<?xml version="1.0" encoding="utf-8"?>
<!--RSS generated by Flaimo.com RSS Builder [2013-05-24 05:07:21]-->
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"><channel><docs>http://bugs.endian.com/</docs><link>http://bugs.endian.com/</link><description><![CDATA[MantisBT - Issues]]></description><title>MantisBT - Issues</title><image><title>MantisBT - Issues</title><url>http://bugs.endian.com/images/mantis_logo_button.gif</url><link>http://bugs.endian.com/</link><description><![CDATA[MantisBT - Issues]]></description></image><language>en</language><category>All Projects</category><ttl>10</ttl><dc:language>en</dc:language><sy:updatePeriod>hourly</sy:updatePeriod><sy:updateFrequency>1</sy:updateFrequency><item><title>0004548: Please provide documentation in PDF</title><author></author><link>http://bugs.endian.com/view.php?id=4548</link><description><![CDATA[Online HTML does not print correctly -- exceeds margins.&lt;br /&gt;
&lt;br /&gt;
Copy and paste into Word requires excessive time tryint to reformat.&lt;br /&gt;
&lt;br /&gt;
Request a PDF of the documentation, please.]]></description><category>Documentation</category><pubDate>Thu, 23 May 2013 16:00:13 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4548</guid><comments>http://bugs.endian.com/view.php?id=4548#bugnotes</comments></item><item><title>0004547: HTTP Proxy - (104) Connection reset by peer</title><author></author><link>http://bugs.endian.com/view.php?id=4547</link><description><![CDATA[Kernel version: 2.6.32.43-57.e48.i686.PAE&lt;br /&gt;
&lt;br /&gt;
When HTTP Proxy filter is ON a web page can't be loaded at all (may be the issue will happened with others but I can't say at the moment). Instead, a web page from endian saying &quot;(104) Connection reset by peer&quot; appeares. When I turn the HTTP proxy off I can successfully load the web page in question. The problematic web page is - &lt;a href=&quot;http://www.minfin.bg&quot;&gt;http://www.minfin.bg.&lt;/a&gt; [&lt;a href=&quot;http://www.minfin.bg&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;] &lt;br /&gt;
The issue arisen regardless of the browser. &lt;br /&gt;
&lt;br /&gt;
Thank you in advance.]]></description><category>Application Level Proxies</category><pubDate>Tue, 21 May 2013 17:33:09 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4547</guid><comments>http://bugs.endian.com/view.php?id=4547#bugnotes</comments></item><item><title>0004374: Installation of Endian Firewall from USB flash drive fails</title><author></author><link>http://bugs.endian.com/view.php?id=4374</link><description><![CDATA[When trying to install EFW 2.5.1 from an USB flash drive, the installation fails before the first user input is required.&lt;br /&gt;
The system is booting the vmlinuz which is located on the USB drive. After that the /etc/inittab from instroot.gz is read and /bin/installer is executed. This installer file runs in an endless loop and the VGA display flashes blue/black.&lt;br /&gt;
&lt;br /&gt;
Yes, I double-checked the MD5 checksums on the EFW installation ISO file.]]></description><category>Installation</category><pubDate>Fri, 17 May 2013 00:23:00 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4374</guid><comments>http://bugs.endian.com/view.php?id=4374#bugnotes</comments></item><item><title>0004472: SIP Proxy Endian 2.5.1</title><author></author><link>http://bugs.endian.com/view.php?id=4472</link><description><![CDATA[Endian 2.5.1 rewrites sip packets exiting tap1 with the IP to main interface. It also makes the changes inside the SIP packet which makes me believe there is some sort of SIP proxy action. The problem is I cannot find a sip proxy installed and this was a fresh install of Endian 2.5.1 not an upgrade. Is there some daemon running in the back that does these rewrites? Please see attached wire shark sniff. I have removed public IP information. Please note this capture was taken issuing the command: &quot;tcpdump -s 0 -i tap1 -w tap1.pcap&quot; The correct flow show have the internal IP of the phone as the source and not the external IP of the Endian uplink interface. I believe this started happening when I enabled the web proxy in transparent mode with dansguardian but cannot be sure. When the server replies, it replies to the endian public IP address over the public internet.]]></description><category>Uncategorized</category><pubDate>Wed, 08 May 2013 07:44:49 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4472</guid><comments>http://bugs.endian.com/view.php?id=4472#bugnotes</comments></item><item><title>0004391: System not recognizing Intel nic based on 82574L</title><author></author><link>http://bugs.endian.com/view.php?id=4391</link><description><![CDATA[Possibly somehow related to issue 0003451&lt;br /&gt;
&lt;br /&gt;
System has two onboard nics, one is Intel 82574L, the other 82579LM. One of those two nics is not seen by 2.5 in networconfiguration but works just without any problems in 2.4...I think both NICs use the e1000e driver.&lt;br /&gt;
&lt;br /&gt;
I've seen a difference in loading network driver as it seems the 2.4 uses 1.2.20-NAPI while 2.5 is loading at the same point 1.0.2-k2.&lt;br /&gt;
&lt;br /&gt;
Any idea?]]></description><category>Hardware related (kernel, drivers, hardware)</category><pubDate>Wed, 08 May 2013 03:49:45 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4391</guid><comments>http://bugs.endian.com/view.php?id=4391#bugnotes</comments></item><item><title>0004545: error squid_ldap_group</title><author></author><link>http://bugs.endian.com/view.php?id=4545</link><description><![CDATA[Hello guys,&lt;br /&gt;
&lt;br /&gt;
I started to test the Endian 2.5.1 and enjoyed. Currently I'm testing on a VM in Hyper-v. Well, already configured for integration with Active Directory and is listing the users and groups usually ok communication. I began to configure some access policies for a group of AD and early functioned properly, but after some time the policies do not work anymore and blocked everything, just out of nowhere. Since this policy is like first. When running a tail-f / var / log / squid / cache.log appear the following errors:&lt;br /&gt;
&lt;br /&gt;
user filter '(&amp;(objectClass=person)(sAMAccountName=squid))', searchbase 'dc=edusoft,dc=net'&lt;br /&gt;
attempting to authenticate user 'CN=squid,CN=Users,DC=edusoft,DC=net'&lt;br /&gt;
Connected OK&lt;br /&gt;
group filter '(&amp;(objectClass=person)(sAMAccountName=squid)(memberOf=CN=Suporte,OU=Groups Edusoft,OU=Edusoft,DC=edusoft,DC=net))', searchbase 'dc=edusoft,dc=net'&lt;br /&gt;
squid_ldap_group WARNING, LDAP search error 'Operations error'&lt;br /&gt;
Connected OK&lt;br /&gt;
group filter '(&amp;(objectClass=person)(sAMAccountName=squid)(memberOf=CN=Administrators,CN=Builtin,DC=edusoft,DC=net))', searchbase 'dc=edusoft,dc=net'&lt;br /&gt;
&lt;br /&gt;
At another time also appeared the message:&lt;br /&gt;
&lt;br /&gt;
Can't contact LDAP server&lt;br /&gt;
&lt;br /&gt;
It seems that error is occurring in the validation of the AD group, but when I edit an access policy appears normally AD users and groups.&lt;br /&gt;
&lt;br /&gt;
Any idea what it might be?&lt;br /&gt;
&lt;br /&gt;
Rodrigo]]></description><category>Proxy  - HTTP</category><pubDate>Tue, 07 May 2013 15:21:43 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4545</guid><comments>http://bugs.endian.com/view.php?id=4545#bugnotes</comments></item><item><title>0004544: Upgrading to 2.5.1 (Development) causes error code</title><author></author><link>http://bugs.endian.com/view.php?id=4544</link><description><![CDATA[Running efw-upgrade command result in following error message:&lt;br /&gt;
&lt;br /&gt;
========================&lt;br /&gt;
Committing transaction...&lt;br /&gt;
Preparing...                    ######################################## [  0%]&lt;br /&gt;
error: file /etc/init.d from install of chkconfig-1.3.11.2-1 conflicts with file from package initscripts-2.2.41-0.endian5&lt;br /&gt;
error: file /bin/login from install of util-linux-ng-2.13.1-6_WR.endian5 conflicts with file from package shadow-utils-4.0.3-56.endian1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Committing transaction...&lt;br /&gt;
Preparing...                    ######################################## [  0%]&lt;br /&gt;
error: file /etc/init.d from install of chkconfig-1.3.11.2-1 conflicts with file from package initscripts-2.2.41-0.endian5&lt;br /&gt;
error: file /bin/login from install of util-linux-ng-2.13.1-6_WR.endian5 conflicts with file from package shadow-utils-4.0.3-56.endian1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ERROR: Error during upgrade of rpm&lt;br /&gt;
&lt;br /&gt;
Committing transaction...&lt;br /&gt;
Preparing...                    ######################################## [  0%]&lt;br /&gt;
error: file /etc/init.d from install of chkconfig-1.3.11.2-1 conflicts with file from package initscripts-2.2.41-0.endian5&lt;br /&gt;
error: file /bin/login from install of util-linux-ng-2.13.1-6_WR.endian5 conflicts with file from package shadow-utils-4.0.3-56.endian1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ERROR: Error during upgrade of rpm&lt;br /&gt;
&lt;br /&gt;
Committing transaction...&lt;br /&gt;
Preparing...                    ######################################## [  0%]&lt;br /&gt;
error: file /etc/init.d from install of chkconfig-1.3.11.2-1 conflicts with file from package initscripts-2.2.41-0.endian5&lt;br /&gt;
error: file /bin/login from install of util-linux-ng-2.13.1-6_WR.endian5 conflicts with file from package shadow-utils-4.0.3-56.endian1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ERROR: Error during upgrade of rpm&lt;br /&gt;
&lt;br /&gt;
Committing transaction...&lt;br /&gt;
Preparing...                    ######################################## [  0%]&lt;br /&gt;
error: file /etc/init.d from install of chkconfig-1.3.11.2-1 conflicts with file from package initscripts-2.2.41-0.endian5&lt;br /&gt;
error: file /bin/login from install of util-linux-ng-2.13.1-6_WR.endian5 conflicts with file from package shadow-utils-4.0.3-56.endian1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ERROR: Error during upgrade of rpm&lt;br /&gt;
&lt;br /&gt;
Committing transaction...&lt;br /&gt;
Preparing...                    ######################################## [  0%]&lt;br /&gt;
error: file /etc/init.d from install of chkconfig-1.3.11.2-1 conflicts with file from package initscripts-2.2.41-0.endian5&lt;br /&gt;
error: file /bin/login from install of util-linux-ng-2.13.1-6_WR.endian5 conflicts with file from package shadow-utils-4.0.3-56.endian1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ERROR: Error during upgrade of rpm&lt;br /&gt;
&lt;br /&gt;
Committing transaction...&lt;br /&gt;
Preparing...                    ######################################## [  0%]&lt;br /&gt;
error: file /etc/init.d from install of chkconfig-1.3.11.2-1 conflicts with file from package initscripts-2.2.41-0.endian5&lt;br /&gt;
error: file /bin/login from install of util-linux-ng-2.13.1-6_WR.endian5 conflicts with file from package shadow-utils-4.0.3-56.endian1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ERROR: Error during upgrade of rpm&lt;br /&gt;
&lt;br /&gt;
Committing transaction...&lt;br /&gt;
Preparing...                    ######################################## [  0%]&lt;br /&gt;
error: file /etc/init.d from install of chkconfig-1.3.11.2-1 conflicts with file from package initscripts-2.2.41-0.endian5&lt;br /&gt;
error: file /bin/login from install of util-linux-ng-2.13.1-6_WR.endian5 conflicts with file from package shadow-utils-4.0.3-56.endian1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ERROR: Error during upgrade of rpm&lt;br /&gt;
&lt;br /&gt;
Committing transaction...&lt;br /&gt;
Preparing...                    ######################################## [  0%]&lt;br /&gt;
error: file /etc/init.d from install of chkconfig-1.3.11.2-1 conflicts with file from package initscripts-2.2.41-0.endian5&lt;br /&gt;
error: file /bin/login from install of util-linux-ng-2.13.1-6_WR.endian5 conflicts with file from package shadow-utils-4.0.3-56.endian1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ERROR: Error during upgrade of rpm&lt;br /&gt;
ERROR: Error during upgrade of rpm]]></description><category>Endian Firewall</category><pubDate>Thu, 02 May 2013 09:59:04 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4544</guid><comments>http://bugs.endian.com/view.php?id=4544#bugnotes</comments></item><item><title>0004543: green network fault in hyper-v 2012 legacy adapter</title><author></author><link>http://bugs.endian.com/view.php?id=4543</link><description><![CDATA[After few hours from reboot  green don't respond. I've 2 uplink network in same hyper-v 2012 network Adapter configuration that work without problem.]]></description><category>Endian Network</category><pubDate>Thu, 02 May 2013 08:59:20 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4543</guid><comments>http://bugs.endian.com/view.php?id=4543#bugnotes</comments></item><item><title>0004542: WCCP in Proxy</title><author></author><link>http://bugs.endian.com/view.php?id=4542</link><description><![CDATA[Hi,&lt;br /&gt;
&lt;br /&gt;
It is possible to setup the wccp in proxy? I can see that in version 2.5.1 community, wccp2 is already compiled. I have added the wccp2_* setup in squid template and created a GRE tunnel manually using ip tunnel and ifconfig to up the GRE interface.&lt;br /&gt;
&lt;br /&gt;
the problem is, i don't see any tcpdump in the GRE tunnel that I created. It seems the wccp request is not getting to the wccp router.&lt;br /&gt;
&lt;br /&gt;
Please help.&lt;br /&gt;
&lt;br /&gt;
Thank you.&lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
&lt;br /&gt;
Albert]]></description><category>Proxy  - HTTP</category><pubDate>Wed, 01 May 2013 04:37:33 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4542</guid><comments>http://bugs.endian.com/view.php?id=4542#bugnotes</comments></item><item><title>0004162: clamd crash, tcp socket should be monitored</title><author></author><link>http://bugs.endian.com/view.php?id=4162</link><description><![CDATA[Hi Guys,&lt;br /&gt;
&lt;br /&gt;
this happens randomly:&lt;br /&gt;
&lt;br /&gt;
Sep  2 09:19:46 xxx havp[3818]: Scanner errors: Clamd: Could not connect to scanner socket (lasturl: &lt;a href=&quot;http://www.google.it/&quot;&gt;http://www.google.it/&lt;/a&gt; [&lt;a href=&quot;http://www.google.it/&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;])&lt;br /&gt;
Sep  2 09:19:47 xxx havp[3824]: Clamd: Could not connect to scanner! Scanner down?&lt;br /&gt;
Sep  2 09:20:45 xxx havp[3813]: Clamd: Could not connect to scanner! Scanner down?&lt;br /&gt;
Sep  2 09:20:45 xxx havp[3811]: Scanner errors: Clamd: Could not connect to scanner socket (lasturl: &lt;a href=&quot;http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl&quot;&gt;http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl&lt;/a&gt; [&lt;a href=&quot;http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;])&lt;br /&gt;
Sep  2 09:21:06 xxx havp[4051]: Clamd: Could not connect to scanner! Scanner down?&lt;br /&gt;
Sep  2 09:21:06 xxx havp[4034]: Scanner errors: Clamd: Could not connect to scanner socket (lasturl: &lt;a href=&quot;http://check.sanasecurity.com/&quot;&gt;http://check.sanasecurity.com/&lt;/a&gt; [&lt;a href=&quot;http://check.sanasecurity.com/&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;])&lt;br /&gt;
Sep  2 09:21:06 xxx havp[4034]: 127.0.0.1 POST 200 &lt;a href=&quot;http://check.sanasecurity.com/&quot;&gt;http://check.sanasecurity.com/&lt;/a&gt; [&lt;a href=&quot;http://check.sanasecurity.com/&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;] 264+495 SCANERROR Clamd: Could not connect to scanner socket&lt;br /&gt;
&lt;br /&gt;
**POSSIBLE SOLUTION**&lt;br /&gt;
&lt;br /&gt;
We should check the clamd socket with monit, which is pretty easy since monit support the CLAMAV protocol!&lt;br /&gt;
&lt;br /&gt;
root@xxx:/etc/monit.d # cat clamd.conf &lt;br /&gt;
 check process clamd with pidfile /var/run/clamav/clamd.pid &lt;br /&gt;
   group virus&lt;br /&gt;
   start program = &quot;/etc/init.d/clamd start&quot;&lt;br /&gt;
   stop program = &quot;/etc/init.d/clamd stop&quot;&lt;br /&gt;
   if failed host 127.0.0.1 port 3310 protocol CLAMAV for 5 cycle then restart&lt;br /&gt;
   if 5 restarts within 5 cycles then timeout&lt;br /&gt;
   depends on clamavd_bin&lt;br /&gt;
   mode manual&lt;br /&gt;
&lt;br /&gt;
 check file clamavd_bin with path /usr/sbin/clamd&lt;br /&gt;
   group virus&lt;br /&gt;
   if failed checksum then unmonitor&lt;br /&gt;
   if failed permission 755 then unmonitor&lt;br /&gt;
   if failed uid root then unmonitor&lt;br /&gt;
   if failed gid root then unmonitor&lt;br /&gt;
   mode manual&lt;br /&gt;
&lt;br /&gt;
This would increase reliability for http proxy and smtp proxy as well!&lt;br /&gt;
What you think?]]></description><category>Proxy  HTTP</category><pubDate>Tue, 23 Apr 2013 16:17:02 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4162</guid><comments>http://bugs.endian.com/view.php?id=4162#bugnotes</comments></item><item><title>0003221: http proxy don't  returns anything after some time. If flush cache of Squid, the firewall works again correctly</title><author></author><link>http://bugs.endian.com/view.php?id=3221</link><description><![CDATA[After some utilisation the firewall don't returns pages. Ping is working, dns also.&lt;br /&gt;
If I flush the cache of squid, proxy is again OK.]]></description><category>Proxy HTTP</category><pubDate>Tue, 16 Apr 2013 21:29:36 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=3221</guid><comments>http://bugs.endian.com/view.php?id=3221#bugnotes</comments></item><item><title>0004540: DUAL LINK WAN</title><author></author><link>http://bugs.endian.com/view.php?id=4540</link><description><![CDATA[Hello&lt;br /&gt;
&lt;br /&gt;
I have the following scenario for Internet access:&lt;br /&gt;
&lt;br /&gt;
WAN0 - eth1: RED&lt;br /&gt;
WAN1 - eth4: RED&lt;br /&gt;
&lt;br /&gt;
If I set any of the links as the second link shows MAIN FAILURE with the following log.&lt;br /&gt;
&lt;br /&gt;
/var/log/messages&lt;br /&gt;
Apr 16 13:11:52 LOFW001GFT sudo:   nobody : TTY=unknown ; PWD=/home/httpd/cgi-bin ; USER=root ; COMMAND=/etc/rc.d/uplinks start uplink1 --with-hooks&lt;br /&gt;
Apr 16 13:11:52 LOFW001GFT uplink[uplink1]: Starting Uplink 'uplink1'&lt;br /&gt;
Apr 16 13:11:53 LOFW001GFT kernel: [  261.936098] e1000e 0000:01:00.1: irq 30 for MSI/MSI-X&lt;br /&gt;
Apr 16 13:11:53 LOFW001GFT kernel: [  261.986175] e1000e 0000:01:00.1: irq 30 for MSI/MSI-X&lt;br /&gt;
Apr 16 13:11:53 LOFW001GFT kernel: [  261.986492] ADDRCONF(NETDEV_UP): eth4: link is not ready&lt;br /&gt;
Apr 16 13:11:53 LOFW001GFT kernel: [  262.606054] e1000e 0000:01:00.1: irq 30 for MSI/MSI-X&lt;br /&gt;
Apr 16 13:11:53 LOFW001GFT kernel: [  262.656051] e1000e 0000:01:00.1: irq 30 for MSI/MSI-X&lt;br /&gt;
Apr 16 13:11:53 LOFW001GFT kernel: [  262.656379] ADDRCONF(NETDEV_UP): eth4: link is not ready&lt;br /&gt;
Apr 16 13:11:53 LOFW001GFT uplink[uplink1]: Notify uplinks daemon about status change of uplink 'uplink1'. Status id FAILED&lt;br /&gt;
Apr 16 13:11:53 LOFW001GFT uplink[uplink1]: Uplink 'uplink1' status: 'OFFLINE'&lt;br /&gt;
Apr 16 13:11:53 LOFW001GFT uplink[uplink1]: Could not set up routing&lt;br /&gt;
&lt;br /&gt;
As a way to circumvent the problem perform the following activities.&lt;br /&gt;
&lt;br /&gt;
1) Link setup MAIN&lt;br /&gt;
2) mv /var/efw/uplinks/uplink1/failure /var/efw/uplinks/uplink1/active&lt;br /&gt;
3) ifconfig eth4 200.146.46.254 netmask 255.255.255.248&lt;br /&gt;
&lt;br /&gt;
This way I can climb the two links but it is not the most pleasant thing to do.&lt;br /&gt;
&lt;br /&gt;
Would like to help me solve this problem?&lt;br /&gt;
&lt;br /&gt;
I await a return.&lt;br /&gt;
&lt;br /&gt;
Sincerely.&lt;br /&gt;
&lt;br /&gt;
Fernando Guse]]></description><category>Endian Firewall</category><pubDate>Tue, 16 Apr 2013 19:25:09 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4540</guid><comments>http://bugs.endian.com/view.php?id=4540#bugnotes</comments></item><item><title>0004295: NTOP Segmentation Fault</title><author></author><link>http://bugs.endian.com/view.php?id=4295</link><description><![CDATA[Hello everyone, &lt;br /&gt;
&lt;br /&gt;
I have noticed an issue with the 2.5.1 EFW Ntop that I wanted to report. After an out-of-the box installation, I tried to activate the NTOP monitoring system. It would run for a while (3-7 minutes) and then stop. &lt;br /&gt;
&lt;br /&gt;
/etc/init.d/ntop status would return that ntop is dead, but a PID still exists. &lt;br /&gt;
&lt;br /&gt;
I couldn't find any useful logs for ntop outside of monit.log, but it only ever contained information about the system starting and stopping. As such, I launched ntop using the configurations in /etc/ntop/ntop.conf (But I specified to use http 3001 not https 3001).&lt;br /&gt;
&lt;br /&gt;
It seemed to work fine for a while, which blew my mind, but eventually it stopped with the following output:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Thu Mar  8 10:33:02 2012  THREADMGMT[t2967894960]: SIH: Idle host scan thread running [p9813]&lt;br /&gt;
Thu Mar  8 10:33:02 2012  THREADMGMT[t2976283568]: SFP: Fingerprint scan thread running [p9813]&lt;br /&gt;
Thu Mar  8 10:33:02 2012  THREADMGMT[t2917264304]: NPS(WAN): pcapDispatch thread starting [p9813]&lt;br /&gt;
Thu Mar  8 10:33:02 2012  THREADMGMT[t2917264304]: NPS(WAN): pcapDispatch thread running [p9813]&lt;br /&gt;
Thu Mar  8 10:33:02 2012  THREADMGMT[t2908875696]: NPS(2): Started thread for network packet sniffing [br0]&lt;br /&gt;
Thu Mar  8 10:33:02 2012  THREADMGMT[t2900487088]: NPS(3): Started thread for network packet sniffing [eth0]&lt;br /&gt;
Thu Mar  8 10:33:02 2012  THREADMGMT[t2908875696]: NPS(br0): pcapDispatch thread starting [p9813]&lt;br /&gt;
Thu Mar  8 10:33:02 2012  THREADMGMT[t2908875696]: NPS(br0): pcapDispatch thread running [p9813]&lt;br /&gt;
Thu Mar  8 10:33:02 2012  THREADMGMT[t2900487088]: NPS(eth0): pcapDispatch thread starting [p9813]&lt;br /&gt;
Thu Mar  8 10:33:02 2012  THREADMGMT[t2900487088]: NPS(eth0): pcapDispatch thread running [p9813]&lt;br /&gt;
./start_ntop.sh: line 2:  9813 Segmentation fault      ntop --user ntop --db-file-path /var/ntop --interface eth1,br0,eth0 --trace-level 3 --https-server 0 --http-server 3001 --disable-schedyield --no-fc&lt;br /&gt;
&lt;br /&gt;
It will start every time, but eventually fails with the segmentation fault]]></description><category>Other Services</category><pubDate>Fri, 12 Apr 2013 18:54:44 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4295</guid><comments>http://bugs.endian.com/view.php?id=4295#bugnotes</comments></item><item><title>0004539: Sarg generates no access denied</title><author></author><link>http://bugs.endian.com/view.php?id=4539</link><description><![CDATA[By enabling authenticated proxy the SARG can not generate the access denied page.]]></description><category>Uncategorized</category><pubDate>Thu, 11 Apr 2013 12:34:03 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4539</guid><comments>http://bugs.endian.com/view.php?id=4539#bugnotes</comments></item><item><title>0004532: 2.5.1 DNS issue openvpn</title><author></author><link>http://bugs.endian.com/view.php?id=4532</link><description><![CDATA[I have installed 2.5.1 several times now on different hardware and version 2.5.1 will not push DNS serves to clients.  Clients can ping and get to servers by IP but not FQDN.  If I install 2.5.0 it pushes the DNS servers every time.  It looks to us that the OpenVPN version is the same in both versions so why does one version push DNS and the other does not?&lt;br /&gt;
&lt;br /&gt;
Any suggestions before I rebuild to 2.5.0?]]></description><category>OpenVPN Client and Server</category><pubDate>Sun, 07 Apr 2013 18:40:41 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4532</guid><comments>http://bugs.endian.com/view.php?id=4532#bugnotes</comments></item><item><title>0004231: "Your Harddisk is to small" error message during install of 2.5 version</title><author></author><link>http://bugs.endian.com/view.php?id=4231</link><description><![CDATA[When installing 2.5 on VMware with a disk 15GB or less the installation fails with an error message &quot;Your harddisk is to small&quot; sh: -c line 0: unexpected EOF while looking for matching '&quot;]]></description><category>Installation</category><pubDate>Sun, 07 Apr 2013 06:08:42 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4231</guid><comments>http://bugs.endian.com/view.php?id=4231#bugnotes</comments></item><item><title>0002464: Snort blocks smb and netbios over VPN despite FW rule</title><author></author><link>http://bugs.endian.com/view.php?id=2464</link><description><![CDATA[Ive got EFW 2.3 with openvpn and client is a roadwarrior. VPN works fine ie. I can ping and SSH to machines on the GREEN zone to/from the openvpn client.&lt;br /&gt;
&lt;br /&gt;
PING OK : VPN client &lt;----&gt; GREEN zone&lt;br /&gt;
SSH OK : VPN client &lt;----&gt; GREEN zone&lt;br /&gt;
smb/netbios BLOCKED : VPN client &lt;----&gt; GREEN zone&lt;br /&gt;
&lt;br /&gt;
After almost a week I figured out that snort(IPS) will block smb and netbios over the VPN despite the VPN firewall rule to allow all access, also same result if VPN firewall is disabled.&lt;br /&gt;
&lt;br /&gt;
If I switch off IPS then file and print sharing WORKS. There is nothing in the logs about these packets being blocked otherwise I would have found out much earlier.&lt;br /&gt;
&lt;br /&gt;
Please advise a fix to this.]]></description><category>Firewall (iptables)</category><pubDate>Wed, 03 Apr 2013 12:09:21 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=2464</guid><comments>http://bugs.endian.com/view.php?id=2464#bugnotes</comments></item><item><title>0004538: calaendar problem, duplice day</title><author></author><link>http://bugs.endian.com/view.php?id=4538</link><description><![CDATA[in month 3 day 16 duplicate at year 2013 and in year 2012 day 17 duplicate&lt;br /&gt;
place after remove this bug send for me.&lt;br /&gt;
&lt;a href=&quot;mailto:mgr9500@yahoo.com&quot;&gt;mgr9500@yahoo.com&lt;/a&gt;]]></description><category>GUI</category><pubDate>Wed, 03 Apr 2013 09:28:30 +0200</pubDate><guid>http://bugs.endian.com/view.php?id=4538</guid><comments>http://bugs.endian.com/view.php?id=4538#bugnotes</comments></item><item><title>0004497: Openvpn GUI settings not saved to settings file - settings file resets when saving via GUI</title><author></author><link>http://bugs.endian.com/view.php?id=4497</link><description><![CDATA[Hello,&lt;br /&gt;
&lt;br /&gt;
I upgraded our firewall from 2.4.1 to 2.5. I restored a backup to do this, mainly because we have around 150 openvpn users I didn't want to recreate.&lt;br /&gt;
&lt;br /&gt;
When I try to save global options in the GUI, nothing is saved to the /etc/openvpn.conf file. When I edit the conf file and restart the Openvpn service through SSH, everything is OK and the options are pushed correctly. The options aren't displayed in the GUI though.&lt;br /&gt;
&lt;br /&gt;
When I then try to change a global option in the GUI, or even just click the save &amp; restart button in the GUI, the openvpn.conf file gets reset to default, and my clients receive the DNS servers below instead of their correct ones (at that moment no DNS servers are defined in the conf file because of the reset)&lt;br /&gt;
&lt;br /&gt;
DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1&lt;br /&gt;
                                    fec0:0:0:ffff::2%1&lt;br /&gt;
                                    fec0:0:0:ffff::3%1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Thanks!]]></description><category>OpenVPN Client and Server</category><pubDate>Fri, 22 Mar 2013 17:26:03 +0100</pubDate><guid>http://bugs.endian.com/view.php?id=4497</guid><comments>http://bugs.endian.com/view.php?id=4497#bugnotes</comments></item><item><title>0003432: HAVP =&gt; no youtube videos from iphone &amp; ipad</title><author></author><link>http://bugs.endian.com/view.php?id=3432</link><description><![CDATA[When HAVP is enabled we are unable to see youtube videos with iphone or ipad.&lt;br /&gt;
when is disabled the problem disappears.&lt;br /&gt;
&lt;br /&gt;
The issue is reproducible and the zone is indifferent (green/orange or blue).&lt;br /&gt;
&lt;br /&gt;
I noticed testing this that the cause is havp but no error message in the log.&lt;br /&gt;
&lt;br /&gt;
System tested was full up-to-date.]]></description><category>Proxy HTTP</category><pubDate>Mon, 11 Mar 2013 09:41:10 +0100</pubDate><guid>http://bugs.endian.com/view.php?id=3432</guid><comments>http://bugs.endian.com/view.php?id=3432#bugnotes</comments></item><item><title>0004415: NTOP / Traffic Monitoring Is Not Working</title><author></author><link>http://bugs.endian.com/view.php?id=4415</link><description><![CDATA[On Endian Firewall 2.5.1. &lt;br /&gt;
&lt;br /&gt;
The NTOP doesn't work even Intrusion is turned off (some reported this issue may due to Intrusion turned on).]]></description><category>Other Services</category><pubDate>Mon, 11 Mar 2013 05:21:02 +0100</pubDate><guid>http://bugs.endian.com/view.php?id=4415</guid><comments>http://bugs.endian.com/view.php?id=4415#bugnotes</comments></item><item><title>0004535: Endian 2.5 Community does not accept special characters in the PSK</title><author></author><link>http://bugs.endian.com/view.php?id=4535</link><description><![CDATA[I'm trying to use a PSK for the establishment of an IPsec tunnel. This PSK contains some special characters, such as * and &amp;.&lt;br /&gt;
&lt;br /&gt;
When I try to set this PSK up at an Endian 2.5 Community firewall, it complains about these characters with an error message like this:&lt;br /&gt;
&lt;br /&gt;
&quot;Invalid characters found in the pre-shared key.&quot;&lt;br /&gt;
&lt;br /&gt;
I've searched the issues database and found the issue &lt;a href=&quot;http://bugs.endian.com/view.php?id=613&quot;&gt;0000613&lt;/a&gt; where the situation is the same. The responsible for the ticket says it's solved but I'm facing the same issue on version 2.5.&lt;br /&gt;
&lt;br /&gt;
Please help me out.]]></description><category>VPN - IPSec</category><pubDate>Fri, 01 Mar 2013 03:15:50 +0100</pubDate><guid>http://bugs.endian.com/view.php?id=4535</guid><comments>http://bugs.endian.com/view.php?id=4535#bugnotes</comments></item><item><title>0001151: portforwarding: unable to access GREEN from GREEN via RED portforward rule</title><author></author><link>http://bugs.endian.com/view.php?id=1151</link><description><![CDATA[as per summary, a device on the GREEN network is unable to access another device on the GREEN network, by using the RED interface and portforwarding.&lt;br /&gt;
&lt;br /&gt;
we configure mobile devices to access resources on the GREEN network, by using the RED device and port forwarding. they can operate onsite and offsite (without vpn) this way.]]></description><category>Firewall (iptables)</category><pubDate>Fri, 22 Feb 2013 14:58:25 +0100</pubDate><guid>http://bugs.endian.com/view.php?id=1151</guid><comments>http://bugs.endian.com/view.php?id=1151#bugnotes</comments></item><item><title>0004221: kernel :  xt_TCPMSS: bad length (1024 bytes) + PATCH</title><author></author><link>http://bugs.endian.com/view.php?id=4221</link><description><![CDATA[Hi, &lt;br /&gt;
&lt;br /&gt;
a customer with 500+ concurrent voip connection (a 16 cores workstation) saying that the firewall &quot;crashed&quot;  due to heavy voip traffic.&lt;br /&gt;
&lt;br /&gt;
When logged in this is what I recall interesting:&lt;br /&gt;
&lt;a href=&quot;http://pastie.org/2991370&quot;&gt;http://pastie.org/2991370&lt;/a&gt; [&lt;a href=&quot;http://pastie.org/2991370&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;]&lt;br /&gt;
&lt;br /&gt;
Leaving the other problems (already know what and why) and focusing to the kernel message I found that is related with netfilter, an the matching rule (MSS) is located in mangle, chain:&lt;br /&gt;
&lt;br /&gt;
Chain FORWARD (policy ACCEPT 231M packets, 33G bytes)&lt;br /&gt;
 pkts bytes target     prot opt in     out     source               destination         &lt;br /&gt;
1217K   66M TCPMSS     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:0x06/0x02 TCPMSS clamp to PMTU &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://rhkernel.org/#RHEL6+2.6.32-71.18.2.el6/net/netfilter/xt_TCPMSS.c&quot;&gt;http://rhkernel.org/#RHEL6+2.6.32-71.18.2.el6/net/netfilter/xt_TCPMSS.c&lt;/a&gt; [&lt;a href=&quot;http://rhkernel.org/#RHEL6+2.6.32-71.18.2.el6/net/netfilter/xt_TCPMSS.c&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;]&lt;br /&gt;
  63        /* Since it passed flags test in tcp match, we know it is is&lt;br /&gt;
  64           not a fragment, and has data &gt;= tcp header length.  SYN&lt;br /&gt;
  65           packets should not contain data: if they did, then we risk&lt;br /&gt;
  66           running over MTU, sending Frag Needed and breaking things&lt;br /&gt;
  67           badly. --RR */&lt;br /&gt;
  68        if (tcplen != tcph-&gt;doff*4) {&lt;br /&gt;
  69                if (net_ratelimit())&lt;br /&gt;
  70                        printk(KERN_ERR &quot;xt_TCPMSS: bad length (%u bytes)\n&quot;,&lt;br /&gt;
  71                               skb-&gt;len);&lt;br /&gt;
  72                return -1;&lt;br /&gt;
  73        }&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
So the error is caused for 2 reasons:&lt;br /&gt;
&lt;br /&gt;
1) Syn packets which contains data (normally not allowed)&lt;br /&gt;
2) TCP header larger than the packet itself&lt;br /&gt;
&lt;br /&gt;
It's rare to reproduce because on rare occasions is produced this kind of traffic, however there is already a patch on this problem (I belive it's included in the vanilla).&lt;br /&gt;
&lt;br /&gt;
PATCH:&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.gossamer-threads.com/lists/linux/kernel/1180390?do=post_view_threaded&quot;&gt;http://www.gossamer-threads.com/lists/linux/kernel/1180390?do=post_view_threaded&lt;/a&gt; [&lt;a href=&quot;http://www.gossamer-threads.com/lists/linux/kernel/1180390?do=post_view_threaded&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;]]]></description><category>Kernel</category><pubDate>Thu, 21 Feb 2013 05:52:24 +0100</pubDate><guid>http://bugs.endian.com/view.php?id=4221</guid><comments>http://bugs.endian.com/view.php?id=4221#bugnotes</comments></item><item><title>0004394: Support for Intel 82580 based network cards (Ethernet-Server-Adapter I340-T4)</title><author></author><link>http://bugs.endian.com/view.php?id=4394</link><description><![CDATA[The Intel Ethernet-Server-Adapter I340-T4 and other Intel 82580 based network cards don't work on Endian 2.5.1.&lt;br /&gt;
There is a Linux driver on the Intel website: &lt;br /&gt;
&lt;a href=&quot;http://downloadcenter.intel.com/detail_desc.aspx?agr=Y&amp;DwnldID=13663&quot;&gt;http://downloadcenter.intel.com/detail_desc.aspx?agr=Y&amp;DwnldID=13663&lt;/a&gt; [&lt;a href=&quot;http://downloadcenter.intel.com/detail_desc.aspx?agr=Y&amp;DwnldID=13663&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;]&lt;br /&gt;
&lt;br /&gt;
Please add this driver to EFW Community Edition or provide a Kernel source package so that users can compile the driver itself. &lt;br /&gt;
&lt;br /&gt;
Thank you very much!]]></description><category>Hardware related (kernel, drivers, hardware)</category><pubDate>Tue, 19 Feb 2013 06:23:36 +0100</pubDate><guid>http://bugs.endian.com/view.php?id=4394</guid><comments>http://bugs.endian.com/view.php?id=4394#bugnotes</comments></item></channel></rss>
