Project

General

Profile

Activity

From 11/09/2025 to 12/08/2025

Today

09:28 PM pfSense Plus Bug #16571: pkg segfaults on some package installs
This is going to end up being a problem for some users as they depend upon being able to install upstream FreeBSD pac... Denny Page
06:44 PM pfSense Plus Bug #16571 (Not a Bug): pkg segfaults on some package installs
This is not an issue in practice given that builds are done with the pkg version respective to the release. Marcos M
07:44 PM pfSense Bug #16577 (Feedback): Netgate Installer - Invalid path to up-script in mpd_wan.conf when using PPPoE WAN
Fixed in the v1.1.1-RELEASE Luiz Souza
06:36 PM pfSense Bug #15956: Kea DHCP static mappings requires lease expiry before taking effect
I think I have the same issue. I have a static mapping for MAC address, yet pfSense keeps assigning dynamic address o... Nazar Mokrynskyi
06:24 PM pfSense Bug #16572: IPv6 Link Local address on WAN interface does not respond to Neighbour Solicitation by default
The 'default' ruleset on a CE @2.8.1-RELEASE@ system appears to pass inbound Neighbor Solicitation messages in accord... Matt Dombrowski
12:07 PM pfSense Packages Feature #16578 (New): Feature request: pfBlockerNG profiles per interface/VLAN (like OPNsense Unbound Access Lists)
Hey,With Squid/SquidGuard dying, pfBlockerNG is becoming the main tool for everyone doing web filtering and category ... Marcelo Cury

12/07/2025

09:27 AM pfSense Bug #16577 (Feedback): Netgate Installer - Invalid path to up-script in mpd_wan.conf when using PPPoE WAN
Version 1.1-RELEASE of the Netgate installer has a bug in the way the installer configures mpd_wan.conf when trying t... Dan Monaghan
08:16 AM pfSense Plus Bug #16571: pkg segfaults on some package installs
Please change affected version to 25.11. Thanks. Denny Page
04:37 AM pfSense Plus Bug #16571: pkg segfaults on some package installs
Apologies, 24.11 was a typo. The current 25.11 RC (25.11.r.20251126.1732) is the affected version. Denny Page
03:05 AM pfSense Plus Bug #16571 (Incomplete): pkg segfaults on some package installs
Hello,
Have you tested this on a supported release? 24.11 is no longer a supported release of Plus.
Kris Phillips
03:14 AM pfSense Plus Feature #16401 (Incomplete): The Kea DHCP server cannot customize specific Option 125.
Marking as Incomplete, as there has been no response to the above question in 3 months. Kris Phillips
03:10 AM pfSense Plus Bug #16560: Netgate Installer Occassionally Duplicates Characters and Displays Black-on-Black Text
Danilo Zrenjanin wrote in #note-3:
> I can confirm the behavior described in the ticket subscription.
>
> Additio...
Kris Phillips
03:08 AM pfSense Plus Regression #16474 (Closed): No page assigned to this user
Marcelo Cury wrote in #note-5:
> You can close this incident..
> Changed from posixgroup to group and that is it......
Kris Phillips
03:07 AM pfSense Plus Feature #16506 (Confirmed): VLAN creation interface
Tested this on 25.11-RELASE. I can confirm this difference in behavior from prior versions. Kris Phillips
03:03 AM pfSense Bug #16572 (Confirmed): IPv6 Link Local address on WAN interface does not respond to Neighbour Solicitation by default
Not sure if there is a reason behind this being turned off by default, but I can confirm this tunable is disabled on ... Kris Phillips

12/06/2025

07:49 PM pfSense Packages Feature #16576 (New): update nmap package from 7.94 to 7.98
According to the changelog history https://nmap.org/changelog.html
7.94 was release in May 2023. Since then, ther...
a w
05:20 PM pfSense Regression #16575 (Feedback): Firewall logs do not match pf rules with rule number ``0``
Applied in changeset commit:6c00e3c78c4119b729aa5ecfe01e2a26d38505a3. Marcos M
05:16 PM pfSense Regression #16575 (Feedback): Firewall logs do not match pf rules with rule number ``0``
Filter log lines can have a rule number of "0" (first value):
> 0,846,,1683152017,igb0,match,block,in,4,0x28,,43,368...
Marcos M
05:17 PM pfSense Revision 6c00e3c7: Don't skip empty values when parsing filter logs. Fix #16575
Marcos M
10:08 AM pfSense Bug #16574 (New): PPPoe boot error with if_pppoe driver on Broadcom NIC: 'wrong interface, not accepting host unique'
Summary:
When using the new if_pppoe kernel module in pfSense CE 2.8.1 with a Broadcom NIC (bce driver), a PPPoE-rel...
Mike Wren
09:24 AM pfSense Bug #16573 (New): PPPoE interface using new driver on Broadcom NIC breaks external DNS for LAN clients (pfSense still resolves)
Summary:
When using the new if_pppoe kernel module in pfSense 2.8.1 with a Broadcom NIC (bce driver), LAN clients — ...
Mike Wren
03:47 AM pfSense Bug #16572 (Confirmed): IPv6 Link Local address on WAN interface does not respond to Neighbour Solicitation by default
ISPs using Juniper Layer 2 liveness detection use ND packets sent to the link local address to check the host is live... Jamie Cooper

12/05/2025

10:43 PM pfSense Plus Bug #16571 (Not a Bug): pkg segfaults on some package installs
Packages built with the standard FreeBSD package system in 14.3 or 15.0 (pkg version 2.4.2) cause pkg and pkg-static ... Denny Page
08:45 PM pfSense Bug #16290 (Confirmed): ``diag_authentication.php`` crashes with a core dump if RADIUS client Shared Secret value is not correct
Marcos M
08:00 PM pfSense Packages Bug #16003 (Waiting on Merge): ACME IPv6 CloudFlare issues, IPv4 preferred not respected
Internal MR: https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/451
Will merge after the 25.11 rele...
Jim Pingle
08:00 PM pfSense Packages Todo #16382 (Waiting on Merge): Remove deprecated Buypass ACME server support
Internal MR: https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/451
Will merge after the 25.11 rele...
Jim Pingle
08:00 PM pfSense Packages Bug #16556 (Waiting on Merge): ACME package unnecessarily references and checks for ACME v2
Internal MR: https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/451
Will merge after the 25.11 rele...
Jim Pingle
07:05 PM pfSense Bug #16549: Captive portal "allowed IPs" does not work if language is not english
Applied in changeset commit:251e202ecd97c8c994cd9dbebe2c1dc198500b8e. Christian McDonald
07:00 PM pfSense Bug #16549: Captive portal "allowed IPs" does not work if language is not english
Fixed with https://gitlab.netgate.com/pfSense/pfSense/-/commit/251e202ecd97c8c994cd9dbebe2c1dc198500b8e Christian McDonald
06:59 PM pfSense Bug #16549 (Feedback): Captive portal "allowed IPs" does not work if language is not english
Christian McDonald
06:54 PM pfSense Revision 251e202e: captive portal: fix `allowed IPs` with languages other than English. Fixes #16549
Christian McDonald
05:06 PM pfSense Feature #15934: Kea Lease Reclamation and Affinity Options (IPv4 and IPv6)
Further to my comment above that was made 4 months ago. Working with 25.11 Beta Nov 26, I have confirmed that althou... Dale Harron
03:42 PM pfSense Packages Todo #15785 (Feedback): upgrade to frr10
Marcos M
03:33 PM pfSense Revision f7f67ea5: Don't implicitly build frr10
The package pfSense-pkg-frr now depends on these and hence frr10
no longer needs to be listed here.
This reverts com...
Marcos M
03:06 PM pfSense Bug #16540 (Resolved): Reserved DUMMYNET pipes for Captive Portal can overlap
Good to hear. If additional related issues are found, this redmine can be reopened or a new one created. Marcos M
03:03 PM pfSense Feature #16534 (Resolved): Omit reserved NAT64 addresses from DNS64 answers
Tested working on latest build. Marcos M
11:29 AM pfSense Todo #16551 (Resolved): Update output and parsing behavior for PHP shell ``pfanchordrill``
fixed, patch/change works
tested on
25.11-RELEASE (amd64)
built on Mon Dec 1 17:59:00 UTC 2025
FreeBSD 16.0-CURRENT
Georgiy Tyutyunnik
01:57 AM pfSense Bug #15708: The filterdns service won't start
filterdns is designed to start a thread per FQDN entry to enable parallel evaluation of all DNS lookups.
While it is...
Patch Public

12/04/2025

09:30 PM pfSense Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap
Marcos M wrote in #note-17:
> No, I wouldn't expect that behavior from the patch alone. We can discuss further on th...
Christopher Causer
08:01 PM pfSense Docs Todo #16570 (New): Feedback on Firewall — Time Based Rules
*Page:* https://docs.netgate.com/pfsense/en/latest/firewall/time-based-rules.html
*Feedback:*
Since https://redmi...
Steve Y
07:36 PM pfSense Regression #16569 (Not a Bug): Can't set non-recurring schedule
There's no support currently for setting the year. Marcos M
06:48 PM pfSense Regression #16569 (Not a Bug): Can't set non-recurring schedule
Per https://docs.netgate.com/pfsense/en/latest/firewall/time-based-rules.html#configuring-schedules-for-time-based-ru... Steve Y

12/03/2025

09:18 PM pfSense Packages Bug #15296: WAN Interface cannot added to ntopng if offline-packet loss
Sergei Shablovsky wrote in #note-1:
> Sergei Shablovsky wrote:
> >
> > But LAN interfaces ALL would be ADDED as w...
Denny Page
08:56 PM pfSense Packages Regression #14232: ntopng no longer tracks top talkers
FWIW, I spent some time checking into this. Unfortunately, this is a basic restriction in the community version of nt... Denny Page
08:49 PM pfSense Bug #16566 (Resolved): Incorrect configuration change message when deleting an outbound NAT rule

added and deleted the Outbound NAT rules, and no errors occurred.
26.03.a.20251203.1905
Alhusein Zawi
07:49 PM pfSense Bug #16549: Captive portal "allowed IPs" does not work if language is not english
As this is not a regression, we will not be blocking the release of 25.11 over this issue.
However, once a fix is ...
Christian McDonald
07:48 PM pfSense Bug #16549 (In Progress): Captive portal "allowed IPs" does not work if language is not english
Christian McDonald
06:20 AM pfSense Bug #16549: Captive portal "allowed IPs" does not work if language is not english
Tested on
25.07.1-RELEASE (amd64)
built on Wed Aug 20 15:17:00 MSK 2025
FreeBSD 15.0-CURRENT
25.11-RELEASE (am...
aleksei prokofiev
02:56 PM pfSense Bug #15226: Tables for mixed aliases lists occasionally do not contain all records from the alias list.
Since the alias contains a FQDN it sounds like https://forum.netgate.com/topic/199152/unexpected-alias-behaviour-two-... Steve Y
05:50 AM pfSense Feature #16561: Please offically support this PHP script for installing SSL Keys & Certs
Ok, fair enough. Feature Request #16568 has been created. Dennis Adler
05:49 AM pfSense Feature #16568 (New): Please support installation of Certificate/Key pairs through backend APIs
I initially submitted Feature #16561 which Jim Pingle Rejected because the PHP script I suggested is using outdated m... Dennis Adler

12/02/2025

09:45 PM pfSense Feature #16534 (Feedback): Omit reserved NAT64 addresses from DNS64 answers
Applied in changeset commit:c1a0168388cf765eb248e82b28ecbdf21c04964b. Marcos M
08:30 PM pfSense Feature #16534 (In Progress): Omit reserved NAT64 addresses from DNS64 answers
Marcos M
08:13 PM pfSense Revision c1a01683: Omit reserved NAT64 addresses from DNS64 answers. Implement #16534
We create default filter rules to prevent the NAT64 translation for
reserved IPv4 addresses. For example, a request t...
Marcos M
06:03 PM pfSense Todo #16567 (New): Remove link-local fe80::1:1 addresses from trackv6 interfaces
Interfaces configured as trackv6 for IPv6 get configured with an additional link-local address in the form: fe80::1:1... Steve Wheeler
03:35 PM pfSense Bug #16566 (Feedback): Incorrect configuration change message when deleting an outbound NAT rule
Applied in changeset commit:586e9110e99c77f55f27120612f3def9317e7940. Marcos M
03:25 PM pfSense Bug #16566 (Resolved): Incorrect configuration change message when deleting an outbound NAT rule
Deleting a rule at Firewall > NAT > Outbound results in the following incorrect config write message:
> Firewall: NA...
Marcos M
03:25 PM pfSense Revision 586e9110: Update config write message when deleting outbound rules. Fix #16566
Marcos M
03:10 PM pfSense Revision 9bc10c56: Allow installing vital packages via the WebGUI
Only removal of vital packages should be prohibited via the WebGUI. Marcos M
03:05 PM pfSense Bug #16153 (Feedback): ECL can modify a discovered config file
Applied in changeset commit:4ffc71f3e16801862cd67f8f1a901c83bbd82078. Marcos M
03:00 PM pfSense Bug #16153 (In Progress): ECL can modify a discovered config file
Another symptom of the same root cause is that the ECL may fail to restore the config. Marcos M
03:00 PM pfSense Revision 4ffc71f3: Don't write to the backup file when restoring a config. Fix #16153
The function restore_backup() no longer needs to write to a separate file
before replacing the config file. The atomi...
Marcos M
02:12 PM pfSense Bug #16562 (Rejected): Ubound does not start as teh DNS Resolver on pfSense-ce 2.8.1
There isn't enough information here to consider it a valid bug, and I can't reproduce that here.
Please post on th...
Jim Pingle
08:00 AM pfSense Bug #16562 (Rejected): Ubound does not start as teh DNS Resolver on pfSense-ce 2.8.1
Unbound does not start as the DNS resolver.
Dec 2 02:56:38 stargate php-fpm[39573]: /services_unbound.php: The co...
Cory Albrecht
02:10 PM pfSense Regression #14833: OpenVPN client process in bridged tap mode fails after 2.7.0 CE upgrade
Afonso Turcato wrote in #note-2:
> Bob Weybrecht wrote:
> > Have a P2P OpenVPN tunnel that bridges 2 physical inter...
Afonso Turcato
12:37 AM pfSense Regression #14833: OpenVPN client process in bridged tap mode fails after 2.7.0 CE upgrade
Bob Weybrecht wrote:
> Have a P2P OpenVPN tunnel that bridges 2 physical interfaces for the purpose of passing multi...
Afonso Turcato
11:00 AM pfSense Feature #16565 (New): Allow FRR Raw Config to be saved in the standard XML backup file
Currently, FRR configuration can be managed via Services / FRR / Global Settings / Raw Config.
The downside is tha...
Gerard Alcorlo
10:50 AM pfSense Feature #16564 (New): Prevent accidental edits: Distinguish 'Duplicate' mode from 'Edit' mode
Often, when trying to duplicate a firewall rule, I accidentally click 'Edit' instead of 'Duplicate'. I don't realize ... Gerard Alcorlo
10:34 AM pfSense Feature #16563 (New): Remove TCP flags option from firewall rule when the protocol is not TCP
When creating a firewall rule with Protocol set to "any", I attempted to configure *TCP Flags: any flags* under Advan... Gerard Alcorlo

12/01/2025

08:20 PM pfSense Packages Bug #16003: ACME IPv6 CloudFlare issues, IPv4 preferred not respected
Upstream, @acme.sh@ has added a command line parameter to force IPv4 or IPv6 that should accommodate this use case. S... Jim Pingle
08:18 PM pfSense Packages Bug #15061 (Resolved): acme.sh nsupdate with challengealias is failing in certain cases
Jim Pingle
08:18 PM pfSense Packages Feature #9833 (Resolved): ACME: add ability to use custom ACME server
Jim Pingle
07:09 PM pfSense Packages Bug #16329 (Resolved): ECDSA key file missing when exporting a Viscosity bundle with a password protected certificate
Fixed in the latest OpenVPN client export package build. Jim Pingle
05:16 PM pfSense Packages Bug #16329: ECDSA key file missing when exporting a Viscosity bundle with a password protected certificate
We already have code in other places that detects the key type, it's simple enough to do something like this here:
<...
Jim Pingle
05:13 PM pfSense Packages Bug #16329 (In Progress): ECDSA key file missing when exporting a Viscosity bundle with a password protected certificate
Jim Pingle
07:09 PM pfSense Packages Todo #16542 (Resolved): Update OpenVPN Windows Installer to 2.6.17
Fixed in the latest OpenVPN client export package build. Jim Pingle
05:13 PM pfSense Packages Todo #16542: Update OpenVPN Windows Installer to 2.6.17
I'm updating the 2.6.x installer to 2.6.17, removing the 2.5.x installer, and leaving 2.4.x as-is.
The 2.4.x insta...
Jim Pingle
05:11 PM pfSense Packages Todo #16542 (In Progress): Update OpenVPN Windows Installer to 2.6.17
Jim Pingle
05:18 PM pfSense Bug #16552 (Resolved): Hostnames in Kea static leases may not be registered with DNS
Jim Pingle
05:12 PM pfSense Bug #16552: Hostnames in Kea static leases may not be registered with DNS
Tested in 25.11.r.20251126.1732, works as intended. Denny Page
02:23 PM pfSense Docs New Content #16470 (Closed): VLAN Tag Type
Jim Pingle
01:57 PM pfSense Bug #16484: External Configuration Locator does not reset pfSense console after restoration
Hello Kris,
I am not certain that ECL is involved on the first boot: the NetGate installer has copied the configur...
Serge Caron
01:08 PM pfSense Feature #16561 (Rejected): Please offically support this PHP script for installing SSL Keys & Certs
That certificate import script uses outdated methods of configuration manipulation. Rather than supporting an externa... Jim Pingle
06:57 AM pfSense Feature #16561 (Rejected): Please offically support this PHP script for installing SSL Keys & Certs
As you are no doubt aware, the Browser Consortium is cutting down the allowable lifetime for certificates. The curren... Dennis Adler
02:32 AM pfSense Bug #15708: The filterdns service won't start
To the user this bug results in latent failure of a pfsense installation so is more serious than it initially appears... Patch Public

11/29/2025

11:11 PM pfSense Packages Bug #16353 (Feedback): failed to dynamically load plugin '/usr/local/lib/named/filter-aaaa.so': plugin API version mismatch: 1/2
Tested on 25.11-RC. BIND starts normally and without issue for me.
Nov 29 17:08:50 pfSenseKVMTest named[93670]: s...
Kris Phillips
11:07 PM pfSense Bug #16484 (Confirmed): External Configuration Locator does not reset pfSense console after restoration
ECL runs after install when booting, so this has nothing to do with the Netgate Installer, no matter the version. I'... Kris Phillips
10:56 PM pfSense Plus Bug #16553 (Confirmed): When creating Static route using alias for Destination, subnet constrains to /32, even for aliases that point to an IPv6 subnet
This appears to be the default behavior for all Aliases, regardless of the IP version. Both an IPv4 and IPv6 alias w... Kris Phillips
11:14 AM pfSense Plus Bug #16560: Netgate Installer Occassionally Duplicates Characters and Displays Black-on-Black Text
I can confirm the behavior described in the ticket subscription.
Additionally, the color switches from default col...
Danilo Zrenjanin
09:45 AM pfSense Plus Bug #16560 (Confirmed): Netgate Installer Occassionally Duplicates Characters and Displays Black-on-Black Text
Lev Prokofev
09:44 AM pfSense Plus Bug #16560: Netgate Installer Occassionally Duplicates Characters and Displays Black-on-Black Text
Can confirm it, tested on 5100. Lev Prokofev
04:12 AM pfSense Packages Todo #16542: Update OpenVPN Windows Installer to 2.6.17
Released OpenVPN 2.6.17:
* CVE-2025-13751: Windows/interactive service: fix erroneous exit on error that could be
...
Silmor Senedlen

11/28/2025

06:22 PM pfSense Docs New Content #16470: VLAN Tag Type
25.11.r.20251127.2230 has the ability to adjust the tag-type when creating or editing VLANs which coordinates with th... Jordan G
05:13 PM pfSense Plus Bug #16560 (Confirmed): Netgate Installer Occassionally Duplicates Characters and Displays Black-on-Black Text
When booting the installer over serial, often the installer will have "duplicated" output like this:
//bboooott//c...
Kris Phillips
01:05 PM pfSense Todo #16559 (Resolved): Remove custom gateway ordering
works - no longer able to manually change gw order
tested on:
26.03-DEVELOPMENT (amd64)
built on Fri Nov 28 6:00:0...
Georgiy Tyutyunnik
12:14 PM pfSense Bug #16557 (Resolved): Alerts do not trigger for empty config change descriptions
Log entries for config change with null description much more informative after the change:
*25.07.1 FRR ACL chang...
Georgiy Tyutyunnik

11/27/2025

05:20 PM pfSense Plus Regression #16407: Editing Alias assigned to Static Route doesn't update routing table
Answering my own question: editing the alias and re-saving both the alias and the static route does NOT fix the routi... → luckman212
03:18 PM pfSense Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap
No, I wouldn't expect that behavior from the patch alone. We can discuss further on the forum, feel free to post here... Marcos M
10:36 AM pfSense Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap
We applied the patch, but had to revert: The captive portal wasn't appearing, and from a client we could ping 8.8.8.8... Christopher Causer

11/26/2025

07:00 PM pfSense Bug #16429 (Resolved): NAT64 rules using ``reply-to`` do not forward packets
Tested working in 25.11-RC. Marcos M
06:28 PM pfSense Revision 19729155: Garbage collect setting NOASLR in dns/unbound as the option is gone now
Brad Davis
06:05 PM pfSense Todo #16559 (Feedback): Remove custom gateway ordering
Applied in changeset commit:cf9154cab2a485744dbfe0b7b37bef69273c0142. Marcos M
05:51 PM pfSense Todo #16559 (Resolved): Remove custom gateway ordering
The gateway order shown at System > Routing > Gateways uses the following priority:
# Gateways assigned to an interf...
Marcos M
05:53 PM pfSense Revision cf9154ca: Remove ability to manually order gateways. Implement #16559
Marcos M
05:09 PM pfSense Todo #16503 (Resolved): Update Unbound to 1.24.2 to address CVE-2025-11411
We are now building 1.24.2. Christian McDonald
05:08 PM pfSense Todo #16503: Update Unbound to 1.24.2 to address CVE-2025-11411
https://nlnetlabs.nl/news/2025/Nov/26/unbound-1.24.2-released/ Christian McDonald
03:32 PM pfSense Bug #16495 (Feedback): Gateway list order is incorrect until reloading page after moving entries and saving
The gateway ordering may not be what a user expects because some gateways (namely those assigned to interfaces) are a... Marcos M
12:42 PM pfSense Packages Feature #16558 (New): Add support of static-challenge OpenVPN option in Radius for 2FA
Currently, Radius+OTP requires the user to add the PIN+OTP in the password field every time the user connects. With t... Lev Prokofev

11/25/2025

11:39 PM pfSense Bug #15110: pfSense hangs when rebooting

M O wrote in #note-8:
> same issue here. 6100, 23.09.1
>
> onboard mmc died, added a WD SN520 NVME SSD.
>
...
Jim Thompson
11:09 PM pfSense Bug #16495 (In Progress): Gateway list order is incorrect until reloading page after moving entries and saving
I'm not able to reproduce it on my edge anymore, but I can on a different system. I'll need to investigate further. Marcos M
09:49 PM pfSense Bug #16495: Gateway list order is incorrect until reloading page after moving entries and saving
Refreshing the page didn’t show it correctly.
25.11.r.20251118.1708
Alhusein Zawi
10:25 PM pfSense Packages Todo #15785: upgrade to frr10
Applied with commit "78317fc79c3e6c4e4f1ee50eca44ec53bd85623c":https://github.com/pfsense/FreeBSD-ports/commit/78317f... Marcos M
10:17 PM pfSense Packages Bug #16556: ACME package unnecessarily references and checks for ACME v2
Jim Pingle wrote in #note-1:
> That check could be removed anyway since ACMEv1 has been retired since 2021 and the o...
Marc Sánchez Fauste
04:15 PM pfSense Packages Bug #16556: ACME package unnecessarily references and checks for ACME v2
That check could be removed anyway since ACMEv1 has been retired since 2021 and the old server entries were removed l... Jim Pingle
04:01 PM pfSense Packages Bug #16556 (Waiting on Merge): ACME package unnecessarily references and checks for ACME v2
When configuring a custom ACME server, it is not possible to issue wildcard certificates due to a hardcoded check in ... Marc Sánchez Fauste
10:10 PM pfSense Bug #16557 (Feedback): Alerts do not trigger for empty config change descriptions
Applied in changeset commit:09aedfb18eb81663b2fc72d968fa0df0690fb3ca. Marcos M
09:55 PM pfSense Bug #16557 (Resolved): Alerts do not trigger for empty config change descriptions
A user notice is supposed to trigger when a configuration change is written but a description is not specified. This ... Marcos M
09:55 PM pfSense Revision 09aedfb1: Check for an empty description when writing config changes. Fix #16557
Marcos M
06:46 PM pfSense Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap
@chyc Any luck? Marcos M
06:34 PM pfSense Bug #16552: Hostnames in Kea static leases may not be registered with DNS
Awesome news. Thank you both! Denny Page

11/24/2025

08:10 PM pfSense Revision 0fddb3b4: Remove reserved pipes file on reboot
Restores previous behavior. The pipe reservation doesn't matter during
boot since there's no configured dn pipes at t...
Marcos M
07:41 PM pfSense Bug #16552: Hostnames in Kea static leases may not be registered with DNS
This is going to land in 25.11 Christian McDonald
01:53 PM pfSense Plus Bug #16555 (New): Session timeout not being honored, /tmp/sess_* files are accumulating
I'm running pfSense+ 25.11 RC 25.11.r.20251118.1708 on a 6100
I casually reported this at https://forum.netgate.co...
→ luckman212
08:50 AM pfSense Bug #16549: Captive portal "allowed IPs" does not work if language is not english
p.s. Another side effect of the bug, is that symbols → , ← and ⇄ are not displayed in the interface Lorenzo Paulatto

11/23/2025

05:34 PM pfSense Bug #16554 (New): Traffic Shaper Wizard Multi LAN/WAN PRIQ Affects LAN to LAN
Here is how to reproduce an issue where speed is reduced between internal networks where it should only be affecting ... Brian Shell
05:17 PM pfSense Plus Bug #16553 (Confirmed): When creating Static route using alias for Destination, subnet constrains to /32, even for aliases that point to an IPv6 subnet
Tested on 25.11.r.20251118.1708
I have a *Network* alias defined as @n_v6_syno_64@ pointing to -> @2001:470:dead:b...
→ luckman212
05:08 PM pfSense Plus Regression #16407: Editing Alias assigned to Static Route doesn't update routing table
Is a reboot necessary to get the routing table updated with the new alias definition? Or is simply editing the alias ... → luckman212
03:20 AM pfSense Bug #16242 (Confirmed): When IPv6 Is Disabled the Firewall Still Queries IPv6 Localhost for DNS
Tested on 25.11-RC. Can confirm this is still an issue.
However, the interesting thing is that if you disable I...
Kris Phillips
03:11 AM pfSense Packages Todo #16542 (Confirmed): Update OpenVPN Windows Installer to 2.6.17
Checking the latest OpenVPN Client Export package on 25.11, it's still on 2.6.7 for the latest version to be exported... Kris Phillips

11/22/2025

11:39 PM pfSense Plus Bug #16459: Session timeout set to 0 but times out in a few hours
still looking ok in 25.11.r.20251121.2016 Jordan G
07:23 PM pfSense Bug #16290 (Assigned): ``diag_authentication.php`` crashes with a core dump if RADIUS client Shared Secret value is not correct
I'm afraid it hasn't been resolved. Azamat Khakimyanov
07:22 PM pfSense Bug #16290: ``diag_authentication.php`` crashes with a core dump if RADIUS client Shared Secret value is not correct
Tested on 25.11-RC (built on Fri Nov 21 20:16:00 UTC 2025) and 26.03-DEVELOPMENT (built on Sat Nov 22 6:00:00 UTC 202... Azamat Khakimyanov
01:49 AM pfSense Bug #16550: Cannot load alternate TCP Congestion Control kernel modules
Where can we read more about these alternate congestion control modules and when they might be useful? → luckman212

11/21/2025

11:05 PM pfSense Bug #16550 (Confirmed): Cannot load alternate TCP Congestion Control kernel modules
Marcos M
11:05 PM pfSense Bug #16550: Cannot load alternate TCP Congestion Control kernel modules
... Marcos M
03:55 PM pfSense Bug #16550 (Confirmed): Cannot load alternate TCP Congestion Control kernel modules
Since at least the 25.11.b.20251028.1838 beta several TCP CC modules are no longer loading. I have confirmed this is ... Glenn Hall
11:03 PM pfSense Plus Bug #16548 (Closed): GUI and package manager shows the RC branch despite the Stable branch is selected.
This is the result of a backend issue as is being tracked internally. Marcos M
10:00 AM pfSense Plus Bug #16548: GUI and package manager shows the RC branch despite the Stable branch is selected.
Can confirm that
!clipboard-202511211254-v3rec.png!
Despite branch is selected as current it use RC
!clipboard-202...
aleksei prokofiev
07:36 AM pfSense Plus Bug #16548 (Closed): GUI and package manager shows the RC branch despite the Stable branch is selected.

Despite the Stable branch being selected, after a few refreshes of the GUI, it appears that RC strings are pulled i...
Lev Prokofev
09:35 PM pfSense Bug #16552 (Feedback): Hostnames in Kea static leases may not be registered with DNS
Applied in changeset commit:523397bab9948cda9ee5d420c9e93bffee27096e. Marcos M
08:35 PM pfSense Bug #16552 (Resolved): Hostnames in Kea static leases may not be registered with DNS
It's expected that the hostname specified in a Kea static lease is registered in DNS Resolver when DNS Registration i... Marcos M
09:28 PM pfSense Revision 523397ba: Always send domain-name and domain-search options. Fix #16552
If a client doesn't request the "domain-name" or "domain-search" options
then Kea does not include them in the lease....
Marcos M
08:25 PM pfSense Todo #16551 (Feedback): Update output and parsing behavior for PHP shell ``pfanchordrill``
Applied in changeset commit:9ec6472147ba52a53a6d217f8eec51f63d02d180. Marcos M
08:09 PM pfSense Todo #16551 (Resolved): Update output and parsing behavior for PHP shell ``pfanchordrill``
The pf anchor parsing done in pfanchordrill currently may not work with Captive Portal. When a Captive Portal zone ha... Marcos M
08:11 PM pfSense Revision 9ec64721: Update anchor parsing in pfanchordrill. Implement #16551
Marcos M
07:00 PM pfSense Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules
We have a patch pending that stops the crash, my test system has been stable overnight and all day today and I haven'... Jim Pingle
02:41 PM pfSense Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules
Just uploaded a crash dump to the nextcloud drop from the RC debug kernel if it helps
→ luckman212
06:21 PM pfSense Revision 5ebbd87b: Remove l3 check when passing ARP for authenticated clients
Followup to 604a7b0d4d31e332d6fd4111b22ee29416e0700d. Marcos M
03:19 PM pfSense Bug #16549 (Feedback): Captive portal "allowed IPs" does not work if language is not english
In the captive portal configuration, when configuring allowed IPs one has to choose the direction: "Both", "From", "T... Lorenzo Paulatto
10:14 AM pfSense Packages Bug #16206: Package apcupsd starts even when disabled
Tested on
25.11-RC (amd64)
built on Tue Nov 18 20:08:00 MSK 2025
FreeBSD 16.0-CURRENT
The issue is still present.
aleksei prokofiev

11/20/2025

11:23 PM pfSense Revision 4c726dcf: Clarify EIM-NAT help text
Marcos M
11:23 PM pfSense Revision 908cc031: Kea: handle empty binding variables
Followup to 35b7ace2e50e8e9387ae23964a0d18978601e0dd. Marcos M
09:28 PM pfSense Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules
→ luckman212 wrote in #note-19:
> Thanks @jimp
> In the other thread, Marcos was asking for me to test with the de...
Jim Pingle
09:07 PM pfSense Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules
Thanks @jimp
In the other thread, Marcos was asking for me to test with the debug kernel - is that still useful at ...
→ luckman212
08:52 PM pfSense Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules
Based on the full description in the FreeBSD commit the end goal is full cone but the inbound connection from any hos... Jim Pingle
06:56 PM pfSense Feature #16423: Enable Post Quantum Crypto Support in SSH Server
Jim Pingle wrote in #note-5:
> The upcoming Plus 25.11 release has OpenSSL 3.5.3 and OpenSSH 10.0p2: https://docs.ne...
KStar Runner
04:46 PM pfSense Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap
The dummynet pipes are created and removed based on the pipe reservation. Inaccurate pipe reservation data can result... Marcos M
04:35 PM pfSense Bug #16540 (Feedback): Reserved DUMMYNET pipes for Captive Portal can overlap
Applied in changeset commit:c42eba1d78cc0b97dcb5abc604c9ab7e6e50d8a9. Marcos M
09:04 AM pfSense Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap
I think I've found the issue. The dnpipe numbers are being duplicated between the auth'd clients and the allowed host... Christopher Causer
04:25 PM pfSense Revision c42eba1d: Don't clobber Captive Portal pipe reservations. Fix #16540
Keep pipe reservations on reboot for applicable zones. Previously the
pipe reservation file would always be deleted.
...
Marcos M
04:15 PM pfSense Revision 35b7ace2: Fix parsing of Kea binding-variables
- "pkt.src" needs to be converted.
- "option[24]" is an array but appropriate accessors aren't available.
Marcos M
02:05 PM pfSense Feature #14558: Feature Request: GUI options to Unbound Resolver's new DoH abilities
“NSA recommends that an enterprise network’s DNS traffic, encrypted or not, be sent only to the designated enterprise... Jonathan Lee
01:59 PM pfSense Feature #14558: Feature Request: GUI options to Unbound Resolver's new DoH abilities
Please reference:
https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/2471956/nsa-recommends-how-enterpri...
Jonathan Lee
12:20 PM pfSense Bug #16385: Dynamic DNS does not track the right IP when using GW groups and VIPs
Possibly related to https://redmine.pfsense.org/issues/16326 Lev Prokofev

11/19/2025

03:36 PM pfSense Plus Regression #16474: No page assigned to this user
You can close this incident..
Changed from posixgroup to group and that is it...
It works in 25.07.1, but with 25.1...
Marcelo Cury
02:06 PM pfSense Plus Regression #16474: No page assigned to this user
Spoke too soon.
No page assigned to this user is now appearing, which indicates that the problem is no longer DNS or...
Marcelo Cury
11:31 AM pfSense Plus Regression #16474: No page assigned to this user
I was able to identify and temporarily work around the issue.
When TLS/SSL is disabled and the hostname is changed t...
Marcelo Cury
03:02 PM pfSense Plus Feature #15941: /etc/rc.dumpon
Attached is the dump working with custom location showing proof of concept. With the help of Netgate forums we found ... Jonathan Lee
02:33 PM pfSense Plus Feature #15941: /etc/rc.dumpon
Side note use command: dumpon -l when testing this will show where crash files are expected to go.
Also I think t...
Jonathan Lee
01:49 PM pfSense Todo #16547 (New): Make Priority field when editing a VLAN consistent with the VLAN Priority fields in firewall rules
The VLAN Priority field when creating or editing a VLAN entry is currently a free-form text field where the user has ... Jim Pingle
12:29 PM pfSense Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules
While I'm able to create the EIMNAT rule without kernel panicking now, not sure this feature is working for me. Tests... → luckman212
03:20 AM pfSense Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules
Tested on pfSense-25.11.r.20251118.1708 and I have EIMNAT enabled now for outbound NAT.
As long as Static Port isn't...
→ luckman212

11/18/2025

11:25 PM pfSense Bug #16546 (Resolved): NAT64 rules do not pass traffic when a gateway is specified for the rule
Working in 25.11-RC.
https://github.com/pfsense/FreeBSD-src/commit/5845935a8d2dd26f652fae9bce2f8c947a290d46
Marcos M
11:25 PM pfSense Bug #16546 (Resolved): NAT64 rules do not pass traffic when a gateway is specified for the rule
NAT64 rules pass traffic as expected until route-to (aka gateway / policy routing) is added to the rule. When using r... Marcos M
10:05 PM pfSense Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap
There's potential for this kind of issue to occur in the mentioned cases. It's unclear how else it can happen but we ... Marcos M
09:44 PM pfSense Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap
Marcos M wrote in #note-5:
> When the issue happened, was there a CARP event or any configuration change to Captive ...
Christopher Causer
09:15 PM pfSense Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap
When the issue happened, was there a CARP event or any configuration change to Captive Portal? Marcos M
08:41 PM pfSense Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap
Here is the list during the outage.
Just as an example, here is a rule taken from /var/etc/filterdns-tawny_owl-capti...
Christopher Causer
03:42 PM pfSense Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap
At the risk of jumping the gun here, I've taken a look at this output.
Pipe numbers associated with "Allowed IP A...
Christopher Causer
03:19 PM pfSense Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap
Marcos M wrote in #note-1:
> Is this an HA setup? Do you have "Preserve users database" checked in any of the Captive...
Christopher Causer
03:05 PM pfSense Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap
Is this an HA setup? Do you have "Preserve users database" checked in any of the Captive Portal zone configs? When th... Marcos M
08:31 PM pfSense Packages Bug #16544: During WAN failover event, HAproxy frontend IPs are not transferred from the primary to the secondary pfSense HAproxy service
Unfortunately I cannot run beta software as this is for a production environment. It seems it'll be in my company's b... Lauren C

11/17/2025

08:27 PM pfSense Docs New Content #16470 (Feedback): VLAN Tag Type
Updated all of the VLAN docs and screenshots to match current GUI options/layout and updated the examples to use inte... Jim Pingle
07:00 PM pfSense Packages Bug #16544 (Feedback): During WAN failover event, HAproxy frontend IPs are not transferred from the primary to the secondary pfSense HAproxy service
Marcos M
07:00 PM pfSense Packages Bug #16544: During WAN failover event, HAproxy frontend IPs are not transferred from the primary to the secondary pfSense HAproxy service
Try testing on the 25.11-BETA if possible. I'm not able to reproduce it there which indicates it was likely fixed by ... Marcos M
04:31 PM pfSense Packages Bug #16544 (Feedback): During WAN failover event, HAproxy frontend IPs are not transferred from the primary to the secondary pfSense HAproxy service
Configuration synchronization via XMLRPC is enabled. Configuration appears to be syncing, but failover of the fronten... Lauren C
05:33 PM pfSense Bug #16541: Multi-wan setup doesn’t save IPv6 configuration settings
Jim Pingle wrote in #note-3:
> There still isn't enough valid information in that thread to suggest a bug, and LLM o...
Bradley O’Hearne
05:01 PM pfSense Bug #16541: Multi-wan setup doesn’t save IPv6 configuration settings
There still isn't enough valid information in that thread to suggest a bug, and LLM output cannot be trusted.
I ha...
Jim Pingle
04:09 PM pfSense Bug #16541: Multi-wan setup doesn’t save IPv6 configuration settings
Jim Pingle wrote in #note-1:
> There isn't enough information here to conclude there is a bug and not some other cau...
Bradley O’Hearne
01:14 PM pfSense Bug #16541 (Incomplete): Multi-wan setup doesn’t save IPv6 configuration settings
There isn't enough information here to conclude there is a bug and not some other cause, and I can't reproduce it as ... Jim Pingle
01:16 PM pfSense Feature #16423: Enable Post Quantum Crypto Support in SSH Server
The upcoming Plus 25.11 release has OpenSSL 3.5.3 and OpenSSH 10.0p2: https://docs.netgate.com/pfsense/en/latest/rele... Jim Pingle
01:09 PM pfSense Packages Bug #16543 (Rejected): PHP/ Suricata widget error
There isn't enough information here to determine if this is a bug or some other cause (e.g. filesystem issue, disk ha... Jim Pingle
05:43 AM pfSense Packages Bug #16543 (Rejected): PHP/ Suricata widget error
Got this crash log - no idea how it happened.
@Crash report begins. Anonymous machine information:
amd64
15....
A A
03:52 AM pfSense Packages Todo #16542 (Resolved): Update OpenVPN Windows Installer to 2.6.17
Good day
Current package contains Windows Installer version 2.6.7 from 2023.11.09.
Actual Windows version now is 2....
Silmor Senedlen

11/16/2025

05:53 PM pfSense Bug #16541 (Incomplete): Multi-wan setup doesn’t save IPv6 configuration settings
I recently upgraded to pfSense 2.8.* and attempted to configure second WAN and LAN interfaces for the purposes of a m... Bradley O’Hearne
04:26 AM pfSense Bug #16298: Cannot create multiple DHCPv6 reservations for hosts with multiple interfaces
Is there any chance this will make it into 2.9.0? Daryl Morse

11/15/2025

10:53 PM pfSense Feature #16423: Enable Post Quantum Crypto Support in SSH Server
Jim Pingle wrote in #note-3:
> Needs a little more time so we can fix up the SSH server ciphers as well and make sure...
KStar Runner
11:50 AM pfSense Bug #16540 (Resolved): Reserved DUMMYNET pipes for Captive Portal can overlap
Periodically, and outside of work hours (don't know if that's relevant as it may be luck), the allowed hostnames (acc... Christopher Causer
01:32 AM pfSense Plus Bug #16323: Serial/Console Baud Rate Cannot Be Changed
still does not respect the serial console speed that is set in the web interface when testing with 25.11.r.20251114.1404 Jordan G

11/14/2025

11:54 PM pfSense Bug #16122: Interfaces=>Vlans, ipsecX interfaces are listed in the VLAN parent interface config dropdown menu.
still seeing IPsec interface available in VLAN creation drop down when testing on 25.11.r.20251114.1404 Jordan G
11:54 PM pfSense Bug #16248 (Resolved): QLink/Marvell 41000 NIC bug
This is fixed in current 25.11 builds:... Steve Wheeler
11:17 PM pfSense Plus Bug #16539 (Closed): Missing File Error in ACB on 25.11-RC2
Disregard. Further testing in a different browser or in Incognito doesn't trigger this error, so it must be somethin... Kris Phillips
10:36 PM pfSense Plus Bug #16539 (Closed): Missing File Error in ACB on 25.11-RC2
When loading the Services --> AutoConfigBackup page, the following error is logged repeatedly in the System Logs:
...
Kris Phillips
09:05 PM pfSense Todo #16538 (Feedback): Prevent removal of vital packages from the GUI
Applied in changeset commit:8086918989b2dd5d29c1376738b4314c24afd8ad.
Currently no package in the pfSense CE GUI is ...
Marcos M
08:57 PM pfSense Todo #16538 (Feedback): Prevent removal of vital packages from the GUI
Packages listed at System > Package Manager > Installed Packages may be considered vital. These vital packages should... Marcos M
09:01 PM pfSense Revision 80869189: Prevent removal of vital packages from the GUI. Implement #16538
Marcos M
08:44 PM pfSense Revision 6d433e67: Ignore config when removing additional packages on factory reset
Marcos M
08:34 PM pfSense Revision 76e9a611: Introduce helper functions for default system packages
Currently empty. Can be used to keep a package when the system is
reset, e.g. from Diagnostics > Factory Defaults.
Marcos M
07:30 PM pfSense Docs New Content #16452 (Feedback): Add VXLAN documentation
This should cover things sufficiently for now:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/0a7beb56eae44...
Jim Pingle
04:41 PM pfSense Docs Todo #16476 (Closed): Feedback on Services — NTPD — NTP Server Configuration
Fixed the link and added a general note about expiration based on the info in the header comments of the leap second ... Jim Pingle
04:34 PM pfSense Docs Correction #16524 (Closed): IKE Endpoint Configuration - Remote Gateway part requires correction
Fixed and deployed: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/fa98d8a985ec0e4f13874e7d4ff28d67ca95eab7 Jim Pingle
04:19 PM pfSense Docs Correction #16536 (Closed): Floating Rules now work with action=match and quick=enabled
I removed it from the 25.11 docs branch so it will be changed with the release. There was another similar sentence un... Jim Pingle
10:13 AM pfSense Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules
At least some NAT translations must have failed. This may be a configuration issue, or perhaps there's just so much t... Kristof Provost
01:28 AM pfSense Docs Todo #16537 (New): Add Note in Azure pfSense Plus to Enable IP Forwarding on Interfaces
Currently the "Getting Started" guide for multiple interfaces doesn't mention enabling IP Forwarding in Azure on the ... Kris Phillips

11/13/2025

08:54 PM pfSense Docs Correction #16497 (Closed): FreeBSD 15 links redirect to FreeBSD 14 doc pages.
Fixed in https://gitlab.netgate.com/docs/pfSense-docs/-/commit/0b7c3f970b959ff439d49bb66dd2624073ccb803 -- will be li... Jim Pingle
06:55 PM pfSense Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules
@kprovost That's excellent! I suscribed to that phabricator ID and will stay tuned for any way to test. Even after re... → luckman212
04:19 PM pfSense Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules
I managed to reproduce the problem and have a fix pending review: https://reviews.freebsd.org/D53737 Kristof Provost
06:10 PM pfSense Packages Bug #13043 (Confirmed): OSPF over Wireguard interface doesn't populate neighbors after reboot
Customer reports this is still an issue on 25.07.1 and requires a force restart of FRR after boot manually for the Wi... Kris Phillips
04:44 PM pfSense Docs Correction #16536: Floating Rules now work with action=match and quick=enabled
Thank you for the clarification. → luckman212
04:24 PM pfSense Docs Correction #16536 (New): Floating Rules now work with action=match and quick=enabled
Jim Pingle
04:19 PM pfSense Docs Correction #16536 (Not a Bug): Floating Rules now work with action=match and quick=enabled
It's fixed in 25.11:
https://redmine.pfsense.org/issues/16475
We may prevent that in the future if the ability is...
Marcos M
03:46 PM pfSense Docs Correction #16536 (Closed): Floating Rules now work with action=match and quick=enabled
The docs at https://docs.netgate.com/pfsense/en/latest/firewall/floating-rules.html#match-action state:
_"Match ru...
→ luckman212
04:15 PM pfSense Revision c093e703: pfPorts: build net/frr10
Marcos M
01:23 PM pfSense Bug #16535 (Rejected): Netgate 3100 on pfsense 25.07.1-RELEASE: Dynamic DNS cannot find IP on WAN (
There isn't enough detail here to identify any specific problem, and this site is not for support or diagnostic discu... Jim Pingle
02:40 AM pfSense Bug #16535 (Rejected): Netgate 3100 on pfsense 25.07.1-RELEASE: Dynamic DNS cannot find IP on WAN (
Hello!
On pfsense 25.07.1-RELEASE for Netgate 3100, The Dynamic DNS script cannot find the WAN IP address, so upda...
Chris T
12:18 AM pfSense Bug #16487 (Resolved): Virtual IP addresses on PPPoE interfaces using ``if_pppoe`` can prevent PPP session termination
Marcos M
12:16 AM pfSense Bug #15770 (Resolved): Using a Limiter on a rule with a gateway group limits all traffic through that gateway instead of the host IP address
Marcos M
12:16 AM pfSense Feature #16325 (Resolved): Add support for labels in configuration rules
Marcos M
12:15 AM pfSense Feature #15952 (Resolved): Support Message-Authenticator in the PHP RADIUS client
Not likely - best to try moving away from L2TP. Marcos M
12:14 AM pfSense Bug #16290 (Resolved): ``diag_authentication.php`` crashes with a core dump if RADIUS client Shared Secret value is not correct
Marcos M
12:13 AM pfSense Regression #16326 (Resolved): Dynamic DNS does not use preferred VIP in Gateway Group
Marcos M
12:11 AM pfSense Feature #12495 (Resolved): Preserve other record types when updating IPv4 or IPv6 using deSEC DDNS
Marcos M
12:11 AM pfSense Feature #16068 (Resolved): Option to disable logging of packets blocked due to unmatched IP options
Marcos M
12:07 AM pfSense Todo #16128 (Resolved): Sanitize PPPoE configuration parameters
Marcos M

11/12/2025

10:21 PM pfSense Regression #13622 (Resolved): Retain previous QinQ VLAN tag type value for existing entries on upgrade
Marcos M
10:14 PM pfSense Feature #16534 (Needs Patch): Omit reserved NAT64 addresses from DNS64 answers
This needs addressed first: https://github.com/NLnetLabs/unbound/issues/1373 Marcos M
10:12 PM pfSense Feature #16534 (Resolved): Omit reserved NAT64 addresses from DNS64 answers
We create default filter rules to prevent the NAT64 translation for reserved IPv4 addresses. For example, a request t... Marcos M
10:10 PM pfSense Todo #16307 (Resolved): Refactor PF ruleset generation
Marcos M
10:05 PM pfSense Feature #16308 (Resolved): Avoid traffic stalls from unnecessary filter reloads
Marcos M
10:03 PM pfSense Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules
Thanks - I just uploaded them. Also want to add, if any extra info is needed that can't be gleaned from the dumps and... → luckman212
09:15 PM pfSense Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules
You can upload the crash dump files here:
https://nc.netgate.com/nextcloud/s/Dq9WxFFkCp4QiPN
Marcos M
08:34 PM pfSense Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules
Since 25.11.b.20251111.2016 dropped today, I figured I'd try this again. Sadly, got an immediate fatal crash / pagefa... → luckman212
10:01 PM pfSense Feature #16241 (Resolved): Block non-global NAT64 addresses by default
Marcos M
10:01 PM pfSense Regression #16513 (Resolved): WireGuard service show status stopped but peers can still connect
Marcos M
10:00 PM pfSense Packages Bug #15274 (Resolved): HAProxy Configuration Changes Require pfSense Reboot to Take Effect
Marcos M
09:39 PM pfSense Plus Regression #16526 (Resolved): Netgate 2100/3100 LED controller not responding to ``gpioctl``
Fix reported as working on latest build:
https://forum.netgate.com/topic/199182/sg-2100-leds-different-in-25.11.b.20...
Marcos M
09:18 PM pfSense Feature #14864: Add option to enable unbound respip module (support RPZ)
This will need to wait for https://github.com/NLnetLabs/unbound/issues/1373 Marcos M
08:47 PM pfSense Bug #16266 (Resolved): Thermal Sensors widget does not respect per-sensor threshold vales
Works as expected in 25.11-Beta. Tested: pfSense-25.11.b.20251112
!Screenshot%20from%202025-11-12%2020-46-01.png!
Steve Wheeler
07:41 PM pfSense Bug #16266 (Feedback): Thermal Sensors widget does not respect per-sensor threshold vales
MR was merged several months ago. Jim Pingle
08:40 PM pfSense Regression #16421 (Resolved): OpenVPN servers will not start with DH parameter lengths less than 2048
Looks good here now:
* GUI option for 1024 is gone
* The file with 1024 DH parameter data is no longer present
*...
Jim Pingle
08:38 PM pfSense Revision 78076563: Test full unbound config when validating new settings
When test_unbound_config() is called, only a partial configuraiton is
tested. It's possible there may be custom optio...
Marcos M
08:32 PM pfSense Todo #6727 (Resolved): Apple TouchID/FaceID probes for site icon files that do not exist
Jim Pingle
08:31 PM pfSense Bug #15411 (Resolved): Log entries without a hostname can cause the system log to display in an unexpected manner
Seems good on current snapshots, kernel log entries from boot do not make other log entries unreadable anymore. Jim Pingle
08:28 PM pfSense Bug #16341 (Closed): Error notification and log message ``"Updating repositories metadata" returned error code 1`` at boot due to ``certctl`` race condition
I still occasionally see this while running and not at boot, but infrequently and I can't repeat it on demand like I ... Jim Pingle
08:22 PM pfSense Regression #16232 (Resolved): Swap fails to activate when multiple swap partitions exist
This has been working since it went in Jim Pingle
08:21 PM pfSense Regression #16362 (Resolved): ``syslogd`` daemon can terminate when a remote log server refuses connections
Jim Pingle
08:17 PM pfSense Regression #16368 (Resolved): Custom Dynamic DNS services ignore the monitor interface
Jim Pingle
08:17 PM pfSense Todo #16468 (Resolved): Kea configuration parameter ``client-class`` is deprecated
Jim Pingle
08:09 PM pfSense Regression #16449 (Resolved): e1000 network interfaces unexpectedly link at half-duplex
The changes are in 25.11 and dev snapshot builds, should be OK to close. Jim Pingle
08:08 PM pfSense Todo #16471 (Resolved): Upgrade PHP to 8.4
Current builds of 25.11 and dev snapshots have php84-8.4.13 Jim Pingle
08:07 PM pfSense Todo #16509 (Resolved): Update strongSwan to 6.0.3
Current builds of 25.11 now include strongswan-6.0.3
Now that this is complete and we're closer to a release we ca...
Jim Pingle
07:45 PM pfSense Bug #3132 (New): Gateway events for IPv6 affect IPv4 services and vice versa
Jim Pingle
07:42 PM pfSense Feature #15323 (New): Display server description when WOL is sent using mac url or power-on button
Jim Pingle
07:39 PM pfSense Packages Bug #16410 (Closed): Arpwatch incorrect subject line
MR was merged 2 months ago. Jim Pingle
07:38 PM pfSense Feature #16423: Enable Post Quantum Crypto Support in SSH Server
Needs a little more time so we can fix up the SSH server ciphers as well and make sure everything is current/optimal. Jim Pingle
07:36 PM pfSense Bug #16248 (Feedback): QLink/Marvell 41000 NIC bug
This patch is in the current 25.11 builds, has been for a while. Jim Pingle
05:34 PM pfSense Packages Feature #16533: Add Multicast Bridge (mcast-bridge) package
PR is here: https://github.com/pfsense/FreeBSD-ports/pull/1428 Denny Page
05:30 PM pfSense Packages Feature #16533 (New): Add Multicast Bridge (mcast-bridge) package
Multicast Bridge is a daemon for forwarding UDP multicast data between
network interfaces, and is intended as an alt...
Denny Page
05:16 PM pfSense Packages Bug #16491 (Closed): FreeRADIUS Accounts with "%" Character in the Password String Fail Authentication
This was a bug in FreeRADIUS, not pfSense. The package repo contains FreeRADIUS 3.2.8 now which should include this fix. Jim Pingle
05:14 PM pfSense Plus Bug #16375 (Closed): Boot Environment page fails to load if ``pfsense:version`` ZFS property contains newlines
Jim Pingle
05:12 PM pfSense Plus Bug #15613 (Closed): ``rc.savecore`` errors prevent boot in ZFS
Jim Pingle
05:11 PM pfSense Plus Bug #15499 (Closed): Manually verifying the boot environment makes config changes
Jim Pingle
05:06 PM pfSense Docs New Content #16452: Add VXLAN documentation
This was in before but was removed, see https://gitlab.netgate.com/docs/pfSense-docs/-/commit/62916992ae9979d716f1085... Jim Pingle
05:03 PM pfSense Plus Feature #11732 (Closed): VXLAN Interfaces
Jim Pingle
03:20 PM pfSense Feature #15952: Support Message-Authenticator in the PHP RADIUS client
Is there a chance that this could be extended to the L2TP RADIUS authentication section?
!clipboard-202511121020-gmo...
Ansley Barnes
01:07 PM pfSense Packages Bug #16348 (Resolved): HAProxy configuration references non-existent certificate files
I was able to reproduce the issue on version 25.07.1, but only when the Netgate Nexus Controller was enabled.
I co...
Danilo Zrenjanin

11/11/2025

11:35 PM pfSense Bug #16495 (Feedback): Gateway list order is incorrect until reloading page after moving entries and saving
The issue is cosmetic. The order is stored correctly but needs a page refresh to show it.
Applied in changeset commi...
Marcos M
11:25 PM pfSense Revision c951eb9a: Reflect correct gateway order after saving. Fix #16495
Also add input validation for the new order. Marcos M
10:38 PM pfSense Plus Regression #16526 (Feedback): Netgate 2100/3100 LED controller not responding to ``gpioctl``
Marcos M
10:11 PM pfSense Feature #15952: Support Message-Authenticator in the PHP RADIUS client
Tested working; "Require Message Authenticator" can now be set to "Yes" in FreeRADIUS when using pfSense as a client. Marcos M
08:14 PM pfSense Feature #15952 (Feedback): Support Message-Authenticator in the PHP RADIUS client
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/commit/c25dea7695534ded51ffceae4ced6c740dee3c49 Christian McDonald
07:17 PM pfSense Feature #15952 (In Progress): Support Message-Authenticator in the PHP RADIUS client
Christian McDonald
09:35 PM pfSense Bug #16532 (New): The calculation of online leases IPs is incorrect.
Hi,
PfSense Plataform: CE 2.8.0 and 2.8.1
*The generated list by the Status/IPsec/Leases page appears to be inc...
Geovane Gonçalves
08:38 PM pfSense Plus Regression #16369 (Closed): Go-based software crashes on hardware with 5-level paging (LA57)
Jim Pingle
07:08 PM pfSense Feature #14483: Conditionally reconfigure IPsec VTI interfaces only when necessary while applying IPsec changes
No, there haven't been any changes that could help here or any alternate approaches that would be less labor-intensive. Jim Pingle
06:00 PM pfSense Feature #14483: Conditionally reconfigure IPsec VTI interfaces only when necessary while applying IPsec changes
Any update on this? Mike Moore
05:51 PM pfSense Revision ca5fa2c3: Use consistent auth log format. Fix #16528
Marcos M
05:47 PM pfSense Revision 1e780ca9: Move get_user_remote_address() and get_user_remote_authsource() to util.inc
These functions are defined in auth.inc and used in config.lib.inc.
Since auth.inc requires config.lib.inc, move the ...
Marcos M
05:46 PM pfSense Revision 94e8d98c: Use the correct pf ridentifier max when deduplicating rule tracker IDs
pf uses uint32 for ridentifier. Marcos M
05:04 PM pfSense Revision 03dc855a: Clean username before auth fail log. Fixes #16314
Jim Pingle

11/10/2025

10:49 PM pfSense Regression #16326: Dynamic DNS does not use preferred VIP in Gateway Group
IIRC there have been other changes around that area in 25.11 which is probably why the patch doesn't apply. Marcos M
06:49 PM pfSense Regression #16326: Dynamic DNS does not use preferred VIP in Gateway Group
Marcos M wrote in #note-12:
> Further testing showed an issue when the BACKUP node tried to update the record. There...
Casey Sardoss
10:35 PM pfSense Bug #16290 (Feedback): ``diag_authentication.php`` crashes with a core dump if RADIUS client Shared Secret value is not correct
A fix will be included in the next 25.11 build. Marcos M
10:33 PM pfSense Packages Bug #15916: pfBlockerNG dnsbl daemon not able to start in CARP mode
This should be fixed in pfBlockerNG-devel - changes have been picked to 25.11.
pfBlockerNG (non-devel) will pick u...
Marcos M
10:30 PM pfSense Packages Bug #15916 (Feedback): pfBlockerNG dnsbl daemon not able to start in CARP mode
Marcos M
10:05 PM pfSense Regression #16421 (Feedback): OpenVPN servers will not start with DH parameter lengths less than 2048
Applied in changeset commit:799ec00952c0057d44f77024c2081ce0ff48a28d. Marcos M
09:53 PM pfSense Revision 799ec009: Remove unsupported dh-parameters. Fix #16421
Marcos M
04:48 PM pfSense Plus Regression #16526 (Resolved): Netgate 2100/3100 LED controller not responding to ``gpioctl``
In current 25.11 builds the LED controller in the 2100 and 3100 no longer responds to the gpioctl duty command. This ... Steve Wheeler
04:42 PM pfSense Bug #13792: Filterdns assumes sets of resolved addresses for each hostname are nonintersecting
I'd point out too that filterdns isn't updating the alias with the valid IP on its next run, it seems to be assuming ... Steve Y
02:04 PM pfSense Docs Correction #16497: FreeBSD 15 links redirect to FreeBSD 14 doc pages.
→ luckman212 wrote in #note-3:
> It looks like the latest 25.11 snaps are now based on 16.0, not 15.0
Yes, that i...
Jim Pingle
02:03 PM pfSense Bug #16495: Gateway list order is incorrect until reloading page after moving entries and saving
Christopher Cope wrote in #note-1:
> Firstly, the behavior on this page is not consistent with the rest of the firew...
Jim Pingle
01:49 PM pfSense Bug #14741 (Closed): PHP error in DNS Forwarder host overrides when the language is set to French
Jim Pingle
01:48 PM pfSense Feature #16525 (Rejected): Add option to enable openssl FIPS compliance
It isn't that easy, real FIPS compliance means the entire system must be re-tested and certified for every build (at ... Jim Pingle

11/09/2025

08:57 PM pfSense Feature #16525 (Rejected): Add option to enable openssl FIPS compliance
If possible, would be nice to add a menu option to enable FIPS in openssl.
This can often be a requirement for pfSe...
Craig Coonrad
 

Also available in: Atom