16c1d390 02/23/2021 09:25 PM Jim Pingle

Try parsing four digit years in cert timestamps. Fixes #11504

(cherry picked from commit bdaa35dcf31def521ba8c60c0aa9c41bf5005311)

cb17faca 02/23/2021 07:22 PM Jim Pingle

Improve handling of broken/invalid certs. Fixes #11489

(cherry picked from commit 29804b9e6ff07d0224d9396b063f88f486f0d231)

a97987a5 02/21/2021 02:28 PM Viktor Gurov

Non local gateways fix. Issue #11433

(cherry picked from commit 087d28fa3f5cfebfd4af7f4a4479b0fac053e062)

2fe5cc52 02/20/2021 10:28 PM Jim Pingle

Don't add empty pools line. Fixes #11488

(cherry picked from commit bb3a6eb44958841df4257ae7936e6714d1ed99a8)

afffe759 02/20/2021 10:20 PM Jim Pingle

Fix child SA name generation. Fixes #11487

(cherry picked from commit eb5bd64face47422285cb883ad44fc5d77c361fa)

585e7567 02/19/2021 07:37 PM Steve Beaver

Fix alias renaming issue

10eb0425 02/18/2021 04:00 PM Jim Pingle

Do not prefix FQDN IPsec IDs with @. Fixes #11442

(cherry picked from commit c09137ab4726dc492c658c27b6c46e25f0fbb55b)

9d08d4bf 02/18/2021 04:00 PM Jim Pingle

Fix custom XMLRPC port for Captive Portal. Fixes #11425

(cherry picked from commit fef846ce7ec4158a140f359b0fb35182f6ae9db9)

6fb4b1b0 02/16/2021 01:22 PM Renato Botelho

Welcome pfSense 2.5.0-RELEASE

5e9b5483 02/12/2021 01:51 PM Jim Pingle

Fix WireGuard add/next name behavior. Fixes #11407

  • No need to set index when creating a new entry
  • WireGuard interface name label was assuming array index=wg if name
    which was incorrect

(cherry picked from commit 11fd7da72502c991b1f1c0e886ea212235f4a505)

1bc20f0d 02/11/2021 08:27 PM Steve Beaver

Handle case where copyright file is downloaded but has a size of zero

a57003ef 02/10/2021 03:28 PM Steve Beaver

Fix Microsoft's idea of an apostropphe

b6ed7d8b 02/10/2021 12:58 PM Steve Beaver

Increment requested copyright version

e5b9b569 02/10/2021 01:52 AM Steve Beaver

Revise copyright modal to accommodate larger content

098bf8e9 02/09/2021 06:53 PM Jim Pingle

Use Netgate domain for bogons. Issue NG 5446

(cherry picked from commit 4a30c608aacdcb8a467e97d9ccda514e412731bf)

67947a5f 02/09/2021 05:01 PM Renato Botelho

Detect Plus by product label

98528dce 02/09/2021 04:54 PM Renato Botelho

Rename Factory -> Plus

c33ebcbc 02/09/2021 04:15 PM Jim Pingle

This file moved, remove old copy. Fixes #11389

(cherry picked from commit 860391bfcb5d273daef32780003014cfdd557a6d)

83081d3a 02/08/2021 07:04 PM Steve Beaver

Revert "Refactor system_advanced_misc for MVC"

This reverts commit c33b0ab6c2fcd4c9786d1b5e7903c01fa1fafa7d.

5898a649 02/08/2021 06:07 PM Steve Beaver

Refactor system_advanced_misc for MVC

66933ee4 02/08/2021 06:01 PM Steve Beaver

Typo

d1216ae0 02/08/2021 05:54 PM Steve Beaver

Add registered trdemark symbol where appropriate

d6b55b5f 02/08/2021 01:23 PM Viktor Gurov

Nested alias checking fix. Issue #11372

4f630b14 02/08/2021 01:22 PM Viktor Gurov

Return correct Track IPv6 address if >1 VIP on interface. Issue #5999

3537f4a8 02/05/2021 11:39 AM Renato Botelho

Welcome 2.5.0-RC

21c2bb34 02/04/2021 06:13 PM Renato Botelho

Remove what I suspect is a debug leftover

93830bec 02/04/2021 03:12 PM Viktor Gurov

OpenVPN rmdir fix. Issue #11254

3673b6d0 02/04/2021 11:30 AM Renato Botelho

Style fixes

2d51537f 02/02/2021 01:48 PM Viktor Gurov

Captive Portal custom logo fix. Issue #11360

86b28a02 02/01/2021 04:11 PM Steve Beaver

Refactored system_advanced_* pages for MVC

90749e06 02/01/2021 02:14 PM Viktor Gurov

Issue #11340
Hide WireGuard interfaces on DHCP/DHCPv6 Relay pages,
Hide mediaopt field for WireGuard interfaces on interfaces.php page

f32e1438 01/29/2021 06:54 PM Jim Pingle

Add brackets around IPv6 endpoint address. Issue #11338

9985ed7f 01/28/2021 03:43 PM Viktor Gurov

Gateway Group Policy rule creation fix. Issue #11298

79ec3f15 01/28/2021 03:42 PM Viktor Gurov

Delete all OpenVPN related files on instance deletion. Issue #11254

c66b71c8 01/28/2021 02:58 PM Renato Botelho

Mute console before load crypto modules

0c68239a 01/27/2021 05:06 PM Jim Pingle

Fix WireGuard interface name assignment. Fixes #11323

Only set the name when it's empty/unset (e.g. when first created),
automatically determine the next available wg interface number.

4fdcc82b 01/27/2021 04:22 PM Jim Pingle

WireGuard: Always derive public key. Issue #11322

If the user enters a different private key, using the supplied public
key would lead to a mismatch. So always derive the public key when saving.

2ccdb454 01/27/2021 04:11 PM Jim Pingle

WireGuard: Make pubkey read only, populate automatically. Fixes #11322

While here, add a link to copy the public key to the clipboard.

0a0ef335 01/26/2021 02:36 PM Jim Pingle

Improve WireGuard port validation. Fixes #11311

b505e3ae 01/26/2021 01:37 PM Jim Pingle

Suppress errors when opening router file. Fixes #11314

ed837d48 01/25/2021 09:05 PM Jim Pingle

Attempt to use peer wg address if possible for gateway. Implements #11300

0c3fff67 01/25/2021 04:02 PM Jim Pingle

Refine Unbound auto ACL generation. Implements #11309

7fe0979b 01/25/2021 03:28 PM Jim Pingle

Rework WireGuard tonatsubnets/unbound ACL entries. Fixes #11304

2924fc26 01/25/2021 02:14 PM Jim Pingle

Init var before use. Fixes #11307

f25efb4b 01/25/2021 01:41 PM Steve Beaver

Allowe peer port < 512

94230d38 01/25/2021 01:40 PM Steve Beaver

Allowe listen port < 512

8b9d2275 01/25/2021 01:33 PM Jim Pingle

Use correct default MTU for WireGuard. Fixes #11291

e1afb219 01/22/2021 06:23 PM Jim Pingle

Add WireGuard to easyrule

bc8cf86b 01/22/2021 05:40 PM Jim Pingle

Exclude wg(4) from auto outbound NAT. Fixes #11289

df799f2c 01/22/2021 03:24 PM Jim Pingle

Assume default WG port if empty. Fixes #11286

171b0eb2 01/22/2021 01:15 PM Jim Pingle

Revert "Add wg to ALTQ list. Implements #11280"

Unstable. See #11285

This reverts commit 4a49b0d9b182c76f658201124c43278a65542c98.

8dffba30 01/21/2021 09:57 PM Jim Pingle

Fix WireGuard case

5a33a16c 01/21/2021 09:55 PM Jim Pingle

Ticket #5186: Enable Wireguard firewall rules tab

4a49b0d9 01/21/2021 09:31 PM Jim Pingle

Add wg to ALTQ list. Implements #11280

db2fefc5 01/21/2021 08:57 PM Jim Pingle

Show WireGuard interface description during assignment. Issue #11277

f50c6543 01/21/2021 07:55 PM Jim Pingle

WireGuard assignment/disable behavior improvements. NG 5518

  • Do not allow a WireGuard instance to be removed while assigned
  • Do not allow a WireGuard instance to be disabled while assigned
  • Destroy the WireGuard interface when disabled
e564dbd6 01/21/2021 12:18 AM Steve Beaver

Add ^wg to list of interface mimatch types

8e48b2e2 01/20/2021 08:27 PM Jim Pingle

Add OS routes using WireGuard Peer AllowedIPs. Part of NG 5437

45ae5c55 01/20/2021 07:50 PM Jim Pingle

Remove WireGuard peernwks field which is not needed. Part of NG 5437

6e23ca79 01/20/2021 07:43 PM Jim Pingle

Fix some bad WireGuard capitalization

236f8ecc 01/20/2021 07:39 PM Jim Pingle

Automatic WireGuard interface gateways. Part of NG 5437

3856366b 01/20/2021 05:27 PM Renato Botelho

Retire VXLAN support

VXLAN support is not enterprise ready and after internal discussion we
decided we are not able to support it. We are committed to release
features only when they are ready.

55da9aef 01/20/2021 01:44 PM Jim Pingle

Change XML listtag entry for peer to wgpeer for issue #5186

ef0b6170 01/19/2021 08:05 PM Renato Botelho

Fix copyright notices

b386d073 01/19/2021 08:05 PM Renato Botelho

Remove commented out code

1566a360 01/19/2021 08:05 PM Renato Botelho

Spell WireGuard properly

6facda79 01/19/2021 02:35 PM Jim Pingle

Add igc to ALTQ list. Issue NG 5185

c9706433 01/19/2021 02:35 PM Renato Botelho

Preserve wireguard address after interface assign

4efe99c6 01/19/2021 02:35 PM Renato Botelho

Improve code readability

c3acf286 01/19/2021 02:35 PM Steve Beaver

Fixed #5486 by making peer endpoint and port optional

422f8a04 01/19/2021 02:35 PM Steve Beaver

Added new Wireguard config fields peernwks and peerwgaddr per #5437

282d8ee7 01/19/2021 02:35 PM Renato Botelho

wg: Configure static routes

When configuring a wg tunnel, update static routes associated with that
interface

d1ac0394 01/19/2021 02:35 PM Renato Botelho

Update copyright year

39a615f0 01/19/2021 02:35 PM Renato Botelho

Ticket #5186: Re-create config files during boot

580c7a4f 01/19/2021 02:35 PM Renato Botelho

Ticket #5186: Implement is_wg_enabled()

07aa50fd 01/19/2021 02:35 PM Renato Botelho

Ticket #5186: Fix comment

aea837f8 01/19/2021 02:35 PM Steve Beaver

#5186 - Revised peer configuration to use 'wgpeer' rather than 'peer'

a0669cfb 01/19/2021 02:35 PM Renato Botelho

wg: Do not check assigned interface (Ticket #5186)

When saving changes on wireguard, do not check address conflict on
interface assigned to that tunnel, otherwise, it will not allow user to
save any modification

97e391de 01/19/2021 02:35 PM Renato Botelho

wg: Use a more generic function to detect IP address

835e6895 01/19/2021 02:35 PM Renato Botelho

wg: Remove extra spaces

50bd4119 01/19/2021 02:35 PM Renato Botelho

wg: isset() just before is_array() is redundant

d763c52b 01/19/2021 02:35 PM Renato Botelho

wg: unlink_if_exists() can deal with glob matches