Project

General

Profile

Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
e804230c 11/10/2021 12:11 AM Brad Davis

Add a ZFS reservation of 10%

d1e65bb2 11/04/2021 03:06 PM Viktor Gurov

Automatic outbound NAT for Reflection IPv6 support. Fixes #12500

b3979f4a 11/02/2021 01:16 PM Viktor Gurov

Add Chelsio T6 CXGBE (cc) to ALTq capable list. Fixes #12499

4d016cc4 10/28/2021 08:59 AM Kristof Provost

Do not detach ng_ether from physical interfaces

There's no measurable performance impact1 of leaving an unused ng_ether
node attached to ethernet interfaces, so don't waste time trying to
ensure we only attach to interfaces where we expect to use netgraph....

66b1de4c 10/27/2021 08:46 PM Jim Pingle

IPsec SPD status updates. Implements #12397

  • Fix backend parsing of setkey data
  • Check for VTI vs tunnel mode
  • Output mode in GUI status, and VTI interface name if available
  • Make directionality of endpoints and arrow icon match in both the
    direction column and tunnel endpoints column.
c7a78ad6 10/22/2021 08:24 PM Viktor Gurov

Elliptic Curve 25519, 448 bit -> Elliptic Curve 448, 448 bit PH2 rename. Fixes #12350

a96a7151 10/21/2021 03:11 PM Viktor Gurov

Delete stale OpenVPN RADIUS ACL generated rules. Fixes #12481

aa1936ee 10/21/2021 01:27 PM Viktor Gurov

DNS check optimization for NDP diag page. Fixes #11512

6e889d88 10/20/2021 04:11 PM Viktor Gurov

Fix OpenVPN status page halt function when client_id=0. Issue #12416

2c702751 10/20/2021 04:05 PM Viktor Gurov

IPsec PC/SC daemon status / services page fix. Issue #12468

0b783d30 10/20/2021 01:50 PM Viktor Gurov

Remove stale captiveportal_online_users file on boot. Fixes #12455

4738f308 10/19/2021 08:32 AM Viktor Gurov

Send reboot/reroot/halt notification. Implements #12441

dc883862 10/18/2021 03:14 PM Viktor Gurov

Reset CP DB on unclean shutdown if preservedb option is not enabled. Fixes #12355

661c23ea 10/18/2021 03:13 PM Viktor Gurov

GRE/GIF interface configure fix. Issue #12288

322ac50f 10/18/2021 03:13 PM Viktor Gurov

Elliptic Curve 25519, 448 bit -> Elliptic Curve 448, 448 bit rename. Fixes #12350

aabaad0a 10/18/2021 03:12 PM Viktor Gurov

Mute kernel messages on dummynet and thermal hardware modules load. Fixes #12454

67fedb90 10/17/2021 05:50 AM Viktor Gurov

Use proxy for DDNS Check IP Services. Feature #12342

fd331bdc 10/13/2021 05:46 AM Viktor Gurov

Dynamic DNS proxy option. Fixes #12342

b9fbc36a 10/13/2021 05:13 AM Viktor Gurov

Slack Notifications. Feature #12291

59724429 10/09/2021 07:35 AM Viktor Gurov

Do not check subnet overlapping on 6RD interfaces. Fixes #12371

e33311fe 10/08/2021 03:50 PM Viktor Gurov

DNS check optimization. Fixes #11512

1ab2ec0a 10/08/2021 03:49 PM Viktor Gurov

IPv6 Port Forwarding Proxy+NAT input validation. Fixes #12319

b5332117 10/08/2021 03:36 PM Marcos M

Improve XMLRPC Sync for dhcpd. Fixes #10955

08ef78ac 10/08/2021 03:35 PM Viktor Gurov

Allow to halt OpenVPN client on status page. Issue #12416

ed1ff340 10/08/2021 03:34 PM Viktor Gurov

Do not show Configuring IPsec VTI interfaces message at boot if no VTIs are configured. Fixes #12419.

79b8b049 10/08/2021 03:30 PM Viktor Gurov

Remove unused function from pfsense-utils.inc. Todo #12406

0512975e 09/22/2021 12:39 PM Christian McDonald

Fixes redmine #12396

b9885720 09/20/2021 04:17 PM Luiz Souza

Bump up the config version to match a change in plus.

8e2de557 09/20/2021 12:29 AM Luiz Souza

Keep 'enableserial_force' in /conf when a factory reset is performed.

Ticket: #6880

8558539a 09/10/2021 03:57 PM Viktor Gurov

Do not restart IPsec on every gateway alarm. Fixes #12039

dbe51a34 09/10/2021 03:50 PM Marcos M

additional fix #7801 Include IPsec P2 address type in vpn_networks

454cfb43 09/10/2021 02:12 PM Christian McDonald

Fix disk widget upgrade script assuming widgets always have an index

2de8b1f5 09/09/2021 11:08 PM Christian McDonald
  • Removes disk usage from system information widget
  • Adds Pfsense\Services\Filesystem\ library
  • Adds new disk widget
9dac41af 09/09/2021 03:08 PM Kristof Provost

captiveportal: fix ipfw rules

When we authorise a client we add it to the *auth(up|down) tables.
This means traffic will pass and not be forwarded, as piped traffic does
not pass through the firewall again (if net.inet.ip.fw.one_pass is set).

However, these rules are 'layer2', so when the traffic is passed it's...

7e0da288 09/09/2021 03:01 PM Christian McDonald

Initial commit of useful dependencies provided by Composer

5d0c974d 09/08/2021 01:53 PM Jim Pingle

Make ssh PermitRootLogin conditional. Fixes #12346

dd155b32 09/08/2021 11:19 AM Viktor Gurov

IPsec Widget none/disabled tunnels fixes. Issue #12337

f7e2e6e1 09/03/2021 04:42 PM Viktor Gurov

Yandex PDD DDNS token fix. Issue #12331

0ec0b654 09/03/2021 02:00 PM Jim Pingle

Add boot msgs for final IPsec steps. Issue #12328

e9705a77 09/02/2021 06:46 PM Jim Pingle

Use correct var f/OpenVPN IPv6 ACL. Fixes #12333

Fix variable name when referencing an OpenVPN IPv6 tunnel network while
creating a DNS Resolver ACL entry.

While here, also add a safety check to ensure we never attempt to add an
ACL with an empty address.

f8b02f65 09/02/2021 06:04 PM Luiz Souza

Fix the option 4 in menu, factory reset.

7f0d57f4 09/02/2021 12:12 PM Jim Pingle

Correctly resolve VTI remote addr. Fixes #12328

Use ipsec_get_phase1_dst() to resolve an IPsec P1 remote gateway
address rather than passing an FQDN directly to ifconfig

d582c5be 09/01/2021 01:31 PM Viktor Gurov

IPsec PH2 AH proposals order fix. Issue #12323

0a70f90a 08/31/2021 06:03 PM Jim Pingle

OpenVPN exit notify & inactive incompatibilities

  • Ignore exit notify in problematic cases. Fixes #12102
  • Ignore inactive seconds in problematic cases. Fixes #12219
  • Warn against using these options in problematic scenarios
  • Hide from the GUI in obvious incompatible scenarios
83314732 08/31/2021 02:09 PM Viktor Gurov

Cleanup and improve easyrule. Fixes #12151

4b8d710c 08/30/2021 09:02 PM Viktor Gurov

OpenVPN Aliases support. Implements #2668

336103c4 08/30/2021 06:19 PM Jim Pingle

Consider GWG in ipsec_force_reload. Fixes #12315

1394773d 08/27/2021 09:53 PM Luiz Souza

Rename a few missing Netgate devices.

Super Micro XG-1537 -> Super Micro 1537
Super Micro XG-1541 -> Super Micro 1541

2c393b55 08/27/2021 12:49 PM Jim Pingle

Add null check. Fixes #9092

If the value is undefined in config.xml this will be null, not an empty
string.

0ef2ff26 08/26/2021 03:38 PM Luiz Souza

Fix a typo in the Netgate 5100 name.

df945787 08/26/2021 03:21 PM Luiz Souza

Rename the Netgate devices.

XG-15xx -> 15xx
SG-5100 -> Netgate-5100

fe72327b 08/26/2021 01:03 PM Jim Pingle

Revert "Clean up some messy HTML in the cert/ca display code. Prep for future MVC changes."

This reverts commit 8d4fcd7ac1167894136e337fc619e63fa7200fa0.

7628b091 08/24/2021 01:33 PM Jim Pingle

Increase default RA intervals. Fixes #12280

a1eef308 08/24/2021 01:24 PM Jim Pingle

Increase default RA intervals. Fixes #12280

This code path was not included in the original diff.

99dfecb7 08/24/2021 01:12 PM Renato Botelho

radvd: Avoid empty AdvDNSSLLifetime (Fixes #12173)

Make sure $raadvdnsslifetime is defined on second foreach

dd8d9e23 08/23/2021 07:36 PM Jim Pingle

Disable newsyslog compression w/ZFS. Issue #12011

ZFS compresses /var/log by default. If the ZFS dataset /var/log has
compression enabled on the first boot post install or factory reset,
then set a flag to disable newsyslog compression unless the user
overrides the setting in the configuration....

953aba88 08/23/2021 01:52 PM Jim Pingle

Don't wait on manual IPsec actions. Fixes #12298

Use a timeout with swanctl --initiate, and use --force for swanctl
--terminate. This will allow the commands to succeed and return without
waiting on the remote to respond. The negotiation continues in the...

583062bf 08/20/2021 04:06 PM Viktor Gurov

IPv6 fix for setdefaultgateway(). Issue #12282

3ff300c6 08/20/2021 02:11 PM Jim Pingle

Change /var/run to tmpfs. Implements #12145

f873a4ef 08/20/2021 02:01 PM Jim Pingle

Update IPsec Filter Mode text. Implements #12289

VTI mode also works for transport mode (e.g. GRE), so note that as well.

762d3cc9 08/20/2021 05:20 AM Viktor Gurov

Increase default IPv6 router advertisement (RA) intervals and lifetime. Fixes #12280

d566427f 08/19/2021 06:59 PM Jim Pingle

Convert RAM disks to tmpfs. Implements #12145

923399be 08/19/2021 05:14 AM Viktor Gurov

Allow to use nested URL alias in URL alias. Fixes #11863

cf757a80 08/18/2021 08:11 PM Jim Pingle

Regex cleanup should also kill {}. Fixes #12257

It's not used often (and less in the GUI) and can be a source of
problems with large numbers of repetitions even outside of grouped
expressions.

a38556ff 08/18/2021 04:12 PM Jim Pingle

Use SHA512 to hash user password. Implements #10298

Original commit by Viktor Gurov

7be7d84e 08/18/2021 01:58 PM Jim Pingle

Ensure Unbound python script exists. Fixes #12274

Check to make sure a referenced python script exsits before attempting
to use it in the Unbound configuration. If the file does not exist,
Unbound will fail to start.

bca881c4 08/17/2021 01:12 PM Jim Pingle

Correct grep usage where needed. Fixes #12265

8cd3f92f 08/17/2021 01:11 PM Jim Pingle

Regex cleanup change. Fixes #12257

Rather than attempting to cleanup group repetition, just discard the
unwanted pattern.

3a0f6f36 08/17/2021 06:07 AM Viktor G

Move IPsec Mobile additional configuration attributes to strongswan.conf. Fixes #11447

4f04c78e 08/17/2021 06:05 AM Viktor Gurov

Fix IPsec PH1 with Remote Gateway 0.0.0.0 rules creation. Issue #12262

d57eab57 08/17/2021 06:05 AM Viktor G

VLAN/QinQ-only interface mismatch detection. Fixes #12170

57a737f1 08/16/2021 05:42 PM Jim Pingle

More route display changes. Fixes #12257

  • Move escape_filter_regex() from syslog.inc to util.inc since it will
    be used by things other than syslog.
  • Add some basic regex sanity and consistency check functions
  • Cleanup diag_routes.php route filter before use...
c5bda432 08/14/2021 05:33 AM Viktor G

Do not delete disabled routes. Fixes #10706

2e6b2841 08/14/2021 05:33 AM Viktor Gurov

Prevent deletion of OpenVPN instances with assigned interfaces. Fixes #12224

6514012d 08/14/2021 05:33 AM Viktor Gurov

Reconfigure stacked IP Aliases on parent CARP VIP changes. Fixes #12227

0997d828 08/13/2021 12:49 PM Viktor Gurov

Display Gateway IPv6 on status_interfaces.php regardless of Gateway IPv4 status. Fixes #12253

37c677a1 08/13/2021 12:49 PM Viktor Gurov

Fix is_hostname() regression. Issue #12245

36abc2ad 08/13/2021 08:35 AM Viktor G

Update convert_friendly_interface_to_friendly_descr() to show IP Alias description. Fixes #11337

d1d8383c 08/13/2021 08:11 AM Viktor Gurov

Use client-connect/client-disconnect script for Remote Access (SSL/TLS) server mode. Fixes #12238

5ed5f14d 08/13/2021 08:11 AM Viktor G

Set $retries=10 in resolve_retry() to improve resolution timeout. Fixes #12196

0f441291 08/13/2021 08:10 AM Viktor G

1:1 NAT rules creation update. Fixes #12168

  • Fix 1:1 NAT rule creation when Any is selected for Internal IP
  • Fix 1:1 NAT rule creation when Any is selected for Internal IP on 6RD/6to4 interface
c7599055 08/13/2021 05:46 AM Viktor Gurov

Parse ARM 32/64 network boot options on Static DHCP Mapping page. Fixes #12216

126f555e 08/13/2021 05:45 AM Viktor G

Do not create disabled IPsec VTI interfaces. Fixes #12212

96270d7c 08/13/2021 05:38 AM Viktor G

Router Advertisements fixes. Issue #12173

  • Set AdvDNSSLLifetime value to 3*MaxRtrAdvInterval per RFC 8106
  • Provide DNS configuration via radvd checkbox fix
d1150a0c 08/13/2021 05:37 AM Viktor G

Write CRL files only if certificate authentication is used in IPsec. Fixes #12195

013cbaaa 08/11/2021 05:32 AM Viktor G

Hide pcscd service from the service list if IPsec PKCS11 support is disabled. Todo #11933

1d7ae980 08/11/2021 05:26 AM Viktor G

NTP Server SHA256 authentification support. Implements #12213

1c334904 08/11/2021 05:26 AM Viktor G

Delete OpenVPN related config files for disabled instance. Fixes #12223

cf40cd17 08/11/2021 05:18 AM Viktor G

Support for UEFI HTTP Boot option in DHCP config. Implements #11659

647cf03a 08/11/2021 05:16 AM Viktor Gurov

Wireless Channel/Width Issues fix. Issue #12234

8d4fcd7a 08/10/2021 06:37 PM Steve Beaver

Clean up some messy HTML in the cert/ca display code. Prep for future MVC changes.

a6296852 08/10/2021 02:00 PM Renato Botelho

Merge pull request #4512 from jvandervyver/master

7f0ad465 08/10/2021 02:00 PM Renato Botelho

Merge pull request #4530 from Alexilmarranen/master

07fbed96 08/10/2021 02:00 PM Renato Botelho

Merge pull request #4534 from Uglymotha/master

6c3bfb73 08/09/2021 02:15 PM Jim Pingle

OpenVPN status f/tap+empty tunnel net Fixes #12232

fbf4a07f 08/07/2021 02:41 PM Jim Pingle

Correct syntax. Fixes #12229

0d3747aa 08/06/2021 03:40 PM Jim Pingle

Improve NTP serial port validation. Fixes #12191

868c1a67 08/05/2021 10:05 PM Steve Beaver

Init [''system']['acb']

dafe25ea 08/04/2021 05:29 PM Steve Beaver

Ensure ACB config section exists

1dd1832f 08/04/2021 05:25 PM Steve Beaver

Install ACB cron job on upgrade