# 2.2 Release featuring FreeBSD 10.1, strongSwan and AES-GCM for IPsec, Unbound DNS Resolver, and more * Feature #484: Add a warning if users are using non-official package repo * Bug #729: if_bridge unpredictable filter interface selection * Bug #807: Cannot set the keymap to anything other then the default * Feature #973: OpenVPN client in GUI cannot connect to a server requiring username/password * Feature #983: Improve/Enhance IP Alias VIP handling in GUI * Bug #1047: Disable TSO, hardware checksum don't work for unassigned but active interfaces * Bug #1107: mpd on AMD64 generates invalid checksums with NAT * Bug #1359: Optimize reloading of IPsec tunnels * Feature #1361: DNSMasq, source interface and IPSec VPNs * Bug #1399: rrdtool respawning too fast * Bug #1681: OpenVPN tun IPs fail HTTP REFERER checks * Bug #3557: module runfw.ko is missing in 2.2 alpha * Bug #1621: Switching WAN from type PPP to other leaves former port assigned * Bug #3782: ntp/gps serial speed doesn't set * Bug #1629: invalid state table entries after WAN IP change * Feature #1836: RFC 5006 support for DNS from RAs * Bug #1928: Can't sync voucher database when carp peer is also active * Feature #1938: Filter messages broken into multiple syslog messages * Feature #1972: Allow /31 networks to be configured * Bug #1983: Cancel Button generates a Confirm Form Resubmission message * Bug #2073: APIPA broadcasts forwarded by route-to * Todo #2109: pfSense on FreeBSD 10.x * Bug #2121: pfctl -ss output has changed on FreeBSD 10 * Bug #2122: pf log output slightly different in FreeBSD 10 * Bug #2124: Package system updates for FreeBSD 10.x * Bug #2125: Update Package XML for FreeBSD 10.x * Bug #2126: Build package binaries for FreeBSD 10.x * Feature #2129: TCP mss clamping for IPv6 * Feature #2151: Add IPv6 support to the pfSense module * Feature #2295: Allow multiple OpenVPN compression settings (disable, yes, no, adaptive) * Feature #2302: Uploaded Layer 7 patterns not saved in config, backed up, or synced * Feature #2416: Hybrid NAT mode that is a mix of Auto+Manual * Bug #2421: Filter log parser misinterprets some rare lines resulting in TCP:lo for the proto/flags * Bug #2495: pfsense doesn't seem to know what its WAN IP is * Feature #2501: Add no-sync option for firewall rules * Bug #2514: static routes for monitor IPs should be removed * Todo #2565: Update code for PHP 5.4, fix pass-by-reference * Bug #2610: Whole-disk gmirror may break when upgraded to a FreeBSD 10.x base * Feature #2715: Don't reactivate CARP until I manually do it * Bug #2665: 'pass out' on gif matches inbound traffic * Bug #2706: Padlock may need some adjustments for FreeBSD 10.x * Bug #2786: Setting MTU on VLAN does not set MTU on parent interface in 2.2 * Bug #3568: DynDNS: Hostname '@' not accepted for Namecheap * Bug #2833: Add a knob to prefer IPv4 over IPv6 for rare situations that require it * Feature #2847: Add a checkbox to flag a gateway as "down" * Feature #2849: IKEv2 support for IPsec * Bug #2882: 6RD not working in latest snapshots * Bug #2984: IPSec adds route but isn't needed any more * Feature #2986: Turkish Language Import For Next Snapshots * Feature #2989: Changing language english to turkish not effect * Bug #2993: IPsec in transport mode, tunneled traffic does not flow through enc0 * Feature #3018: Can't disable autogenerate SPD rules * Bug #3122: CP Pass-through MAC entry must deny entering the firewall's own MAC address * Bug #3165: OpenVPN Bridge with Client Specific Override * Bug #3182: VMware vmxnet interfaces are not detected as VLAN capable * Bug #3187: LiveCD boot issue on multicore systems. * Bug #3195: CP MAC allows duplication * Bug #3198: IPSEC, when nating to a different size subnet a invalid natting rule is made. * Bug #3213: Error creating more than 30 limiters * Bug #3219: Forwarded domain with underscore should be allowed to add * Bug #3237: "Revoked" status is incorrect for certificates that are different but share the same descriptive name. * Bug #3281: In certain cases, GRE interfaces are missing the "RUNNING" flag at bootup and will not function * Bug #3297: IPsec log parsing code does not skip disabled Phase 1 entries * Bug #3298: Package type tabs on 2.2 should have a default 'all' tab * Feature #3327: Allow reordering of 1:1 NAT entries * Feature #3328: Allow reordering of IPsec Phase 1 and Phase 2 entries * Todo #3338: Update racoon.conf "remote" syntax * Feature #3339: Add a button to allow downloading the Captive Portal HTML text, error text, and logout page text * Feature #3341: Add a means for reverting GUI auth backend to Local Database from the console * Bug #3347: Certificate Authority SAN names not working in 2.1 * Bug #3350: Disabling and enabling VLAN leaves VLAN interface missing * Bug #3353: Changing IPv6 from None to DHCP6 or vice-versa causes a panic+reboot * Bug #3354: Savecore error during bootup * Bug #3361: DHCP6 WAN is not obtaining a default gateway * Feature #3362: Add a means to reset CP HTML/Error Page/Logout Page to default * Feature #3365: Implement package signing * Bug #3389: GUI allows to configure ICMPv4 types for ICMPv6 firewall rules * Todo #3396: Replace dnsmasq with Unbound * Todo #3399: Implement a replacement for base nsupdate command for RFC2136 Dynamic DNS * Bug #3401: Openvpn Server IPV4 generating attribute TUN-IPV6 this right? * Feature #3413: CARP interface names in WebGUI * Bug #3417: racoon crashes after mobile xauth login with fourth DNS server configured * Bug #3437: web redirector doesn't listen on IPv6 port 80 * Bug #3469: rc.update_urltables can skip doing a required update * Bug #3482: Initial Setup disables WAN * Feature #3490: Update DHCP options for network booting with UEFI * Bug #3491: Improper input validation on firewall rules when using a numerical alias name * Bug #3558: Schedule States in System - Advanced - Misc not working * Bug #3498: Wake on Lan Widget no auth needed * Bug #3501: sanity check for PBI installations before uninstalling old pbi package. * Bug #3503: E-Mail Reports syslog error: "rrdcolors.inc.php for theme does not exist" (and proposed fix) * Feature #3515: Windows OpenVPN clients require register-dns to properly use a DNS server set by Pfsense * Bug #3517: VPN re * Feature #3522: Option to set CARP interfaces to 'maintenance mode', persisting through a reboot so the primary machines stays as backup/inactive * Bug #3535: Selecting "LAN" as "WAN" in Multi-WAN Traffic Shaper wizard breaks the ruleset * Bug #3537: Bandwidth values are forced by the Traffic Shaper Wizard but are not required nor used for PRIQ * Bug #3540: 100% CPU-Issue when IPv6 DHCP with stateless addresses is active * Bug #3542: cert_get_issuer() in certs.inc doesn't always return the full Distinguished Name * Bug #3550: [IPv6] wizard not pointing to the right IPv6 address after first setup. * Bug #3554: apinger and OpenVPN: Gateway down after OpenVPN client service restart * Bug #3562: Wireless Radius Setup Fails - partially due to empty config strings * Bug #3573: tun/tap interfaces not available for assignment in 2.2 * Bug #3575: OPT interfaces on GRE tunnels do not accept IPv6 or IPv4 addresses to be set. * Bug #3576: Console upgrade automatically skips hash check if no hash file found * Bug #3579: Limiter rules causing syntax errors * Feature #3589: OpenVPN client: GUI option for "route-nopull" * Bug #3593: pfSsh.php playback gitsync master not working on 2.2 ALPHA * Bug #3594: Captive portal inconsistancy - "Allowed IP addresses" vs "Allowed Hostnames" * Bug #3596: OpenVPN being passed bad arguments * Feature #3599: missing kernel option / kernel module in 2.2 (mount_nullfs) * Bug #3601: Assigning a PPP Interface failed * Bug #3611: DHCP relay to a server behind the gateway does not work * Bug #3612: Packages through proxy doesn't work since change to HTTPS * Bug #3613: Remote syslog server gets added to " DHCP service events" without being checked. * Bug #3614: dhcpd: send_packet: No buffer space available * Bug #3615: /etc/rc.d/*.sh start" is executed during bootup, but equivalent "stop" cmd is never issued during shutdown * Bug #3619: ipfw/dummynet not always loaded when required in 2.2 * Bug #3620: Saving unbound settings twice in a row yields incorrect interface selection validation errors * Bug #3621: Editing an IPsec Phase 1 creates a new Phase 1 instead * Bug #3662: "Provide a list of accessible networks to clients" is not working * Bug #3629: URL alias update process hangs waiting for lock * Todo #3632: Move to sqlite3 php module * Feature #3633: OpenVPN client's "Client Certificate" should be optional * Bug #3637: Incorrect interface matching on bridge edit page * Bug #3639: Captive portal crash when paackets come * Bug #3644: rc.expireaccounts expires every expired account every time it runs * Bug #3647: Serial console input is sent to system log as kernel messages * Bug #3661: xauth user is not displayed in IPsec status * Bug #3648: Filter logs broken on amd64, working on i386 * Bug #3649: IPv6 Gateway is not functioning when using DHCPv6 * Bug #3650: IP aliases are configured even when an interface is disabled * Bug #3654: Outbound IPsec rules do not exclude WAN subnet * Bug #3655: 127.0.0.1 shouldn't be used in resolv.conf if dnsmasq not binding there * Bug #3657: Web Interface - Missing Static IPv6 /127 Subnet Prefix * Bug #3663: Filter parser does not display ICMP log messages * Bug #3664: "IPsec" not displayed in firewall log interface column * Bug #3665: IPsec tunnel description not displayed on status output * Bug #3666: PMTUD is broken for NATed traffic * Bug #3674: Subnet options do not activate on manual outbound NAT rule edit page * Bug #3675: pfPorts failed builds on RELENG_2_2 * Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900 * Bug #3680: disabling an interface which is part of an interface group puts another (arbitrary) interface into the group instead * Bug #3690: php-fpm blocks (stops the boot, prevents webgui startup, etc) * Bug #3689: Filter logs Input Validation Failure * Bug #3927: Unable to set gif MTU * Bug #3691: Fetch error on HTTPS console update by URL * Bug #3692: apinger loss % gets stuck * Bug #3700: pfctl: illegal option -- G * Bug #3702: gif interface assignment removes tunnel's inside IPv6 IPs * Bug #3703: MTU not applied on reboot * Todo #3705: use HTTPS for rc.update_bogons.sh * Bug #3960: deleting or changing phase 2 doesn't remove former P2 * Bug #3712: missing protocols in NAT edit page * Bug #3713: Gateways missing for OpenVPN server (shared key or /30s) * Bug #3714: Session cookie inconsistent behavior when switching GUI protocols * Todo #3715: Change default serial speed to 115200 * Bug #3717: Adding an IPv6 rule on an interface with IPv6 gateway does not add "reply-to" in the resulting rule - fix proposal attached * Bug #4177: Bug in OpenVPN user/pass auth * Bug #3724: Jumbo frames not being honoured with vmxnet3 driver * Bug #3725: Firewall Logs Widget Filters Not Working * Bug #3727: PPP config loses "on-demand" setting when configured via interfaces tab * Bug #3728: Cancel Button Doesn't Work - Firewall Aliases Edit * Bug #3745: VLANs are not ALTQ capable on 2.2 (missing patches?) * Bug #3746: Firewall hostname being reset by DHCP WAN client * Bug #3747: Route uses wrong interface (lo0) when tun local and remote are the same * Bug #3748: Interface in extended down state, not functional when link is brought back up * Bug #3749: Upgrade from 2.1.4 to 2.2 does not automatically reboot * Bug #3750: Console auto login is not setup properly on upgrade from 2.1.4 to 2.2 * Bug #3757: Minicron process inexplicaly terminated * Bug #3760: reply-to with TCP and IPv6 generates broken checksums * Bug #3769: Only the first phase 2 entry is used when multiple entries are present for an IPsec tunnel in 2.2 * Bug #3770: Some drivers not being built with altq support * Bug #3773: Can't add an IP alias on lo0 through the web GUI in 2.2 * Bug #3775: Installer installs incorrect gettytab/ttys * Bug #3777: User with "WebCfg - Help pages " permission listed first gets a bogus redirect * Bug #3781: strongswan dpdtimeout value not generated correctly * Bug #3785: strongswan config being generated with ike SA lifetime set to value of ipsec SA lifetime * Bug #3789: rc.update_bogons.sh and login shell ignore http proxy settings * Bug #3790: Input validation is too strict for IPv6 Prefix ID for Track Interface * Todo #3795: Update hostapd to support 802.11n * Bug #3797: DHCP server restarted multiple times on secondary after config sync * Bug #3809: IPsec Save Xauth Password no longer work * Bug #3800: Disable source port rewriting - Auto created rule LAN to WAN missing? * Bug #3801: Captive Portal on 2.2 does not pass through logged-in users * Bug #3807: Unable to edit existing Virtual IPs * Bug #3811: IP aliases on CARP w/IPsec getting mixed up on addition of a new VLAN. * Bug #3812: IPSec validation should prevent phase2 policies(subnets) to include remote peer on it * Bug #3813: DNS Server override with PPPoE doesn't work in 2.2 * Bug #3817: Missing call to preg_quote at pkg-utils.inc:295 * Bug #3822: 2.2 boot hangs at "Synchronizing user settings" * Bug #3823: diag_ipsec.php fails with PSK+Xauth mobile client connected * Bug #3825: Rejected traffic shown as blocked in firewall log * Bug #3826: 2.2 diag_ipsec.php issues * Bug #3829: Widget Firewall: Reverse Resolve with DNS Issues * Feature #3832: change default update URL to https * Bug #3833: DHCP "release" action can be triggered via GET, should only be via POST * Bug #3857: is_port() validate a wrong port range * Bug #3840: Disable (or give the option to disable) the OS addition to the SSH daemon banner * Bug #3842: Verdana font from the Linux package ttf-mscorefonts-installer causes rendering issues with pfSense WebGUI * Bug #3846: Adding interface for new VLAN selects active WAN VIP address breaking connectivity * Bug #3848: enabling schedule on 2.1.5 causes page fault * Bug #3852: IGMPPROXY still spamming the main systemlog * Bug #3853: DHCP Server failover_peerip is not synchronized on 2.2 with CARP * Bug #3854: pf on 2.2 should not have an upper table entry limit, but generates errors with large datasets * Bug #3856: Delete a user, edit another one and going back... delete the edited user * Bug #3863: Supermicro IPMI Boot virtual CD-ROM * Bug #3864: /diag_dump_states.php has duplicate