Activity
From 08/14/2025 to 09/12/2025
09/11/2025
-
05:07 PM pfSense Packages Feature #16424 (New): Missing CVE fixes for pfsense supplied Suricata binary
- PfSense supplied suricata binary 7.0.8 is now 3 versions behind current 7.0.11. Why isn't the pfsense supplied versio...
-
03:05 PM pfSense Revision c1d6a3b2: Update the bind parameter after src commit 9ba51cce8bbd
-
03:42 AM pfSense Feature #16423 (New): Enable Post Quantum Crypto Support in SSH Server
- The SSH server in 25.07.1 uses OpenSSH_9.7p1 which natively supports one PQC (post quantum crypto) key exchange algor...
09/10/2025
-
09:33 PM pfSense Revision 36270ba7: Fix typo with generating the IPv6 interface using 6rd
-
05:51 PM pfSense Revision 6c744fef: Add missing include when deleting assigned interface
- "firewall_nat.inc" is needed for remove_rdr_rules().
-
03:53 PM pfSense Docs Todo #16017 (Resolved): Update AutoConfigBackup docs to account for new changes
-
03:52 PM pfSense Docs Todo #16408 (Closed): Add workaround for EFI boot issue
- Added
-
03:45 PM pfSense Docs Todo #16408 (In Progress): Add workaround for EFI boot issue
-
03:18 PM pfSense Bug #16422: DNS Resolver không phản hồi ổn định qua CARP VIP sau nâng cấp lên pfSense 2.8.1
- After upgrading from pfSense CE 2.8.0 to 2.8.1, the system encountered unstable DNS response issues via the CARP VIP....
-
12:57 PM pfSense Bug #16422 (Not a Bug): DNS Resolver không phản hồi ổn định qua CARP VIP sau nâng cấp lên pfSense 2.8.1
- We can only take issue reports in English but running that through a translator it appears likely your problem is rel...
-
12:41 PM pfSense Bug #16422 (Not a Bug): DNS Resolver không phản hồi ổn định qua CARP VIP sau nâng cấp lên pfSense 2.8.1
- Sau khi nâng cấp từ pfSense CE 2.8.0 lên 2.8.1, hệ thống gặp lỗi DNS không phản hồi ổn định qua CARP VIP. Khi dùng VI...
-
01:54 PM pfSense Feature #6742: OAuth2 authentication for OpenVPN (and for FreeRadius)
- Please add support for use case A
-
01:41 PM pfSense Feature #6742: OAuth2 authentication for OpenVPN (and for FreeRadius)
- +1 for use-case A
09/09/2025
-
06:33 PM pfSense Regression #16421 (New): OpenVPN servers will not start with DH parameters < 2048
- On current Plus 25.11 and CE 2.9.0 snapshots, OpenVPN servers will not start if they have a DH parameter size of @102...
-
06:20 PM pfSense Bug #16419: Kea DHCP and Boost-libs version mismatch: boost-libs-1.86.0 not available for installation on pfSense 2.8.1
- I confirm that this is not a bug.
I have identified that the boost-libs package and several other packages remained... -
05:55 PM pfSense Plus Bug #16080: Issues Upgrading from 24.03 to 24.11 SG-1100 Atheros 9280
- !clipboard-202509091255-sctdf.png!
!clipboard-202509091255-dxfb2.png!
!clipboard-202509091255-yv508.png!
-
04:50 PM pfSense Packages Bug #16414: Multiple potential vulnerabilities in the Suricata package
- New package build is now published and available for Plus 25.07.1, Plus 25.07, CE 2.8.1, and CE 2.8.0.
-
03:45 PM pfSense Packages Bug #16414 (Resolved): Multiple potential vulnerabilities in the Suricata package
- MR Merged
-
04:50 PM pfSense Packages Bug #16413: Potential stored XSS in the Status_Traffic_Totals package
- New package build is now published and available for Plus 25.07.1, Plus 25.07, CE 2.8.1, and CE 2.8.0.
-
03:44 PM pfSense Packages Bug #16413 (Resolved): Potential stored XSS in the Status_Traffic_Totals package
- MR Merged
-
04:50 PM pfSense Packages Bug #16412: Potential file enumeration vulnerability in the Snort package via IP reputation lists
- New package build is now published and available for Plus 25.07.1, Plus 25.07, CE 2.8.1, and CE 2.8.0.
-
03:44 PM pfSense Packages Bug #16412 (Resolved): Potential file enumeration vulnerability in the Snort package via IP reputation lists
- MR Merged
-
04:49 PM pfSense Packages Bug #16411: Potential XSS in HAProxy Package
- New package build is now published and available for Plus 25.07.1, Plus 25.07, CE 2.8.1, and CE 2.8.0.
-
03:44 PM pfSense Packages Bug #16411 (Resolved): Potential XSS in HAProxy Package
- MR Merged
-
03:51 AM pfSense Feature #16420 (Pull Request Review): Update Simplified Chinese (zh_CN) translation
- Note:
Since this project does not have an issue tracker, I cannot submit an issue directly. Currently, there are d...
09/08/2025
-
06:19 PM pfSense Packages Bug #16416 (Rejected): It's possible to add DNSBL Virtual IP with subnet mask if to use Restore Configuration option in Diagnostics -> Backup&Restore
- It sounds like config.xml was modified manually. That's not supported and should only be done when you know exactly w...
-
05:55 PM pfSense Bug #16409 (Not a Bug): if_pppoe not writing to /var/log/ppp.log
- That log is only for mpd5. You can see some logs for the kernel module in the system logs but there's not much by def...
-
05:36 PM pfSense Revision 40f9d5a3: Alert user about NAT64 rules changes from config upgrade
-
05:12 PM pfSense Packages Bug #16361 (Closed): Update mDNS-Bridge to 2.1
-
05:08 PM pfSense Packages Bug #16361: Update mDNS-Bridge to 2.1
- This is superseded by #16399 and may be closed.
-
12:52 PM pfSense Bug #16419 (Rejected): Kea DHCP and Boost-libs version mismatch: boost-libs-1.86.0 not available for installation on pfSense 2.8.1
- Something is wrong with your installation/hardware or it's somehow looking at the wrong repository. If that one packa...
-
12:30 PM pfSense Bug #16419 (Rejected): Kea DHCP and Boost-libs version mismatch: boost-libs-1.86.0 not available for installation on pfSense 2.8.1
- Hello,
After upgrading to pfSense 2.8.1, I am unable to use Kea DHCP (version 2.6.2) because it requires boost-lib... -
12:41 PM pfSense Docs Todo #16417 (Rejected): Feedback on Packages — ACME package — ACME Package Settings — Validation Methods
- I have multiple ACME certs using the Namecheap validation method and none require that. Any method could require that...
-
12:38 PM pfSense Plus Feature #16395 (Rejected): Block device by name (with random mac-adress)
- arping just uses DNS to find addresses. You can already block by hostname by placing the hostname in an alias. There ...
-
12:34 PM pfSense Bug #16415 (Not a Bug): Switching from DHCP to Static on a WAN leaves WAN_DHCP gateway present and shows as default route
- If a user has never edited the WAN_DHCP gateway, it's purely dynamic and will go away on its own when switching away....
-
10:55 AM pfSense Packages Bug #16418 (New): The Arping package is sensitive to spaces in the target IP address or MAC.
- Tested on Arping 1.2.2_6
25.07.1-RELEASE (amd64)
built on Wed Aug 20 16:17:00 +04 2025
FreeBSD 15.0-CURRENT
If yo... -
10:32 AM pfSense Feature #15952: User Auth RADIUS Client Secure Protocols
- Hi Jim. Looks like this radius client implementation supports the required attribute - https://codeberg.org/fkooman/p...
09/07/2025
-
06:18 PM pfSense Docs Todo #16417 (Rejected): Feedback on Packages — ACME package — ACME Package Settings — Validation Methods
- *Page:* https://docs.netgate.com/pfsense/en/latest/packages/acme/settings-validation.html
*Feedback:* It would be ... -
03:20 PM pfSense Plus Bug #15036: Traffic Shaper Wizard Dedicated generates error
- Retested on 25.07.1 and on 25.11-DEV (built on Sun Sep 7 6:00:00 UTC 2025)
This issue hasn't been fixed. I still g... -
03:09 PM pfSense Bug #13723: dpinger doesn't renew Gateway Monitoring IP address for IPsec VTi after changing IPsec VTi subnet
- Tested on 25.07.1 and on 25.11-DEV (built on Sun Sep 7 6:00:00 UTC 2025)
This issue hasn't been fixed for both pfS... -
12:47 PM pfSense Packages Bug #16416 (Rejected): It's possible to add DNSBL Virtual IP with subnet mask if to use Restore Configuration option in Diagnostics -> Backup&Restore
- Tested on 25.07.1 (pfBlockerNG 3.2.7)
If to use incorrect DNSBL Virtual IP in config.xml file ('DNSBL VIP with sub... -
08:47 AM pfSense Bug #16406: No logfile for captive portal auth
- Hi Kris,
just upgraded two systems from 2.8.0 to 2.8.1: Same result, no captive portal authentication logs ... see... -
01:54 AM pfSense Bug #16406 (Incomplete): No logfile for captive portal auth
- Testing this on 2.8.1. I'm unable to recreate this bug report. When connecting, I get an authentication message, as...
-
02:15 AM pfSense Bug #16415 (Not a Bug): Switching from DHCP to Static on a WAN leaves WAN_DHCP gateway present and shows as default route
- When changing from DHCP to Static on a WAN interface, the WAN_DHCP gateway remains.
This causes both the new sta... -
02:06 AM pfSense Bug #15759 (Resolved): CVE-2024-43102 umtx Kernel panic or Use-After-Free
- Closing this out, as we've been on FreeBSD 15 for a while, which is unaffected by this CVE.
Closing as Resolved. -
02:05 AM pfSense Bug #13276 (Confirmed): IGMP Proxy Error Message for Logging Links to System Log Instead of Routing Log
-
02:04 AM pfSense Bug #13276: IGMP Proxy Error Message for Logging Links to System Log Instead of Routing Log
- Tested on 25.07.1 and 2.8.1 of Plus and CE. This issue is still present in both versions and links to the wrong log ...
-
01:59 AM pfSense Plus Feature #16395 (New): Block device by name (with random mac-adress)
- If pfSense doesn't handle DHCP and DNS for a network, it may be hard to determine a hostname/FQDN for the endpoint, s...
-
01:55 AM pfSense Feature #16404 (Confirmed): Option to choose update branch from the console menu
- I can confirm this is an issue that would helpfully be resolved by adding a console menu option.
This is especia... -
12:03 AM pfSense Plus Regression #16381: EFI loader fails to boot on some devices
- Confirmed that UEFI booting works on 25.07.1 when manually using the loader from 24.11.
09/06/2025
-
06:53 PM pfSense Plus Regression #16407 (Confirmed): Editing Alias assigned to Static Route doesn't update routing table
- I also see this behavior on...
-
12:55 PM pfSense Packages Bug #16399 (Feedback): Update mDNS-Bridge to 2.2
- Merged.
09/05/2025
-
10:55 PM pfSense Plus Regression #16381: EFI loader fails to boot on some devices
- Another customer hitting this on an HP DL380 Gen10 with 25.07.1. In his case, he is also not able to boot from BIOS m...
-
08:49 PM pfSense Revision 04026a29: Improve generating the 6rd prefix for OpenVPN by using the configured interface instead of hardcoding the WAN
-
07:04 PM pfSense Packages Bug #16414 (Resolved): Multiple potential vulnerabilities in the Suricata package
- There are multiple potential vulnerabilities in the Suricata package:
Reflected cross-site scripting: In @/usr/loc... -
06:58 PM pfSense Packages Bug #16413 (Resolved): Potential stored XSS in the Status_Traffic_Totals package
- There is a potential stored cross-site scripting vulnerability in the Status_Traffic_Totals package:
In @/usr/loca... -
06:56 PM pfSense Packages Bug #16412 (Resolved): Potential file enumeration vulnerability in the Snort package via IP reputation lists
- There is a potential file enumeration vulnerability in the Snort package:
In @/usr/local/www/snort/snort_ip_reputa... -
06:53 PM pfSense Packages Bug #16411 (Resolved): Potential XSS in HAProxy Package
- There is a potential reflected cross-site scripting vulnerability in the HAProxy package:
@/usr/local/www/haproxy/... -
02:13 PM pfSense Packages Bug #16410 (Pull Request Review): Arpwatch incorrect subject line
-
12:03 PM pfSense Packages Bug #16410 (Pull Request Review): Arpwatch incorrect subject line
- Arpwatch omits a '.' in the email subject line it sends:...
-
10:33 AM pfSense Bug #16409 (Not a Bug): if_pppoe not writing to /var/log/ppp.log
- When using if_pppoe kernel module activated through GUI option _System/Advanced/Networking/Use if_pppoe kernel module...
-
02:43 AM pfSense Packages Bug #16361: Update mDNS-Bridge to 2.1
- I was able to successfully install, configure and use mDNS-Bridge 2.1 in pfSense+ 25.11.a.20250904.1751
09/04/2025
-
07:23 PM pfSense Docs Todo #16408 (Closed): Add workaround for EFI boot issue
- Ref https://docs.netgate.com/pfsense/en/latest/troubleshooting/boot-issues.html#efi-boot-issues
Some hardware may ... -
06:35 PM pfSense Packages Bug #16301: Telegraf stops service over night
- @balu It's possible that your Telegraf is crashing or restarting on its own, but fails to restart due to Issue #16225
-
12:03 AM pfSense Revision 97f9eb5c: Add support for OpenVPN to track the WAN interface for IPv6 delegations
09/03/2025
-
09:29 PM pfSense Packages Feature #16089: Add packages for Zabbix 7.2 and 7.4 agent and proxy
- @kphillips This issue is 6 months old now, so I'd like to understand what causes delays with releasing updated packag...
-
08:21 PM pfSense Plus Regression #16407 (Confirmed): Editing Alias assigned to Static Route doesn't update routing table
- This issue is similar to this redmine: https://redmine.pfsense.org/issues/7547
In order to test:
1. Create an A... -
05:55 PM pfSense Revision b4a156b6: Move build_ipv6interface_list() to an include file
-
05:55 PM pfSense Revision dde1f557: Move generating the 6rd prefix out to a new function called generate_6rd_prefix()
-
05:55 PM pfSense Bug #16406 (Incomplete): No logfile for captive portal auth
- Hi PFSense-Team!
We run PFSense at around 200 locations and we are using voucher and captive portal intensively. A... -
01:23 PM pfSense Plus Bug #16405: Netgate 6100 fails to reboot if pfSense is installed on external USB drive
- Jim Pingle wrote in #note-1:
> That is not a supported or tested configuration.
>
> You can install an M.2 SSD in... -
01:18 PM pfSense Plus Bug #16405 (Not a Bug): Netgate 6100 fails to reboot if pfSense is installed on external USB drive
- That is not a supported or tested configuration.
You can install an M.2 SSD inside the 6100 if you cannot use the ... -
07:48 AM pfSense Plus Bug #16405 (Not a Bug): Netgate 6100 fails to reboot if pfSense is installed on external USB drive
- Due to issues with MMC, I had to install pfSense Plus to an external USB NVME drive on Netgate 6100.
Reboot worked f... -
02:17 AM pfSense Packages Feature #16070: Add ANDwatch package
- Thank you Marcos
09/02/2025
-
08:43 PM pfSense Packages Feature #16070 (Feedback): Add ANDwatch package
- Merged.
-
08:29 PM pfSense Revision d5488f39: Clean up ports build conf
-
07:30 PM pfSense Feature #16241: Block non-global NAT64 addresses by default
- The system alias supports the info pop-up when used in user rules which describes each entry and matches those in @_r...
-
06:50 PM pfSense Revision c6ed6e26: Build net-mgmt/pfSense-pkg-ANDwatch
-
04:02 PM pfSense Feature #16404 (Confirmed): Option to choose update branch from the console menu
- I frequently run into pfsense:s that have a older version of the Base System but don't let me upgrade from option 13 ...
-
03:52 PM pfSense Feature #16403 (New): "Real" Factory reset
- Hi,
An issue I face is that we have a "firewall-aas" kind of approach to some customer's firewalls.
They pay us... -
12:28 PM pfSense Feature #16402: In the firewall rules, it is necessary to add a function that can match the IPV6 suffix for IPV6 users with dynamic PD.
- It's already possible in rules, not practical to implement in aliases, see the mentioned issue(s) as well as #12190
-
12:26 PM pfSense Feature #16402 (Duplicate): In the firewall rules, it is necessary to add a function that can match the IPV6 suffix for IPV6 users with dynamic PD.
- Duplicate of #6626
-
12:26 PM pfSense Bug #15202 (Closed): Add Option for Network Portion of Subnet "Wildcard" for IPv6 Rules
- Duplicate of #6626
-
12:22 PM pfSense Feature #14802 (Duplicate): Re-enable multiqueue support for virtio NIC
- Closing as a duplicate of #16166 as that has an implementation pending already.
09/01/2025
-
03:14 AM pfSense Feature #14802: Re-enable multiqueue support for virtio NIC
- FYI, this is apparently happening: https://redmine.pfsense.org/issues/16166
-
03:14 AM pfSense Feature #16166: Option to deactivate ALTQ for VTNET interfaces
- There is already an older issue https://redmine.pfsense.org/issues/14802, which I believe this change will resolve as...
08/31/2025
-
05:40 PM pfSense Feature #16402 (Duplicate): In the firewall rules, it is necessary to add a function that can match the IPV6 suffix for IPV6 users with dynamic PD.
- My country is promoting IPV6 vigorously,
but I encountered some problems when using pfsense.
Rules does not seem t... -
05:33 PM pfSense Plus Feature #16400: The DHCP Server does not have a Force option to force the sending of the option.
- Missing something like dhcp-option-force for dnsmasq
-
05:25 PM pfSense Plus Feature #16400 (New): The DHCP Server does not have a Force option to force the sending of the option.
- The DHCP Server does not have a Force option to force the sending of the option.
My ISP uses DHCP Option to verify w... -
05:31 PM pfSense Plus Feature #16401 (New): The Kea DHCP server cannot customize specific Option 125.
- My ISP's IPTV Box uses DHCP Option 125 to verify whether the upstream optical modem allows IPTV.
This is custom dat... -
05:25 PM pfSense Packages Bug #16399: Update mDNS-Bridge to 2.2
- This addresses issues discussed in https://github.com/dennypage/mdns-bridge/issues/3.
-
05:09 PM pfSense Packages Bug #16399: Update mDNS-Bridge to 2.2
- PR https://github.com/pfsense/FreeBSD-ports/pull/1423
-
04:49 PM pfSense Packages Bug #16399 (Feedback): Update mDNS-Bridge to 2.2
- Add an option to enable mDNS decode errors that are now silent by default.
-
05:14 PM pfSense Packages Bug #16361: Update mDNS-Bridge to 2.1
- Release 2.2 is in upstream FreeBSD, and has been submitted for pfSense as issue #16399
-
12:56 PM pfSense Plus Feature #16395: Block device by name (with random mac-adress)
- Yes, I suggest blocking by hostname.
The thing is that the user mistakenly connects his android phone to the work ne... -
12:57 AM pfSense Plus Feature #16395 (Incomplete): Block device by name (with random mac-adress)
- Hello,
Are you referring to blocking by device hostname?
Please provide additional details on what "name" you... -
01:06 AM pfSense Plus Bug #16080 (Incomplete): Issues Upgrading from 24.03 to 24.11 SG-1100 Atheros 9280
-
01:06 AM pfSense Plus Bug #16080: Issues Upgrading from 24.03 to 24.11 SG-1100 Atheros 9280
- Nick K wrote in #note-3:
> Kris Phillips wrote in #note-2:
> > Can you please re-test this on 25.07? There was a b... -
01:03 AM pfSense Plus Feature #16026 (Confirmed): UI improvement on user deletion
- I'll mark this as confirmed, as certificates do remain around when a user is deleted.
However, this is how it is... -
01:00 AM pfSense Plus Bug #16398 (Confirmed): When the PD of the WAN interface changes, DHCPv6 does not correctly send the Preferred Lifetime of the previous PD in the Router Advertisement, causing the client to not correctly update its Preferred IP address.
- I can confirm this behavior. RAs should decrement the lifetime to 0 when upstream ISPs change prefix delegations in ...
08/30/2025
-
09:01 PM pfSense Plus Bug #13569: Restarting an OpenVPN server running on a CARP VIP in an HA cluster can disrupt unrelated TCP states
- Retested on 25.07.1 and issue hasn't been solved yet.
-
03:10 PM pfSense Plus Bug #16398: When the PD of the WAN interface changes, DHCPv6 does not correctly send the Preferred Lifetime of the previous PD in the Router Advertisement, causing the client to not correctly update its Preferred IP address.
- This is a very serious problem that will render my pfsense completely unusable.
-
03:08 PM pfSense Plus Bug #16398 (Confirmed): When the PD of the WAN interface changes, DHCPv6 does not correctly send the Preferred Lifetime of the previous PD in the Router Advertisement, causing the client to not correctly update its Preferred IP address.
- My ISP uses PPPoE+DHCPv6 to provide dual-stack capabilities. After redialing, the IPV6 prefix will change.
After the...
08/29/2025
-
07:42 PM pfSense Bug #16397: Show correct first error in system_information.widget
- https://github.com/pfsense/pfsense/pull/4742
-
07:41 PM pfSense Bug #16397 (New): Show correct first error in system_information.widget
- The error message when pfsense is unable to check for updates is always overwritten with "Error in version informatio...
-
06:07 PM pfSense Plus Regression #16381: EFI loader fails to boot on some devices
- Setting exec="staging_slop 268435456" did not resolve boot issues for a customer experiencing problems with booting 2...
-
05:58 PM pfSense Plus Regression #16381 (In Progress): EFI loader fails to boot on some devices
- This is still an issue, even on 25.07.1, with certain hardware.
-
05:30 PM pfSense Todo #16388: Upgrade to Kea 3.0.1
- All the necessary bits should now be in place for Kea 3 in devel builds.
-
05:29 PM pfSense Todo #16388 (Feedback): Upgrade to Kea 3.0.1
-
11:37 AM pfSense Plus Bug #16392: Admin group membership is lost on secondary after changes to user
- reproduced on 25.07.1
latest Plus Dev has it fixed
tested on:
25.11-DEVELOPMENT (amd64)
built on Fri Aug 29 1:56:... -
07:49 AM pfSense Plus Feature #16395 (Rejected): Block device by name (with random mac-adress)
- I would like to ask you to make a function for blocking a device with a random MAC address by name (the name always r...
08/28/2025
-
10:11 PM pfSense Plus Feature #16394 (New): Add Options for Uninstalling Multiple Packages
- Given that customers are recommended to uninstall all packages before upgrading to a new release, it would be helpful...
-
09:13 PM pfSense Plus Bug #16393: When selecting DHCP6 Client Configuration -> Advanced Configuration LAN did not receive prefix delegation.
- RUI YUAN wrote in #note-2:
> I have provided enough information. Why do you think I didn't provide it?
I will dir... -
08:54 PM pfSense Plus Bug #16393: When selecting DHCP6 Client Configuration -> Advanced Configuration LAN did not receive prefix delegation.
- RUI YUAN wrote in #note-2:
> I have provided enough information. Why do you think I didn't provide it?
I mean, yo... -
08:53 PM pfSense Plus Bug #16393: When selecting DHCP6 Client Configuration -> Advanced Configuration LAN did not receive prefix delegation.
- I have provided enough information. Why do you think I didn't provide it?
-
08:25 PM pfSense Plus Bug #16393 (Rejected): When selecting DHCP6 Client Configuration -> Advanced Configuration LAN did not receive prefix delegation.
- There isn't enough information here for a proper bug report. Please use the forum to discuss and diagnose your issue ...
-
07:57 PM pfSense Plus Bug #16393 (Rejected): When selecting DHCP6 Client Configuration -> Advanced Configuration LAN did not receive prefix delegation.
- When selecting
DHCP6 Client Configuration -> Advanced Configuration
LAN did not receive prefix delegation.
-
05:13 PM pfSense Plus Bug #16392 (Feedback): Admin group membership is lost on secondary after changes to user
- This is fixed in CE change 7d545332, I'm also merging it to Plus for 25.11 and the fix will be made available in the ...
-
07:08 AM pfSense Plus Bug #16392: Admin group membership is lost on secondary after changes to user
- That's great to hear, thank you very much for looking into this!
-
12:12 AM pfSense Plus Bug #16392: Admin group membership is lost on secondary after changes to user
- I found it, there's a bug in the account and group sync that doesn't properly account for a user being modified and d...
-
05:09 PM pfSense Revision 7d545332: Only delete a local user on rpc sync if not being modified. Fixes #16391
-
04:22 PM pfSense Revision cfb34ce4: kea2fib6: use new binding-variables in Kea 3
-
04:17 PM pfSense Revision f69de4c1: kea: use binding-variables for storing remote-addr and iface-name
-
12:11 AM pfSense Feature #16241: Block non-global NAT64 addresses by default
Firewall-generated ruleset shows:
table <_nat64reserved_> { 64:ff9b::0/104 64:ff9b::a00:0/104 64:ff9b::6440:...
08/27/2025
-
10:58 PM pfSense Plus Bug #16392: Admin group membership is lost on secondary after changes to user
- I did some more testing and my theory about the admin sync knob is incorrect. There's some interesting behavior where...
-
10:43 PM pfSense Plus Bug #16392: Admin group membership is lost on secondary after changes to user
- This looks like a goofy application of the 'synchronize admin accounts' option in the HA config. With this disabled, ...
-
04:40 PM pfSense Plus Bug #16392 (Assigned): Admin group membership is lost on secondary after changes to user
-
07:34 AM pfSense Plus Bug #16392 (Feedback): Admin group membership is lost on secondary after changes to user
- This affects the synchronization of users an a ha primary/secondary pair.
There is an existing user which is a memb... -
07:22 PM pfSense Revision 7a44ce9b: Add upgrade function to handle spaces in PPP passwords
- Now that spaces are respected, they should be removed when upgrading from
older configuraitons. -
07:17 PM pfSense Docs Correction #16391 (Closed): KEA DHCP Settings help link
- Fixed in https://gitlab.netgate.com/docs/pfSense-docs/-/commit/9fb8b585b2e85822950d547ba0f2f64ec6ca9091
Deployed a... -
07:10 PM pfSense Todo #16128 (Feedback): Sanitize pppoe configuration parameters
- Applied in changeset commit:9da0ba1c6561793e180bf2708a34df27f14e9ee5.
-
06:52 PM pfSense Bug #16296 (Not a Bug): NAT64 traffic originating on OpenVPN interfaces not routing
- The reply-to tag is indeed the culprit. That tag gets added because the OpenVPN Server interface has been assigned - ...
-
04:21 PM pfSense Packages Bug #16220 (Resolved): Wireguard widget default refresh interval is invalid
-
02:04 PM pfSense Revision 9da0ba1c: Sanitize pppoe configuration parameters. Fix #16128
08/26/2025
-
05:47 PM pfSense Todo #16128 (In Progress): Sanitize pppoe configuration parameters
08/25/2025
-
07:30 PM pfSense Docs Correction #16391 (Closed): KEA DHCP Settings help link
Clicking "?" on Services>DHCP Server>Settings does not go to the related help link.
25.07.1-
03:30 PM pfSense Packages Bug #16342: Incorrect behavior of logout button in Tailscale
- aleksei prokofiev wrote in #note-6:
> Retested on 25.07.1
> stepes:
> 1. Create key in admin panel
> 2. Setup Ta...
08/24/2025
-
11:59 PM pfSense Packages Bug #16342: Incorrect behavior of logout button in Tailscale
- confirmed above behavior with 25.07.1 and tailscale 0.1.8
-
05:12 AM pfSense Packages Bug #16342: Incorrect behavior of logout button in Tailscale
- Retested on 25.07.1
stepes:
1. Create key in admin panel
2. Setup Tailscale on pfSense using this key and connect...
08/23/2025
-
11:27 PM pfSense Plus Bug #15303: dpinger service does not always switch from Pending to Online
- Tested on 25.07.1-RELEASE. Editing the gateway on a WAN interface from DHCP to Static and assigning a new static gat...
-
11:23 PM pfSense Packages Feature #16089: Add packages for Zabbix 7.2 and 7.4 agent and proxy
- Checked available packages on 25.07.1. 7.2 and 7.4 are not available.
-
11:19 PM pfSense Packages Todo #16382 (New): Remove deprecated Buypass ACME server support
- It does not need to be aligned with any version, it will happen when it's time for it to happen. It's not a bug or re...
-
11:17 PM pfSense Packages Todo #16382 (Confirmed): Remove deprecated Buypass ACME server support
- Updating status to Confirmed for now and updating Target Version to 25.11, as that should be in November beyond this ...
-
11:16 PM pfSense Packages Bug #16390 (Not a Bug): OpenVPN Client Export Fails to Save Non-High PKCS#12 Encryption Setting
- It is not a persistent setting and isn't intended to be one. It's an export format choice.
-
11:07 PM pfSense Packages Bug #16390 (Confirmed): OpenVPN Client Export Fails to Save Non-High PKCS#12 Encryption Setting
- I can confirm this behavior. Tested on 25.07.1 with OpenVPN Client Export version 1.9.5.
-
08:57 AM pfSense Packages Bug #16390 (Not a Bug): OpenVPN Client Export Fails to Save Non-High PKCS#12 Encryption Setting
- If you attempt to save an encryption level other than High and set it as the default, the setting automatically rever...
-
09:59 PM pfSense Packages Bug #16361: Update mDNS-Bridge to 2.1
- I would like to install version 2.1 to test the fix on my 25.07.1 system. I am unsure how to do this since it is not ...
-
06:21 PM pfSense Bug #16290: Diagnostics -> Authentication crashes if Shared Secret is not correct
- Retested on 25.07 and on latest 25.11-DEV (built on Sat Aug 16 6:00:00 UTC 2025)
I see this issue on both tested p... -
02:14 PM pfSense Packages Bug #16277: Enabling IPv6 support in DNSBL doesn't allow pfb_dnsbl to start
- ...
-
02:09 PM pfSense Packages Bug #16277: Enabling IPv6 support in DNSBL doesn't allow pfb_dnsbl to start
- Tested against:...
-
01:49 PM pfSense Bug #16385 (Duplicate): Dynamic DNS does not track the right IP when using GW groups and VIPs
-
06:05 AM pfSense Bug #16385 (Confirmed): Dynamic DNS does not track the right IP when using GW groups and VIPs
- I can confirm this behavior. The dynamic DNS service doesn't pick the source IP set under the gateway group config, a...
-
08:50 AM pfSense Packages Bug #16329 (Confirmed): openvpn-client-export 1.9.5 | Viscosity Bundle | ECDSA cert missing key when Password Protect Certificate is ticked
- Tested against:...
08/22/2025
-
08:06 PM pfSense Feature #12495 (Feedback): Preserve other record types when updating IPv4 or IPv6 using deSEC DDNS
- Merged.
-
07:53 PM pfSense Revision 75bd2052: Merge pull request #4740 from Godwottery/patch-1
-
07:43 PM pfSense Revision e510b123: Fix 79d74cbd, the port name needs to be lowercase
-
07:10 PM pfSense Feature #16241 (Feedback): Block non-global NAT64 addresses by default
- Applied in changeset commit:90b6e959994692863a71f454785ac7f364054fbe.
-
07:03 PM pfSense Feature #16241 (In Progress): Block non-global NAT64 addresses by default
-
07:01 PM pfSense Revision 90b6e959: Block non-global NAT64 addresses by default. Implement #16241
- Add automatic rules to comply with RFC6052's requirement of dropping
packets that would be translated by NAT64 to non... -
06:22 PM pfSense Bug #16389 (Confirmed): Crash when DHCP is disabled
- I knew that slow processing in emulation systems is not considered. The main problem is why this happens after disabl...
-
06:15 PM pfSense Bug #16389 (Rejected): Crash when DHCP is disabled
- I'm not surprised. Emulation is SLOW. As such, this likely exposes race conditions that just aren't seen on native ha...
-
05:40 PM pfSense Regression #16232 (Feedback): Swap fails to activate when multiple swap partitions exist
- Applied in changeset commit:f4a20381874486f6cc0448f75da923b8726a2936.
- 05:27 PM pfSense Revision f4a20381: Correctly mount multiple SWAP devices. Fixes #16232
- Correct the detection of SWAPDEVICE when the fstab contains multiple lines including SWAP.
-
05:21 PM pfSense Revision 03dade8f: kea2unbound: convert to binding-variables for Kea 3.0
-
05:17 PM pfSense Revision 1bf6eabc: kea: use new binding-variables to store domain-[name|search] in db
-
05:15 PM pfSense Revision 79d74cbd: Disable GSSAPI in cURL until the switch to MIT stabilizes
08/21/2025
-
07:55 PM pfSense Bug #16389 (Confirmed): Crash when DHCP is disabled
- I'm running pfSense 2.8.0 in QEMU emulator on my ARM-based chipset laptop.
It worked well until I disabled its LAN D... -
06:02 PM pfSense Todo #16388 (Feedback): Upgrade to Kea 3.0.1
- Tracking ticket for Kea 3.0
-
05:11 PM pfSense Revision bc585f2d: kea: relocate kea scripts for Kea 3.0 hardening
-
09:07 AM pfSense Revision 167ce421: Explicitly specify IP and preserve other record types when updating IPv4 or IPv6 using deSEC DDNS. Fix #12495
08/20/2025
-
07:15 PM pfSense Docs Correction #16201 (Closed): Feedback on pfSense® software Configuration Recipes — Configuring CoDel Limiters for Bufferbloat
- I changed things around a bit so there was more room to explain what the user should choose there for IPv6.
-
06:55 PM pfSense Bug #16004: tailscale unexpected state: NoState
- Upgraded to 25.07 and facing the same issue. Tried the "tailscale up" command as suggested in the netgate forum threa...
-
04:57 PM pfSense Feature #16387: Disaster recovery when WAN is configured with a static IP
- Thank you for your time and insight.
The intent is to reinstall pfSense in the location with working connectivity.... -
03:16 PM pfSense Feature #16387 (Rejected): Disaster recovery when WAN is configured with a static IP
- This has nothing to do with a static IP address and everything to do with your broken procedures. Opening more issues...
-
12:51 PM pfSense Feature #16387 (Rejected): Disaster recovery when WAN is configured with a static IP
- As confirmed in #14921, External Config Locator only triggers a package sync on first boot.
As documented in #16374,... -
04:48 PM pfSense Regression #16232 (Pull Request Review): Swap fails to activate when multiple swap partitions exist
- https://gitlab.netgate.com/pfSense/factory/-/merge_requests/175
-
03:56 PM pfSense Regression #16232: Swap fails to activate when multiple swap partitions exist
- Also affects 25.07.(1)
The script change from cut to awk creates an invalid device when multiple SWAP lines are pr... -
04:42 PM pfSense Packages Bug #16329: openvpn-client-export 1.9.5 | Viscosity Bundle | ECDSA cert missing key when Password Protect Certificate is ticked
- Today I've upgraded the firewalls in question from 24.11 to 25.07.1 and retested exporting EC. The same thing happens...
-
02:43 PM pfSense Plus Bug #16384 (Rejected): not able to install packages
- I can't reproduce that here. On the latest 25.11 snapshot (25.11.a.20250816.0600) I can install packages without erro...
-
02:08 AM pfSense Plus Bug #16384 (Rejected): not able to install packages
when I try to install packages on 25.11.a.20250816.0600 I get "installation failed!"
WARNING: Current pkg reposi...-
11:17 AM pfSense Packages Bug #16386 (Confirmed): pfSense upgrade re-enables Suricata rulesets that were previously deactivated
- I can confirm this issue. It also occurs after the reinstallation of the package.
Tested on:... -
11:16 AM pfSense Packages Bug #16386: pfSense upgrade re-enables Suricata rulesets that were previously deactivated
- I can confirm this issue. It also occurs after the reinstallation of the package.
Tested on:... -
11:03 AM pfSense Packages Bug #16386 (Confirmed): pfSense upgrade re-enables Suricata rulesets that were previously deactivated
- *Steps to Reproduce*
# Install and enable Suricata on one or more interfaces.
# In the Suricata settings, manuall... -
10:09 AM pfSense Bug #16385 (Duplicate): Dynamic DNS does not track the right IP when using GW groups and VIPs
- Hello,
When we use GW group with CARP VIP selected in HA cluster , the IP selected by the GW group is not used in ... -
05:18 AM pfSense Packages Todo #15785: upgrade to frr10
- Urgently add this to the latest version of the development. BGP is the foundation of the network.
The v10 version ...
08/19/2025
-
03:41 PM pfSense Bug #16163 (Incomplete): Gateway widget incorrectly displays IPv6 default gateway status
- For now it's best to continue the discussion on the forum.
-
03:29 PM pfSense Feature #12495: Preserve other record types when updating IPv4 or IPv6 using deSEC DDNS
- New PR:
https://github.com/pfsense/pfsense/pull/4740 -
03:23 PM pfSense Feature #12494 (Rejected): DynDNS: make simultaneous update of IP and LegacyIP possible
- Each service can potentially implement this feature differently and given the current DDNS implementation it's best t...
-
01:29 PM pfSense Bug #16383: Ping for Regression #15898
- Indeed, checking the code I can see it's there. It was not mentioned in the release notes for 24.11, https://docs.net...
-
01:10 PM pfSense Bug #16383 (Not a Bug): Ping for Regression #15898
- That issue was fixed in Plus 24.11, as indicated in its "Plus Target Version" field.
-
01:03 PM pfSense Bug #16383 (Not a Bug): Ping for Regression #15898
- Just wanted to check in when the fix for regression bug #15898 https://redmine.pfsense.org/issues/15898 will be inclu...
-
12:41 PM pfSense Packages Todo #16382: Remove deprecated Buypass ACME server support
- Jim Pingle wrote in #note-1:
> We are aware (See https://forum.netgate.com/topic/198512/heads-up-buypass-is-shutting... -
12:14 PM pfSense Packages Todo #16382: Remove deprecated Buypass ACME server support
- We are aware (See https://forum.netgate.com/topic/198512/heads-up-buypass-is-shutting-down-their-acme-service ) -- bu...
-
11:55 AM pfSense Packages Todo #16382 (New): Remove deprecated Buypass ACME server support
- Unfortunatly Buypass is shutting down it's TLS/SSL certificate issuing service; https://www.buypass.no/produkter/tls-...
-
12:17 PM pfSense Packages Feature #15706 (Duplicate): Zabbix
-
05:48 AM pfSense Packages Feature #15706: Zabbix
- Zabbix 7.0 packages were released for 24.11 in redmine #15548 so this can be closed.
-
12:16 PM pfSense Packages Bug #13444 (Closed): zabbix_proxy : cannot open "/var/log/zabbix-proxy/zabbix_proxy.log": [13] Permission denied
-
05:43 AM pfSense Packages Bug #13444: zabbix_proxy : cannot open "/var/log/zabbix-proxy/zabbix_proxy.log": [13] Permission denied
- It looks like the PR from @christin has resolved this issue, as I haven't experienced any permission issues with the ...
08/18/2025
-
10:19 PM pfSense Bug #16163: Gateway widget incorrectly displays IPv6 default gateway status
- Potential clue ... just updated to 25.07.1. Following the reboot, the v6 gateway status showed as in the previous sc...
-
08:34 PM pfSense Packages Bug #16301: Telegraf stops service over night
- The output of "ps aux|grep telegraf":...
-
07:22 PM pfSense Bug #16373: pfSense 25.07 Dynamic DNS Client Failure
- Jim Pingle wrote in #note-2:
> This is most likely from the gateway being offline, which is known and not a bug. You... -
06:31 PM pfSense Docs Todo #16363 (Closed): Feedback on Services — UPnP IGD
- Updated.
-
04:02 PM pfSense Plus Regression #16381 (In Progress): EFI loader fails to boot on some devices
- The EFI loader can potentially fail to boot with certain combinations of hardware.
This issue is for tracking purp... -
03:56 PM pfSense Plus Bug #16080: Issues Upgrading from 24.03 to 24.11 SG-1100 Atheros 9280
- Kris Phillips wrote in #note-2:
> Can you please re-test this on 25.07? There was a bump in FreeBSD version since 2... -
02:37 PM pfSense Plus Bug #16375: Boot Environment page fails to load if ``pfsense:version`` ZFS property contains newlines
- The only platform known to be affected is Azure, it was not reproducible anywhere else. Also, not a regression as 25....
-
01:51 PM pfSense Plus Bug #16380 (Rejected): Bridge WAN-LAN Problem.
- There is not enough information here to determine what may be the cause of your problem, but that is not a proper bri...
-
01:31 PM pfSense Plus Bug #16380 (Rejected): Bridge WAN-LAN Problem.
- WAN no IP Address;
LAN with IP Address;
Rules in LAN All Enable;
Gateway on LAN Interface;
The firewall cannot... -
01:27 PM pfSense Feature #16379 (New): Firewall Log GUI filter for IPv4 or IPv6
- Under the Advanced Log filter for firewall logs, it would be nice if one could filter only IPv6 hits in the logs, or ...
-
12:44 PM pfSense Bug #16374: Unable to restore 2.8.0 with static WAN IP
- Hello Jim,
I can reproduce this issue directly from console.
The attached "1stBoot.log" documents the change of... -
12:12 PM pfSense Bug #16359: Cannot (re)install a configuration where WAN is a VLAN defined on a LAGG using the new Netgate installer
- Hello Kris,
First, this is a "belt and suspenders" configuration used to protect critical systems (HVAC, lighting,... -
11:57 AM pfSense Regression #16362: syslogd can die if a remote syslog server refuses connection
- In my test setup it was of the order of 10mins.
-
09:44 AM pfSense Regression #16362: syslogd can die if a remote syslog server refuses connection
- I can't reproduce this.
In my test I did see that syslogd noticed the error (ECONNREFUSED) and then marked the des... -
01:16 AM pfSense Bug #16376 (Confirmed): With "System Events" enabled certain logs are duplicated on remote syslog
- Confirmed...
-
12:23 AM pfSense Regression #16368: Custom Dynamic DNS services ignore the monitor interface
- confirm patch works with 25.07.1
08/17/2025
-
08:48 PM pfSense Packages Bug #16342: Incorrect behavior of logout button in Tailscale
- I believe since the log out and clean button is on the authentication page, the expectation is that the pre-auth key ...
-
04:11 AM pfSense Bug #16351: OpenVPN Gateway creation - incorrect IPv6 address
- When you create a dual stack OpenVPN server with the following settings:
Gateway creation: both
IPv4 (legacy ip) tun... -
02:29 AM pfSense Bug #15847: Kea DHCP lease utilization stats incorrect for delegated prefix pools
- With the move from 25.03 to 25.07, I re-tested this on the release version. This issue is still present in the curre...
08/16/2025
-
11:39 PM pfSense Bug #16163: Gateway widget incorrectly displays IPv6 default gateway status
- Hey, Kris. Have only been running 25.07 for a couple of days. Haven't yet seen the Gateway IPv6 display change on i...
-
09:09 PM pfSense Bug #16163: Gateway widget incorrectly displays IPv6 default gateway status
- Marc Goldburg wrote in #note-1:
> Correction: System_Patches rev is 2.2.20_4
Hello Marc,
Are you still experie... -
09:28 PM pfSense Regression #16368: Custom Dynamic DNS services ignore the monitor interface
- I can confirm the patch fixes the issue on...
-
09:13 PM pfSense Bug #16351 (Incomplete): OpenVPN Gateway creation - incorrect IPv6 address
- Hello,
Please clarify what you mean by "legacy IP" and what you expect the IPv6 address to be. Both of those addr... -
09:10 PM pfSense Plus Bug #16080: Issues Upgrading from 24.03 to 24.11 SG-1100 Atheros 9280
- Can you please re-test this on 25.07? There was a bump in FreeBSD version since 24.11 that may or may not affect thi...
-
09:04 PM pfSense Bug #16359: Cannot (re)install a configuration where WAN is a VLAN defined on a LAGG using the new Netgate installer
- Serge Caron wrote in #note-2:
> Hello Kris,
>
> Thank you for your prompt reply. LACP is not used in this configu... -
09:01 PM pfSense Bug #16018: Mysterious Entire Crash in "PFSense CE"
- Guido Lipke wrote in #note-4:
> Marco, the GUI isnt working anymore when the Crash happends... Also a reboot doesnt ... -
05:51 PM pfSense Packages Feature #16378 (New): Add Option for ip ospf message-digest-key
- Currently, the FRR GUI does not have an option to define a message-digest-key for OSPFv2. The default behavior curre...
-
05:04 PM pfSense Packages Bug #16294 (Resolved): Cert Creation/Renewal DNS-Gandi LiveDNS not working with PAT Token
- fixed - Gandi LiveDNS method in acme 1.0 has both PAT and API key fields.
tested on:
25.11-DEVELOPMENT (amd64)
bui... -
04:13 PM pfSense Plus Bug #16375: Boot Environment page fails to load if ``pfsense:version`` ZFS property contains newlines
- unable to reproduce, please specify steps if possible
tested on:
25.07-RELEASE (amd64)
built on Fri Aug 8 16:24:00... -
02:22 PM pfSense Packages Bug #16361: Update mDNS-Bridge to 2.1
- Thanks - I filed https://github.com/dennypage/mdns-bridge/issues/3 about this
-
01:46 PM pfSense Packages Bug #16301: Telegraf stops service over night
- I added service watchdog to automatically restart telegraf. Now I disabled it - if it happens again, I will comment t...
08/15/2025
-
11:24 PM pfSense Bug #16376 (Confirmed): With "System Events" enabled certain logs are duplicated on remote syslog
- Tested on...
-
09:31 PM pfSense Feature #15934: Kea Lease Reclamation and Affinity Options (IPv4 and IPv6)
- With 2.80 and Plus 25.07, I have identified that the following as an issue and should be easy to correct.
Upon a r... -
07:46 PM pfSense Plus Bug #16375 (Feedback): Boot Environment page fails to load if ``pfsense:version`` ZFS property contains newlines
- ...
-
06:35 PM pfSense Plus Bug #16372: Advise users to release more space before upgrading to 25.07
- The upgrade guide is mentioned in the release announcement on the blog, and it's the official place to find informati...
-
06:28 PM pfSense Plus Bug #16372: Advise users to release more space before upgrading to 25.07
- Jim Pingle wrote in #note-1:
> The upgrade guide already mentions this specifically.
>
> https://docs.netgate.com... -
02:06 PM pfSense Plus Bug #16372 (Rejected): Advise users to release more space before upgrading to 25.07
- The upgrade guide already mentions this specifically.
https://docs.netgate.com/pfsense/en/latest/install/upgrade-g... -
03:44 PM pfSense Bug #16367: Reinstall Packages button reports another instance of ``pfSense-upgrade`` is running (Not a duplicate of #15494)
- Thank you for your time.
As reported, issue #16374 is the detailled process to reproduce this condition. I underst... -
03:37 PM pfSense Bug #16367 (Rejected): Reinstall Packages button reports another instance of ``pfSense-upgrade`` is running (Not a duplicate of #15494)
- I can't reproduce this as stated. Most likely the problem is a lack of WAN connectivity when it comes back up, hence ...
-
03:43 PM pfSense Bug #16373 (Not a Bug): pfSense 25.07 Dynamic DNS Client Failure
- This is most likely from the gateway being offline, which is known and not a bug. You can fix the gateway monitoring ...
-
01:59 PM pfSense Bug #16373 (Incomplete): pfSense 25.07 Dynamic DNS Client Failure
- There isn't enough detail here to identify any specific problem, and this site is not for support or diagnostic discu...
-
07:22 AM pfSense Bug #16373 (Not a Bug): pfSense 25.07 Dynamic DNS Client Failure
- Upgrade pfSense to 25.07 and my Dynamic DNS clients now fail with the following error.
```
/services_dyndns_edit.... -
03:38 PM pfSense Bug #16374: Unable to restore 2.8.0 with static WAN IP
- Hello Jim,
That is why I provided a test case config.xml.
I tested this on two unrelated corporate network with... -
03:34 PM pfSense Bug #16374 (Duplicate): Unable to restore 2.8.0 with static WAN IP
- Most likely the same root cause as #16367 in your environment (though I can't reproduce either one)
-
02:34 PM pfSense Bug #16374 (Duplicate): Unable to restore 2.8.0 with static WAN IP
- (This is a rewrite of #16367)
There is no issue restoring a 2.8.0 installation with a static WAN IP in the exact s... -
01:39 PM pfSense Bug #15770 (Confirmed): Limiter Limits Whole Gateway instead of Single IP
- I am able to replicate this on 25.11 as well using limiters. In the example below, limiter @0001@ is for upload (50Mb...
08/14/2025
-
11:52 PM pfSense Plus Bug #16372 (Rejected): Advise users to release more space before upgrading to 25.07
- After upgrading pfSense to version 25.07, I am seeing a firewall-related error and multiple concerns, like /var/cach...
-
09:08 PM pfSense Feature #16241: Block non-global NAT64 addresses by default
- We have some ideas on what could be done to make it easier. I'll ponder this some more.
-
02:49 PM pfSense Packages Bug #16361: Update mDNS-Bridge to 2.1
- → luckman212 wrote in #note-3:
> Does this relate at all to these errors I'm seeing in my system.log:
> [...]
> These... -
12:17 PM pfSense Packages Bug #16361: Update mDNS-Bridge to 2.1
- Does this relate at all to these errors I'm seeing in my system.log:...
Also available in: Atom