# 2.2 Release featuring FreeBSD 10.1, strongSwan and AES-GCM for IPsec, Unbound DNS Resolver, and more * Feature #484: Add a warning if users are using non-official package repo * Bug #729: if_bridge unpredictable filter interface selection * Bug #807: Cannot set the keymap to anything other then the default * Feature #973: OpenVPN client in GUI cannot connect to a server requiring username/password * Feature #983: Improve/Enhance IP Alias VIP handling in GUI * Bug #1047: Disable TSO, hardware checksum don't work for unassigned but active interfaces * Bug #1107: mpd on AMD64 generates invalid checksums with NAT * Bug #1359: Optimize reloading of IPsec tunnels * Feature #1361: DNSMasq, source interface and IPSec VPNs * Bug #1399: rrdtool respawning too fast * Bug #1681: OpenVPN tun IPs fail HTTP REFERER checks * Bug #3557: module runfw.ko is missing in 2.2 alpha * Bug #1621: Switching WAN from type PPP to other leaves former port assigned * Bug #3782: ntp/gps serial speed doesn't set * Bug #1629: invalid state table entries after WAN IP change * Feature #1836: RFC 5006 support for DNS from RAs * Bug #1928: Can't sync voucher database when carp peer is also active * Feature #1938: Filter messages broken into multiple syslog messages * Feature #1972: Allow /31 networks to be configured * Bug #1983: Cancel Button generates a Confirm Form Resubmission message * Bug #2073: APIPA broadcasts forwarded by route-to * Todo #2109: pfSense on FreeBSD 10.x * Bug #2121: pfctl -ss output has changed on FreeBSD 10 * Bug #2122: pf log output slightly different in FreeBSD 10 * Bug #2124: Package system updates for FreeBSD 10.x * Bug #2125: Update Package XML for FreeBSD 10.x * Bug #2126: Build package binaries for FreeBSD 10.x * Feature #2129: TCP mss clamping for IPv6 * Feature #2151: Add IPv6 support to the pfSense module * Feature #2295: Allow multiple OpenVPN compression settings (disable, yes, no, adaptive) * Feature #2302: Uploaded Layer 7 patterns not saved in config, backed up, or synced * Feature #2416: Hybrid NAT mode that is a mix of Auto+Manual * Bug #2421: Filter log parser misinterprets some rare lines resulting in TCP:lo for the proto/flags * Bug #2495: pfsense doesn't seem to know what its WAN IP is * Feature #2501: Add no-sync option for firewall rules * Bug #2514: static routes for monitor IPs should be removed * Todo #2565: Update code for PHP 5.4, fix pass-by-reference * Bug #2610: Whole-disk gmirror may break when upgraded to a FreeBSD 10.x base * Feature #2715: Don't reactivate CARP until I manually do it * Bug #2665: 'pass out' on gif matches inbound traffic * Bug #2706: Padlock may need some adjustments for FreeBSD 10.x * Bug #2786: Setting MTU on VLAN does not set MTU on parent interface in 2.2 * Bug #3568: DynDNS: Hostname '@' not accepted for Namecheap * Bug #2833: Add a knob to prefer IPv4 over IPv6 for rare situations that require it * Feature #2847: Add a checkbox to flag a gateway as "down" * Feature #2849: IKEv2 support for IPsec * Bug #2882: 6RD not working in latest snapshots * Bug #2984: IPSec adds route but isn't needed any more * Feature #2986: Turkish Language Import For Next Snapshots * Feature #2989: Changing language english to turkish not effect * Bug #2993: IPsec in transport mode, tunneled traffic does not flow through enc0 * Feature #3018: Can't disable autogenerate SPD rules * Bug #3122: CP Pass-through MAC entry must deny entering the firewall's own MAC address * Bug #3165: OpenVPN Bridge with Client Specific Override * Bug #3182: VMware vmxnet interfaces are not detected as VLAN capable * Bug #3187: LiveCD boot issue on multicore systems. * Bug #3195: CP MAC allows duplication * Bug #3198: IPSEC, when nating to a different size subnet a invalid natting rule is made. * Bug #3213: Error creating more than 30 limiters * Bug #3219: Forwarded domain with underscore should be allowed to add * Bug #3237: "Revoked" status is incorrect for certificates that are different but share the same descriptive name. * Bug #3281: In certain cases, GRE interfaces are missing the "RUNNING" flag at bootup and will not function * Bug #3297: IPsec log parsing code does not skip disabled Phase 1 entries * Bug #3298: Package type tabs on 2.2 should have a default 'all' tab * Feature #3327: Allow reordering of 1:1 NAT entries * Feature #3328: Allow reordering of IPsec Phase 1 and Phase 2 entries * Todo #3338: Update racoon.conf "remote" syntax * Feature #3339: Add a button to allow downloading the Captive Portal HTML text, error text, and logout page text * Feature #3341: Add a means for reverting GUI auth backend to Local Database from the console * Bug #3347: Certificate Authority SAN names not working in 2.1 * Bug #3350: Disabling and enabling VLAN leaves VLAN interface missing * Bug #3353: Changing IPv6 from None to DHCP6 or vice-versa causes a panic+reboot * Bug #3354: Savecore error during bootup * Bug #3361: DHCP6 WAN is not obtaining a default gateway * Feature #3362: Add a means to reset CP HTML/Error Page/Logout Page to default * Feature #3365: Implement package signing * Bug #3389: GUI allows to configure ICMPv4 types for ICMPv6 firewall rules * Todo #3396: Replace dnsmasq with Unbound * Todo #3399: Implement a replacement for base nsupdate command for RFC2136 Dynamic DNS * Bug #3401: Openvpn Server IPV4 generating attribute TUN-IPV6 this right? * Feature #3413: CARP interface names in WebGUI * Bug #3417: racoon crashes after mobile xauth login with fourth DNS server configured * Bug #3437: web redirector doesn't listen on IPv6 port 80 * Bug #3469: rc.update_urltables can skip doing a required update * Bug #3482: Initial Setup disables WAN * Feature #3490: Update DHCP options for network booting with UEFI * Bug #3491: Improper input validation on firewall rules when using a numerical alias name * Bug #3558: Schedule States in System - Advanced - Misc not working * Bug #3498: Wake on Lan Widget no auth needed * Bug #3501: sanity check for PBI installations before uninstalling old pbi package. * Bug #3503: E-Mail Reports syslog error: "rrdcolors.inc.php for theme does not exist" (and proposed fix) * Feature #3515: Windows OpenVPN clients require register-dns to properly use a DNS server set by Pfsense * Bug #3517: VPN re * Feature #3522: Option to set CARP interfaces to 'maintenance mode', persisting through a reboot so the primary machines stays as backup/inactive * Bug #3535: Selecting "LAN" as "WAN" in Multi-WAN Traffic Shaper wizard breaks the ruleset * Bug #3537: Bandwidth values are forced by the Traffic Shaper Wizard but are not required nor used for PRIQ * Bug #3540: 100% CPU-Issue when IPv6 DHCP with stateless addresses is active * Bug #3542: cert_get_issuer() in certs.inc doesn't always return the full Distinguished Name * Bug #3550: [IPv6] wizard not pointing to the right IPv6 address after first setup. * Bug #3554: apinger and OpenVPN: Gateway down after OpenVPN client service restart * Bug #3562: Wireless Radius Setup Fails - partially due to empty config strings * Bug #3573: tun/tap interfaces not available for assignment in 2.2 * Bug #3575: OPT interfaces on GRE tunnels do not accept IPv6 or IPv4 addresses to be set. * Bug #3576: Console upgrade automatically skips hash check if no hash file found * Bug #3579: Limiter rules causing syntax errors * Feature #3589: OpenVPN client: GUI option for "route-nopull" * Bug #3593: pfSsh.php playback gitsync master not working on 2.2 ALPHA * Bug #3594: Captive portal inconsistancy - "Allowed IP addresses" vs "Allowed Hostnames" * Bug #3596: OpenVPN being passed bad arguments * Feature #3599: missing kernel option / kernel module in 2.2 (mount_nullfs) * Bug #3601: Assigning a PPP Interface failed * Bug #3611: DHCP relay to a server behind the gateway does not work * Bug #3612: Packages through proxy doesn't work since change to HTTPS * Bug #3613: Remote syslog server gets added to " DHCP service events" without being checked. * Bug #3614: dhcpd: send_packet: No buffer space available * Bug #3615: /etc/rc.d/*.sh start" is executed during bootup, but equivalent "stop" cmd is never issued during shutdown * Bug #3619: ipfw/dummynet not always loaded when required in 2.2 * Bug #3620: Saving unbound settings twice in a row yields incorrect interface selection validation errors * Bug #3621: Editing an IPsec Phase 1 creates a new Phase 1 instead * Bug #3662: "Provide a list of accessible networks to clients" is not working * Bug #3629: URL alias update process hangs waiting for lock * Todo #3632: Move to sqlite3 php module * Feature #3633: OpenVPN client's "Client Certificate" should be optional * Bug #3637: Incorrect interface matching on bridge edit page * Bug #3639: Captive portal crash when paackets come * Bug #3644: rc.expireaccounts expires every expired account every time it runs * Bug #3647: Serial console input is sent to system log as kernel messages * Bug #3661: xauth user is not displayed in IPsec status * Bug #3648: Filter logs broken on amd64, working on i386 * Bug #3649: IPv6 Gateway is not functioning when using DHCPv6 * Bug #3650: IP aliases are configured even when an interface is disabled * Bug #3654: Outbound IPsec rules do not exclude WAN subnet * Bug #3655: 127.0.0.1 shouldn't be used in resolv.conf if dnsmasq not binding there * Bug #3657: Web Interface - Missing Static IPv6 /127 Subnet Prefix * Bug #3663: Filter parser does not display ICMP log messages * Bug #3664: "IPsec" not displayed in firewall log interface column * Bug #3665: IPsec tunnel description not displayed on status output * Bug #3666: PMTUD is broken for NATed traffic * Bug #3674: Subnet options do not activate on manual outbound NAT rule edit page * Bug #3675: pfPorts failed builds on RELENG_2_2 * Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900 * Bug #3680: disabling an interface which is part of an interface group puts another (arbitrary) interface into the group instead * Bug #3690: php-fpm blocks (stops the boot, prevents webgui startup, etc) * Bug #3689: Filter logs Input Validation Failure * Bug #3927: Unable to set gif MTU * Bug #3691: Fetch error on HTTPS console update by URL * Bug #3692: apinger loss % gets stuck * Bug #3700: pfctl: illegal option -- G * Bug #3702: gif interface assignment removes tunnel's inside IPv6 IPs * Bug #3703: MTU not applied on reboot * Todo #3705: use HTTPS for rc.update_bogons.sh * Bug #3960: deleting or changing phase 2 doesn't remove former P2 * Bug #3712: missing protocols in NAT edit page * Bug #3713: Gateways missing for OpenVPN server (shared key or /30s) * Bug #3714: Session cookie inconsistent behavior when switching GUI protocols * Todo #3715: Change default serial speed to 115200 * Bug #3717: Adding an IPv6 rule on an interface with IPv6 gateway does not add "reply-to" in the resulting rule - fix proposal attached * Bug #4177: Bug in OpenVPN user/pass auth * Bug #3724: Jumbo frames not being honoured with vmxnet3 driver * Bug #3725: Firewall Logs Widget Filters Not Working * Bug #3727: PPP config loses "on-demand" setting when configured via interfaces tab * Bug #3728: Cancel Button Doesn't Work - Firewall Aliases Edit * Bug #3745: VLANs are not ALTQ capable on 2.2 (missing patches?) * Bug #3746: Firewall hostname being reset by DHCP WAN client * Bug #3747: Route uses wrong interface (lo0) when tun local and remote are the same * Bug #3748: Interface in extended down state, not functional when link is brought back up * Bug #3749: Upgrade from 2.1.4 to 2.2 does not automatically reboot * Bug #3750: Console auto login is not setup properly on upgrade from 2.1.4 to 2.2 * Bug #3757: Minicron process inexplicaly terminated * Bug #3760: reply-to with TCP and IPv6 generates broken checksums * Bug #3769: Only the first phase 2 entry is used when multiple entries are present for an IPsec tunnel in 2.2 * Bug #3770: Some drivers not being built with altq support * Bug #3773: Can't add an IP alias on lo0 through the web GUI in 2.2 * Bug #3775: Installer installs incorrect gettytab/ttys * Bug #3777: User with "WebCfg - Help pages " permission listed first gets a bogus redirect * Bug #3781: strongswan dpdtimeout value not generated correctly * Bug #3785: strongswan config being generated with ike SA lifetime set to value of ipsec SA lifetime * Bug #3789: rc.update_bogons.sh and login shell ignore http proxy settings * Bug #3790: Input validation is too strict for IPv6 Prefix ID for Track Interface * Todo #3795: Update hostapd to support 802.11n * Bug #3797: DHCP server restarted multiple times on secondary after config sync * Bug #3809: IPsec Save Xauth Password no longer work * Bug #3800: Disable source port rewriting - Auto created rule LAN to WAN missing? * Bug #3801: Captive Portal on 2.2 does not pass through logged-in users * Bug #3807: Unable to edit existing Virtual IPs * Bug #3811: IP aliases on CARP w/IPsec getting mixed up on addition of a new VLAN. * Bug #3812: IPSec validation should prevent phase2 policies(subnets) to include remote peer on it * Bug #3813: DNS Server override with PPPoE doesn't work in 2.2 * Bug #3817: Missing call to preg_quote at pkg-utils.inc:295 * Bug #3822: 2.2 boot hangs at "Synchronizing user settings" * Bug #3823: diag_ipsec.php fails with PSK+Xauth mobile client connected * Bug #3825: Rejected traffic shown as blocked in firewall log * Bug #3826: 2.2 diag_ipsec.php issues * Bug #3829: Widget Firewall: Reverse Resolve with DNS Issues * Feature #3832: change default update URL to https * Bug #3833: DHCP "release" action can be triggered via GET, should only be via POST * Bug #3857: is_port() validate a wrong port range * Bug #3840: Disable (or give the option to disable) the OS addition to the SSH daemon banner * Bug #3842: Verdana font from the Linux package ttf-mscorefonts-installer causes rendering issues with pfSense WebGUI * Bug #3846: Adding interface for new VLAN selects active WAN VIP address breaking connectivity * Bug #3848: enabling schedule on 2.1.5 causes page fault * Bug #3852: IGMPPROXY still spamming the main systemlog * Bug #3853: DHCP Server failover_peerip is not synchronized on 2.2 with CARP * Bug #3854: pf on 2.2 should not have an upper table entry limit, but generates errors with large datasets * Bug #3856: Delete a user, edit another one and going back... delete the edited user * Bug #3863: Supermicro IPMI Boot virtual CD-ROM * Bug #3864: /diag_dump_states.php has duplicate
element * Bug #3866: firewall log filtering * Bug #3870: re(4) NICs on APU are unable to hardcode speed/duplex properly * Todo #3874: Make miniupnpd config syntax compatible with new versions * Bug #3876: pfsync is not synchronizing states on 2.2 * Bug #3879: Unable to move widgets in GUI * Todo #3880: Write upgrade code for unbound * Bug #3884: Restarting Web GUI does not restart PHP-FPM * Bug #3886: (TurkishLanguage) After the firewall rule for example (lan rule) does not come "Apply Button" * Bug #3890: Aliases multiple CIDR ranges show error message * Bug #3891: ipfw, on pfSense 2.2 kernel dump caused by: ipfw zone 4096 create * Todo #3893: Alias -> IP * Bug #3894: OpenVPN client started multiple times when connecting to FQDN where connectivity to server is delayed * Bug #3904: Firewall Log widget generates a load of HTML code when Reverse DNS resolution is clicked * Bug #3909: carp_status.php shows disabled after initial config when it really isn't * Bug #3910: Cannot set advskew back to 0 * Bug #3912: Dynamic DNS disallows valid character in username * Bug #3913: if_bridge missing ALTQ support * Bug #3917: Mobile IPsec status page issues * Bug #3918: On 2.2, mounting read-only after mounting read-write can be very slow on certain media NanoBSD * Bug #3919: carp vhid=255 * Bug #3921: max-packets option missing from pfctl * Bug #3922: jumbo frames on lagg not working * Bug #3931: Using international characters in IPsec PSK causes invalid XML * Bug #3935: Unable to complete NIC assignment with only one NIC * Bug #3937: Interfaces Dashboard Widget - Font to big and scaling wrong * Bug #3938: Captive Portal PHP Error at bootup on current snapshots * Bug #3939: Cannot create Host or Network type alias with an IP address/range * Bug #3940: check_reload_status uses deprecated libevent-1.4 * Bug #3941: adding a DHCP client interface results in missing default gateway on 2.2 * Bug #3944: git fatal errors are not shown to user when building pfSense iso from source. * Bug #3947: "ipsec_starter: Bad file descriptor" spams system log * Bug #3949: Dynamic DNS public IP check always uses default gateway * Bug #3961: only first of multiple P2s works in 2.2 * Bug #3950: Entering a backwards IP range in an Alias results in an Internal Server Error * Bug #3951: Processes like filterdns and ipfw-classifyd accumulate many open file handles * Bug #3955: IPsec dashboard widget needs adapting for 2.2 * Bug #3957: 2.2 tap missing ALTQ * Todo #3958: test 2.2 upgrade scenarios * Bug #3964: Web interface fails to load on first boot * Bug #3966: OpenVPN crashes with AES-NI + AES-CBC * Bug #3967: Need to restore IP aliases on CARP IPs in 2.2 * Bug #3968: Incorrect gateway is assumed when using tun + topology subnet * Bug #3969: apinger configuration for DHCPv6 gateway is missing interface scope on source IP and target * Bug #3970: some files not removed on upgrade to 2.2 * Bug #3974: DNS Resolver: Advanced - Error in description * Bug #3976: VLAN Interfaces on LAGG get orphaned on LAGG change * Bug #3980: wrong static routes added for remote P2 subnets * Bug #3981: strongswan "gets crazy" after a few reloads, wipes SAD and doesn't remove old SPD * Bug #3982: Installer generates errors when selecting "Embedded" but still appears to work * Bug #3984: system booted with DHCP client NIC unplugged never kicks off dhclient * Bug #3987: not possible to have both IKEv1 and IKEv2 mobile P1s * Bug #3989: DNS Resolver interface drop downs need enlarged * Bug #3990: pfSense_ipfw_getTablestats issue * Bug #3991: /etc MFS on 2.2 Netgate build memstick image runs out of space * Bug #3992: The password confirmation field is not properly formatted at VPN: L2TP: User: Add/Edit * Bug #3995: Site-to-site VPN not working on IKEv2 * Bug #3998: Duplicated limiter numbers * Bug #3999: SRC, GW wrong in pftop on 2.2 * Bug #4000: guess_interface_from_ip parses netstat output that may be truncated * Bug #4001: disconnected CP client no longer gets redirected to portal page * Bug #4002: 0.0.0.0 shown as being in ipfw tables for CP where it isn't * Bug #4003: SSH host keys regenerated post-2.2 upgrade * Bug #4004: CARP on HyperV * Bug #4005: There were error(s) loading the rules: rules.debug:11 * Bug #4006: diag_gmirror.php missing new blank disk as available consumer * Bug #4007: "Last activity" in CP status blank * Bug #4008: dhcpleases doesn't restart when change from/to dnsmasq and unbound * Bug #4009: Selecting "Embedded" during install does not activate the serial console in a persistent way on amd64 * Bug #4011: Integration between unbound and dhcp is not working * Bug #4012: dnsmasq doesn't listen on chosen CARP IPs * Bug #4013: DHCP6 static bindings not included in /var/unbound/host_entries.conf * Bug #4014: Unbound private reverse lookup domain overrides not working * Bug #4015: IKE version change needs javascript to update other available fields * Bug #4018: several packages not looking in pbi dir for files * Bug #4019: clean 2.2 install doesn't have /usr/local/etc/rc.d/ directory * Bug #4020: Unbound not compiled with libevent * Bug #4022: Unbound doesn't set 127.0.0.1 in resolv.conf * Bug #4023: allowed networks in Unbound inadequate * Bug #4025: package service starting issues post-package reinstall * Bug #4027: Unbound host overrides not being implemented * Bug #4036: Unbound bails with "fatal error: Could not read config file: /unbound.conf" * Bug #4037: delete missing from SAD and SPD screens * Bug #4039: IPsec does not install anymore LAN SPDs * Bug #4040: gateway monitoring issues with multiple PPPoE with same gateway * Bug #4052: vpn_ipsec_settings.php missing input validation * Bug #4042: AES-GCM should not be an option in P1 * Bug #4043: ipsec_dump_sad has issues with IKEv2 * Bug #4045: IPsec dashboard widget status incorrect * Bug #4047: address family check on dynamic gateways incorrect * Bug #4048: cosmetic-only RRD error in logs on nano during boot * Bug #4049: dashboard PHP warnings * Bug #4050: Unbound advanced page missing input validation * Bug #4051: Not assigning v6 DNS when Unbound is enabled * Feature #4053: Make backup of RRD more efficient on using /var disk space * Bug #4056: IKEv2 rekeying issues * Bug #4064: improper handling of DNS servers by rtsold * Bug #4066: Dynamic DNS updates failing on PPPoE reconnect * Bug #4067: Unbound configuration does not get synchronized to the secondary members of a cluster install * Bug #4069: cookie_test causes false positives in vulnerability scanners * Bug #4070: Vulnerability SSL Weak Ciphers * Bug #4071: IPsec with remote gateway of FQDN missing rightid after boot * Feature #4072: Display installed pkg version even if pkg server not available * Todo #4073: Validate bogon update failure handling * Bug #4074: Status NTP does not display any result if IPv6 Allow is off * Todo #4075: branch RELENG_2_2, update build tools and build servers accordingly * Bug #4076: DNS Forwarder options do not unset during CARP sync * Bug #4080: can't edit setting after factory reset! * Bug #4089: IPsec skips P1s bound to CARP IPs * Bug #4090: unbound advanced settings cause broken unbound.conf file * Bug #4093: Static Routes GUI page mentions rules * Bug #4094: Gateway Status can report Online when gateway is waiting for DHCP * Bug #4095: Unbound config not regenrated on WAN-style interface acquiring IP address * Bug #4099: IP aliases on localhost not config syncing across * Bug #4100: Validation of y/n answers in setlanip console menu * Bug #4104: unbound package configuration migration to 2.2 broken * Bug #4110: interface-group is not set properly on the openvpn interfaces after reboot * Bug #4111: Unbound replies using wrong source IP when bound to * * Bug #4112: ipsec, strongswan (sometimes) needs a 'conn' section with a unique reqid for each phase2 * Bug #4139: IPsec status widget broken * Bug #4115: Services - DHCP/DHCPv6 Server - some advanced options have messed up GUI * Bug #4116: IP Alias VIPs using CARP VIP as their interface are not properly deactivated for temporary CARP disable * Bug #4119: Disable DHCP server when interface is disabled / DHCP relay is checking for disabled interfaces * Bug #4122: webConfiguratorlockout table is missing expiration * Bug #4124: Alias FQDNs don't permit trailing period * Bug #4125: Captive Portal - Portal page contents - View current page has a broken link * Bug #4126: some PSKs incorrect in ipsec.secrets * Bug #4127: CP per-user bandwidth restriction applied when disabled * Bug #4129: IPsec connections with multiple P2s use only first SA * Bug #4130: Status: Dashboard - index.php: XML error: no leases object found! (IPsec Widget) * Bug #4132: Captive Portal - Portal page contents - confusing instructions (gettext issue) * Bug #4134: Email notifications configuration migration to 2.2 broken (STARTTLS) * Bug #4137: IPSec widget - Invalid argument supplied for foreach() in /usr/local/www/widgets/widgets/ipsec.widget.php on line 89 * Bug #4138: Status - IPsec: Description missing on connected tunnels * Bug #4140: Password protect console menu setting not preserved on upgrade * Bug #4141: captive-portal on opt1 interface affects traffic going through other interfaces * Bug #4143: After firmware upgrade it keeps saying "Packages are currently being reinstalled in the background." for no apparent reason. * Bug #4146: OpenVPN tap interfaces are down after boot * Bug #4148: gen_subnet returns incorrect result for IPv6 * Bug #4151: Main page for this section link in services_unbound_host_edit.php is linked to services_dnsmasq.php * Bug #4152: Main page for this section link in services_unbound_domainoverride_edit.php is linked to services_dnsmasq.php * Bug #4157: IPsec route-to/reply-to "pass out" rules mis-route ISAKMP and ESP traffic with remote on same subnet * Bug #4158: IPsec PSK containing " breaks * Bug #4159: 2.2 amd64 nsupdate broken * Bug #4161: Misspelling in privilege "WebCfg - Services - Captiveprotal Zones page" * Bug #4163: upgraded configs missing * Bug #4164: IPsec dashboard status wrong for connections with multiple P2s * Bug #4169: IPsec NAT address to address using nat instead of binat * Bug #4172: Diag Test Port does not allow blank source port * Bug #4174: multi-WAN IPsec uses wrong interface at times * Bug #4180: OpenVPN Backend for authentication field does not process in other languages * Bug #4182: IPsec ipcomp is not supported with strongswan * Bug #4186: VLANs on lagg not configurable with FEC, LB and RR modes * Bug #4188: IPSec SA requestid has limited range in FreeBSD * Bug #4189: url(IPs) alias not loading correctly. * Feature #4190: Support for RFC 3021, using 31-Bit Prefixes on IPv4 Point-to-Point Links * Bug #4192: check_reload_status aggregation of CARP events causes issues * Bug #4202: IPsec - completely broken after last round of changes * Bug #4203: Default loader tunables for DMA and write caching changed on FreeBSD 10.x * Bug #4204: CP leaking resources on reload * Bug #4212: unbound not starting on 12 CPU host * Bug #4213: WebGUI - improper path to icons * Feature #4214: IKEv2 EAP-MSCHAPv2 support * Bug #4223: ip_in_subnet('11.22.33.5','abcd::/64') returns true.. this should not be. * Bug #4236: Call to undefined function filter_configure() in /etc/inc/vpn.inc * Bug #4248: AES-GCM doesn't interoperate with devices not using padding * Bug #4252: radvd not functional with CARP IPs * Bug #4254: Dynamic interface removal/addition breaks IKEv2 * Bug #4257: tap interfaces missing from bridge after boot * Bug #4258: DNS Resolver - auto-added access controls missing IPv6 subnets where "all" interfaces selected * Bug #4046: Invalid access-control.conf entry with certain IPv6 settings * Bug #4041: Default gateway switching logic seems broken * Feature #3129: Enable LEDs on BCM57780 NICs * Bug #3590: Snort package missing * Bug #3645: Many Call-time Pass-by-reference instances in packages need fixed for PHP 5.5 * Bug #3756: PBI package for Snort does not properly configure the barnyard2 support binary * Bug #3772: Broken openbgpd config generation logic in 2.2 * Bug #3972: Avahi daemon doesn't start due to missing folder for requisite dbus-daemon. * Bug #3975: Gateway Monitoring Offline * Todo #4029: Update phpsysinfo package * Bug #3994: sudo package not working on 2.2 * Bug #4016: squid3 amd64 looks to have bad download link * Bug #4017: postfix package looking for /usr/local on pfsense 2.2 * Bug #4032: squid3-dev 3.3.11_1 pkg 2.2.8 doesn't work OOB * Bug #4059: library required by squid3 may be absent * Bug #4078: NUT fails to start with USB * Bug #4114: Squid 3.4.9 transparent proxy broken. * Bug #4144: Current GUI doesn't allow you to select multiple logging severity options