# 2.4.4 2.4.x maintenance release * Feature #1933: Support for interface groups in NAT screens * Bug #3124: portal_reply_page called twice in specific circumstance * Feature #3686: Distinguish services when sending authentication request to RADIUS server * Bug #4438: Unable to delete IP Alias outside an interface's subnet where a gateway exists in the same subnet * Feature #5112: LDAP support for Captive Portal * Bug #6237: RADVD, Route Information Option type 24, Multiple IPv6 gateways * Bug #6477: Sample bounds can jump around for custom timer periods on Status > Monitoring * Feature #6620: CoDel, FQ-CoDel, PIE and FQ-PIE AQMs * Bug #7013: Changing group scope to remote does not remove it from group file * Todo #6998: Create a port for simplepie to keep it updated and use modular version * Todo #7024: Replace copy of radius.inc by pear-Auth_RADIUS * Bug #7425: dhclient not sending option 77 * Feature #8737: Let users configure PPPoE multilink over single link * Bug #7532: SG-1000 autonegotiation 10baseT speed and duplex * Bug #7604: Bug #6594 is not resolved: Waiting for Internet connection to update pkg metadata and finish package reinstallation * Feature #7623: Allow L2TP user passwords to contain special characters * Bug #7634: When restoring from USB during install, if the config file contains RRD data, the final config.xml on the system will also contain all the RRD infomation * Feature #7707: Captive Portal - Radius Time out configuration field * Feature #7769: DynDNS: Azure integration, update record in Azure (Dynamic DNS Client) * Bug #7774: No TCP Reply State Established on GRE in IPsec Transport * Bug #7905: OpenVPN Authentication Against Backend Stalls All Server Traffic * Feature #8028: Unbound: Add advanced option for qname-minimization * Feature #8030: Unbound: Add support for DNS over TLS to internal clients * Feature #8187: Gateways, allow for configuring a gatewaygroup as the default gateway. #3781 * Bug #8048: DHCPv6 Configured for LAN without LAN interface * Bug #8071: DNSimple support for Dynamic DNS no longer working * Feature #8101: Filter loop prevention * Bug #8120: Unable to disable DHCP Server on interface when DNS Resolver "DHCP Registration" is enabled * Bug #8138: Option is ignored on interfaces without hwaddr * Feature #8202: Captive portal: add support for setting traffic quotas * Feature #8292: IPsec mobile clients with different (virtual) IP addresses by (EAP) identity * Bug #8539: ACLs not configurable in German Language UI * Feature #8361: Add entered name to captive portal status and logs * Bug #8367: Traffic Graph widget shows Inverse view, even when Inverse is set to Off. * Bug #8540: Disable Rekey Checkbox Should be Disabled on New IPsec Tunnels * Bug #8381: Cert manager requires fields that aren't necessary * Bug #8403: system_advanced_admin.php Uses Incorrect/Inconsistent $config sshdkeyonly References... * Feature #8388: Add DNS over TLS for upstream forwarders to the DNS Resolver * Feature #8402: SSH2 Enforced Key and Username+Password Authentication... * Bug #8557: Unbound ACL Page: Parse error: syntax error, unexpected '{' in /usr/local/www/services_unbound_acls.php on line 126 * Bug #8407: FRR BGP MD5 support is broken * Todo #8411: dnsmasq configuration needs changes for 2.79 * Feature #8418: OCSP Stapling * Bug #8422: Switching VLAN mode removes the switch port settings from the config. * Bug #8583: LDAP fails with bind credentials due to mispelled variable * Bug #8429: radvd/IPv6 broken in 2.4.3 when using a LAN bridge * Feature #8430: Add DNS Resolver status page * Feature #8431: Add DNS over TLS checkbox for Domain Override entries * Bug #8437: invalid outbound nat rules written when using ipv6 rules on interfaces that also have ipv4 adresses.. * Bug #8446: QinQ interfaces are assigned incorrectly * Bug #8477: Gateway latency, units used inconsistently. * Feature #8478: Add DynDNS client for DigitalOcean DNS * Bug #8518: Rule Error On Upgrade 2.4.3 -> 2.4.3-p1 * Bug #8519: pfSense update from the webGUI fails * Bug #8495: /etc/rc.reboot does not work on latest 2.4.4 snapshot * Bug #8497: route errors ("route has not been found") on current 2.4.4 snapshots * Bug #8504: Default gateway missing after upgrade * Bug #8505: adding 2nd limiter overwrites the first one (as of 2.4.4.a.20180510.1452) * Bug #8506: Constant link cycling on some DHCP interfaces causes connectivity problems and other issues * Bug #8507: FreeBSD 11.2-BETA dhclient always uses server MTU value * Bug #8515: ts wizard syntax error (as of 2.4.4.a.20180514.0905) * Bug #8524: HTTP_REFERER issue if changing the LAN IP in setup wizard * Feature #8525: add to status.php * Bug #8527: VLANs losing parent interface on LAGG change * Bug #8530: Delete allowed hostname/ip doesn't work if captive portal is not enabled. * Bug #8534: Invalid DHCP options can be added * Bug #8543: IKE Phase 1 configuration not working * Feature #8544: Routed IPsec using FreeBSD if_ipsec(4) VTI * Feature #8548: User creation is not logged correctly * Bug #8551: Routed IPsec/VTI is unable to communicate from the ipsecX interface address to a routed target * Feature #8552: enable http2 * Bug #8553: Creating a user as a member of a group fails to add that group to the user * Bug #8561: default-route is not always set for a pppoe connection after bootup. * Bug #8563: User with only "WebCfg - Firewall: NAT: Port Forward" cannot view the list of port forwards * Bug #8571: loader.conf/.local cleanup is a bit too aggressive * Bug #8575: IPv6 NPt field order bug? * Bug #8582: Ship RFC 7919-provided DH groups * Bug #8586: Gateway Group trigger level * Bug #8587: System information dashboad show only first swap disk/file info * Bug #8588: Latest installer image does not boot as an ISO * Bug #8591: interfaces.php: Checking "Default Gateway" on the "Add a new Gateway" modal does not set it as default * Bug #8592: Can't "Register DHCP leases in the DNS Resolver" when only using DHCPv6 * Bug #8593: Extend maximum gateway monitoring ping interval * Bug #8594: Assess default crypto settings for OpenVPN/IPsec * Bug #8595: Maybe a new mpd5-x+1 MTU ISSUE WITH ORANGE FR * Feature #8596: Warn user when default password has not been changed * Bug #8597: When editing a firewall rule, the "Action" field is selected * Feature #8598: Add IPsec identifiers to Status > IPsec * Bug #8603: PPP WANs do not work on VLANs on current snapshots * Bug #8604: Race condition in NAT reflection filter rules leads to ruleset load failure * Bug #8605: OpenVPN wizard fails to populate LDAP fields * Bug #8606: system_advanced_admin.php: PHP error when saving without sshdkeyonly set * Bug #8626: CN in certificate and probably other user names are not properly escaped in LDAP search * Bug #8617: Error on RADIUS Authentication * Bug #8627: PHP Warning in /system_groupmanager.php * Bug #8618: 2.4.4 *possible bug* with Intel C3858 and Interface Auto-Detection on 10Gb interfaces * Bug #8621: PHP errors on VPN IPSec P1 add * Bug #8622: system_usermanager.php: Group selections not retained when an input error occurs * Bug #8629: Routed IPsec P1 - not coming up after pressing "disconnect" button * Bug #8630: Web-GUI PHP error in brige after removing all interfaces were in bridge * Feature #8635: "Remote/local subnets" in routed IPsec renaming * Bug #8637: field type select_source returns eval warnings if empty on pkg_edit.php * Bug #8639: Unable to boot zfs on root * Bug #8640: PHP Error * Bug #8680: PHP7: Adding a static gateway on an interface when none are already defined causes errors. * Bug #8643: IPsec not working on latest 2.4.4 snap * Feature #8644: IPsec mobile clients DNS enhancement * Bug #8646: Another php error * Bug #8648: php dynamic dns status widget error * Bug #8653: Spurious HA XMLRPC Sync Error after move to PHP7 * Bug #8655: Radius Accounting updates are not sent in a particular situation * Bug #8656: PHP Error - Firewall Scheduler * Bug #8658: Bridge Route Gateway section shows empty undere OpenVPN settings * Bug #8659: DHCPv6 Server removing a static mapping throws error. * Bug #8660: php undef constant breaks suricata * Bug #8661: Cannot view or edit firewall rules in 2.4.4.a.20180717.1700 * Bug #8663: gw group - php error on opening * Bug #8664: DynamicDNS client does not use custom check IP service * Bug #8667: VU#857035 - IKE Protocol Vulnerability * Bug #8673: Bridge interface php error * Bug #8674: Switching IPsec phase one to vti from Tunnel IPv4 and back yields unexpected behavior * Bug #8675: 2.4.x nightly: Warning: A non-numeric value encountered in /etc/inc/unbound.inc on line 85 * Bug #8678: unexpected error string on web page services_dhcpv6.php * Bug #8679: error in services_router_advertisements.php after clicking on Save button * Bug #8681: PHP7 - Error on login when using RADIUS authentication * Bug #8683: Unable to add GIF interface (Hurricane Electric IPv6) * Feature #8685: Implement some controls to hide certain information for VTI Assigned Interfaces * Feature #8687: Interfaces assigned for OpenVPN/GIF/GRE/Routed IPsec should not present IPv4 and IPv6 settings * Bug #8689: Unbound PHP error * Bug #8704: Load Balancer (relayd) settings are not displayed in gui * Bug #8707: New PHP Error [/etc/inc/gwlb.inc] * Bug #8708: Squidguard > Target categories > Order description typo * Bug #8714: error in services_dhcpv6.php after clicking on Save button in case RA was not setup before enabling DHCPv6 * Bug #8715: System update: Unable to check for updates * Bug #8721: DHCP High Availability - Statis assignement Issue on BackUP machine * Bug #8722: ACB issue after upgreade 2.4.4-DEV 20180728 up to current snap * Bug #8725: Packages not uninstalled when removed from package repo * Bug #8728: Can not create VIP after deleting existed one * Bug #8730: NAT PHP7 errors. * Bug #8732: PHP7 errors in DHCP * Bug #8734: FEC LAGG Protocol option present * Bug #8741: IP Alias and CARP VIP subnet remains set to /128 for IPv4 address * Feature #8742: Remove some legacy code in auth.inc * Bug #8744: Re-configuring an enabled captiveportal cause ipfw to drop all traffic, pfSense_ipfw_tables_list() is to blame (PHP 7 related?) * Bug #8745: Adding a bridge generates a crash report. * Bug #8746: StrongSwan 4.4.0 -> 5.6.2 buffer underflow leading to denial of service - CVE-2018-5388 * Bug #8757: PHP Warning: A non-numeric value encountered in /etc/inc/shaper.inc on line 467 * Bug #8762: PHP OpenSSL CRL patch fails with PHP 7.2 * Todo #8764: Rewrite crash reporter to download files locally rather than upload to a server * Bug #8765: Per-user firewall rules for IPsec do not work * Bug #8766: Improve IPsec encryption and hash warnings * Bug #8767: ID handling problem with DNS Forwarder host override management * Bug #8768: IP Aliases with CARP VIP parent need reinitialized after interface event * Feature #8772: Add GUI option for async crypto * Bug #8782: Custom dyndns issue: username and password is not sent * Bug #8783: Saving Captive Portal Zone removes Captive Portal rules * Feature #8788: Disable compression by default for OpenVPN * Bug #8789: Warning on Captiveportal settings page, following recent changes * Bug #8791: Default IPv6 rules do not allow some devices to perform router or neighbor discovery * Bug #8792: OpenVPN wizard PHP error * Feature #8793: Captive Portal HTML Design and Usability Improvements * Bug #8800: Interface group member cannot be deleted, after it's been disabled * Bug #8801: OpenVPN Wizard, User Manager, Cert Manager will place CA CN in the Country Code field of a Certificate * Bug #8803: PHP errors thrown in traffic shaper wizard multi * Bug #8805: Enabling vouchers on the captive portal voucher page does not regenerate captiveportal login template * Bug #8806: HA sync : Starting captiveportal doesn't fire ipfw rules on slave, even if HA is enabled. * Feature #8812: Add "Select All" to Firewall/NAT rule lists * Bug #8813: User login through proxy only logs proxy IP address, not X-Forwarded-For * Bug #8823: Dashboard Crash * Bug #8816: User login does not record the authentication source * Feature #8817: Display login info in System Information widget * Bug #8822: HTTP_REFERER check fails after changing interface IP address * Bug #8824: is_numeric() on PHP 7 no longer validates hexadecimal values * Bug #8826: PHP7: ACB error at upgrade. * Bug #8834: NAT > NPt address fields do not match the hover text * Bug #8837: PHP error when creating alias URL Table (IPs) * Bug #8838: PHP warning when creating an OpenVPN client with invalid setting * Bug #8842: pfSense-pkg-aws-wizard-php72 sticks during install * Bug #8845: Recompile PHP with a larger value of FD_SETSIZE. * Bug #8850: Packages that start on sync are started multiple times at boot * Todo #8851: Change default CA/Cert action to "Create an internal..." * Bug #8856: IPsec not starting and getting PHP error * Bug #8857: PHP error when saving on vpn_ipsec_settings.php * Bug #8858: IPsec VTI cleanup can accidentally remove valid interfaces * Todo #8860: Change status.php to use "ifconfig -va" for more detail * Bug #8863: amdtemp.ko module failed to load * Bug #8868: multiple php errors on update * Bug #8876: status_gateway_groups.php: PHP error when there is no gateways array * Bug #8877: VTI P2 can trigger an endless loop trying to form a P2 ID * Bug #8880: [PHP7] warning on system_gateways.php and extra item in gateways table * Bug #8889: Setup Wizard PHP error when LAN has no DHCP configuration * Bug #8891: PHP error with an empty CRL * Bug #8892: 2.3.5_2 does not offer update to 2.4.4-RC * Bug #8895: You MUST recompile PHP with a larger value of FD_SETSIZE. It is set to 2048, but you have descriptors numbered at least as high as 2161. * Bug #8905: status_logs_settings.php PHP errors on 2.4.4 snapshots * Bug #8910: DHCP default gateway undefined * Bug #8911: Incorrect pkg repo set when restoring a config. * Bug #8913: system_update_settings.php - PHP Error * Bug #8919: DHCP/DHPv6 Relay PHP Error on Save * Bug #8920: Adding a certificate to the first user (index 0) does not redirect back to user manager * Bug #8750: DNS Rebinding check fails to block IPv6 representation of IPv4 addresses in Unbound * Bug #8726: Lack of input validation on custom GUI/dashboard settings leads to potential XSS * Feature #4294: Add additonal option to RADIUS Called-Station-Id value * Bug #8449: FRR 4.0 zebra daemon crashes * Bug #8620: arpwatch database page is not accessible * Bug #8631: syslog-ng - logrotate incorrectly configured to rotate TLS key * Bug #8647: PHP7: Snort package * Bug #8670: HAProxy PHP error * Bug #8676: PHP7: LCDproc package * Bug #8684: PHP7 can't install pfBlockerNG * Bug #8716: Suricata package does not survive pfSense upgrade. * Bug #8718: PHP Warning: Illegal string offset 'config' in /usr/local/pkg/net-snmp.inc on line 403 * Bug #8754: PHP7: Suricata Package, various php warnings * Bug #8779: PHP7: Cron package. PHP Warnings * Bug #8781: Suricata PHP error in 2.4.4 snapshot * Bug #8785: Fail config authentication on squid * Bug #8790: getting PHP error regarding HAproxy pkg * Bug #8796: Enabling Automatic SID State Management causes php warning * Bug #8797: Visiting Flow/Stream causes a php error to be be shown * Bug #8798: Visiting App Parsers causes a php error to be be shown * Bug #8799: Automatic flowbit resolution setting does not match description * Bug #8828: Keep settings checkbox under Global Settings does not behave as expected * Bug #8829: Keep settings checkbox under Global Settings does not behave as expected * Bug #8600: "snmpd SIOCGIFDESCR (e6000sw0port1): Device not configured"