# 2.3.3 2.3.x maintenance release * Bug #2800: OpenVPN doesn't work properly with intermediate/chained CAs * Feature #3151: Disable gateway monitoring actions without disabling gateway monitoring * Bug #3454: Acknowledge all notices is presented to users who do not have privilege * Bug #3560: Disabled Static Route not fully disabled * Bug #3973: Route 53 dynamic DNS provider fails to update record * Feature #4351: Allow to disable BOOTP in DHCP server * Bug #4815: NTP status widget shows truncated IPv6 address * Bug #4820: DHCP Scope at setup * Feature #4898: Allow packages to request syslogd socket to be created inside chroot * Bug #5054: Dynamic DNS - Route53 errors should probably be more verbose * Bug #5321: rxcsum6, txcsum6 not considered by "Disable hardware checksum offload" * Feature #5549: Additional DNS entries in General Setup would be good for 3 or more WAN's * Bug #6064: non-fully qualified hostnames included in hosts file and Unbound local-data * Bug #6153: RFC 2136 Client fails to update more than 1 record * Bug #6224: Firewall NAT Edit forgets dst type selection after reporting input errors * Bug #6227: LAGG MTU not set correctly when it has child QinQ interfaces * Bug #6308: TFTP Proxy can't be turned off * Bug #6357: Dynamic DNS (RFC2136) updates always considered successful * Bug #6391: View Current Portal Page goes to wrong URL * Bug #6432: Relative distinguished names should accept unicode during CA creation. * Bug #6448: Mousing over aliases on disabled rules makes hint difficult to read * Bug #6454: services_ntpd_acls.php: Can't change default options without setting custom access restriction * Bug #6472: Disabling NAT (port forward) rule does not disable the associated firewall rule * Feature #6591: Configurable DDNS check IP services * Bug #6609: OpenVPN Radius auth doesn't send NAS attributes and is not consistent with how strongSwan does it * Feature #6623: Cloudflare DDNS IPv6 support * Bug #6633: redirect-gateway duplicated in client specific overrides * Bug #6634: DHCP Server "TFTP Server" field should allow URLs * Bug #6659: Default routes are not being removed after deletion * Todo #6689: Add enable link to Status > UPnP & NAT-PMP error message if disabled * Bug #6702: Command Prompt syntax error and crash detection report * Bug #6711: diag_states_summary # States and # States twice (explain one is per protocol) * Bug #6712: services_unbound.php Host Overrides don't change any unbound configuration * Bug #6719: OpenVPN DNS Leak Windows 10 * Bug #6732: interfaces_ppps_edit.php: L2TP and PPTP WAN-type interface editing has broken input validation * Bug #6739: OpenVPN compression settings in the GUI are no longer translated into the correct running options. * Bug #6741: /etc/rc.initial does not trap CTRL-C back to console menu but rather to # prompt. * Bug #6751: Route53 DynDNS Problems / Replace Route53 DynDNS Module * Feature #6753: Interfaces list order not consistent * Bug #6779: Traffic shaper wizard uses decimals instead of whole numbers * Feature #6786: Sortable Description Captive Portal MACs list * Bug #6806: Form validation for DHCP NTP Servers does not allow hyphens * Bug #6830: Chelsio T4/T5 CXGBE drivers not loaded as ALTq capable in the PfSense UI * Bug #6833: Wifi channel change applies only on reboot * Bug #6838: bsnmpd logs errors when /etc/printcap is missing * Bug #6840: Upgrade ISC dhcpd to 4.3.5 to address missing hostname workaround * Bug #6849: OpenVPN cipher list output changed, breaking the GUI list of ciphers * Bug #6857: local_sync_accounts fails during boot when using ldap on a non-local network or hostname * Bug #6864: Error checking rejects IPv6 addresses with upper case A-F. * Bug #6869: Diagnostics / Routes Truncates Destination and Gateway Names * Bug #6872: Captive Portal per user bandwidth field no longer accepts 0. * Todo #6889: Improve router mode help text * Bug #6893: Configuration XML is inconsistent with self closing tags * Bug #6895: Moving rules does not scroll * Bug #6898: Suggestion: reword "VPN > IPsec > Tunnels > Edit Phase 1" "Key Exchange version" popup contents * Feature #6899: Can't specify PPTP/L2TP gateway as FQDN * Bug #6903: services_dnsmasq_edit.php: Configuration XML hosts section order appears randomized * Feature #6914: unbound access-control lists * Bug #6915: unbound logging not working after reboot or "Reset log files" * Bug #6916: interfaces_vlan.php: Clicking on "Cancel" deletes VLAN * Bug #6922: Dynamic DNS widget broken with Custom v6 entries * Bug #6927: 1 to 1 NAT allows entry of mixed IP addresses * Bug #6930: DHCP server should be disabled for /31 and /32 * Bug #6931: Status > Filter Reload page is confusingly worded * Bug #6963: SSH Keyboard-Interactive Authentication fails on 2.3.2/2.4 * Bug #6966: Display bug in Status / IPsec / Overview * Bug #6972: "Are you sure you wish to?" prompts and other issues with deleting networks from network-type aliases * Bug #6976: Interface group and alias with same name creates firewall syntax error * Bug #6980: L2TP WAN gateway is missing the type at the end of its dynamic name * Bug #6982: Nested Aliases with FQDNs do not populate parent table in some cases * Bug #6984: NTP/ACLs - Delete button partially invisible + rowhelper handling broken * Bug #6992: ZoneEdit DDNS does not update to CARP IP * Bug #6996: DHCP traffic getting blocked (still/again) with DHCP Relay enabled * Bug #6997: DHCP/DHCPv6 server GUI should be accessible even if DHCP relay is enabled * Bug #7002: OpenVPN unable to use authentication server with ampersand in descriptive name * Bug #7005: IPsec mss clamping not working for mobile clients * Bug #7010: Problem Syncing IP Aliases on Localhost on HA cluster * Bug #7012: scponly shipped with pfSense does not work with Linux scp * Bug #7019: XSS issues in captive portal status pages * Bug #7031: Cannot configure OpenVPN on a DHCP interface that has not received an IP address * Bug #7034: NTP Orphan Mode stratum setting is not displayed in input field * Feature #7051: Allow control of what users can view and/or clear notices * Bug #7043: If user does not have crash_reporter page access the crash reported link is useless * Bug #7045: PHP Shell outputs startup message when running a playback script * Feature #7046: Bring back a method of viewing the gateway status from the shell and status output * Bug #7053: OpenVPN Client Specific Overrides - GUI Omissions and Errors * Bug #7057: Hidden field displays in browser * Feature #7069: Provide knob to disable state display in Diagnostics > States until a filter has been submitted. * Bug #7083: Put back some visual hint for required fields * Bug #7089: Opposite of + or - is occurring when selecting time zone * Bug #7126: Dynamic DNS Widget links for RFC2136 entries are incorrect * Bug #7129: system_advanced_notifications.php - Cannot save settting - growl passwords must match * Bug #7100: pkg_edit.php - $("#showadv").prop('value') not working * Bug #7110: Empty custom NTP ACL produces syntax error in /var/etc/ntpd.conf * Bug #7120: Wrong file permissions on /var/tmp and missing sticky bit when using /var as RAM disk * Bug #7134: Crash in the gui related to widget * Bug #7136: OpenVPN not binding to IP Aliases -> NO LOGS generated * Bug #7139: User with some pages plus Help cannot use page help * Bug #7140: User with page-help-all as first priv is redirected to Dashboard Help * Bug #7141: There is no way to grant just access to Services->UPNP * Feature #7159: Auto correct checksum and missing special characters for NTP GPS initialization commands. * Bug #7164: NTP page allows adding more time server rows than it saves to the configuration * Bug #7173: [2.3.3+] Interface groups with a '-' (dash) in name are not handled correctly, breaking firewall rules * Bug #7180: Disabled OpenVPN clients are not shaded in the gui * Bug #7183: Interface Groups can be entered with the same name * Bug #7225: pkg_mgr_install.php "from" and "to" parameters are not validated or encoded before output * Bug #7226: Package installation message is incomplete * Bug #7227: pkg.php - "pkg_filter" is not encoded before output * Bug #7228: easyrule.php: Use of GET allows rule to be added without CSRF protection * Bug #7230: wizard.php - update_config_field() uses eval to set a value in a way that allows variable protections to be bypassed * Bug #7233: Status DHCP Leases can have incorrect index for edit action * Todo #7246: Sync up status.php on 2.3.3 with 2.4 * Bug #7252: OpenVPN widget, connect time of roadwariors shows a number * Bug #7253: LDAP does no longer properly fallback to local auth, obnoxious timeouts, unusable GUI * Bug #7257: Use pfSense-upgrade to check if there is a new firmware upgrade * Bug #7258: vpn_ipsec_phase1.php: Unable to save Mobile IPsec Phase 1 set for Hybrid RSA + Xauth * Bug #6768: DNS Resolver entry for DHCPv6 static mapping has wrong IP address * Bug #5524: bind package is patching /etc/inc/system.inc (syslog configuration)