Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [bug since 2.1.2] Unable to communicate with https://packages.pfsense.org

    pfSense Packages
    18
    28
    28.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cmb
      last edited by

      If you see SYNs leaving and no SYN ACKs coming back, you're blocking the traffic somewhere. You have proper connectivity in general since HTTP works, and our restrictions for HTTPS are identical to HTTP, so we're not blocking you (and we don't really block any sources short of bogons, and an IP here and there on occasion that's doing stupid stuff).

      1 Reply Last reply Reply Quote 0
      • V
        vipermy
        last edited by

        @cmb:

        It should still be using the proxy, the only thing functionally different is using HTTPS instead of HTTP. If you change "xmlrpcbaseurl" in /etc/inc/globals.inc from HTTPS to HTTP does it work through the proxy?

        Hi, just to share .. we are facing the same issue with pfSenses (behind the proxy) after update to 2.1.2. After updating globals.inc it worked on plain http (and not https).
        Thanks.

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by

          @vipermy:

          Hi, just to share .. we are facing the same issue with pfSenses (behind the proxy) after update to 2.1.2. After updating globals.inc it worked on plain http (and not https).

          Thanks for the feedback. With 3 separate confirmations, via a proxy is likely a legit issue.
          https://redmine.pfsense.org/issues/3612

          If anyone digs at the source on this issue, please add info on that redmine ticket.

          For those who find this thread and aren't using a proxy, you have a general connectivity problem of some sort that's entirely unrelated to this thread, please start your own thread with information about your scenario.

          1 Reply Last reply Reply Quote 0
          • X
            xhark
            last edited by

            Sorry for the delay.

            It works with editing the /etc/inc/globals.inc and change from

                    "xmlrpcbaseurl" => "https://packages.pfsense.org",
            

            to:

                    "xmlrpcbaseurl" => "http://packages.pfsense.org",
            

            I confirm that pfSense try to contact HTTPS without going through the proxy.

            SysNetAdmin & Blogger on http://blogmotion.fr

            1 Reply Last reply Reply Quote 0
            • ?
              A Former User
              last edited by

              @x16wda:

              taunusstein.net, I am seeing the same behavior, coincidentally after I upgraded to 2.1.3 this evening.  :(

              I had not checked packages for several weeks before the upgrade. Tonight, I have no issue pinging the ipv4 site but get no response from the ipv6 address, and I get the same "unable to connect to https://packages.pfsense.org" error.  No proxy in my configuration and no other connectivity issues.

              Update: disable IPv6 (System, Advanced, Networking, uncheck Allow IPv6) and packages show up fine.

              Worked perfect i was pulling my hair out till i tried the disable ipv6 !

              1 Reply Last reply Reply Quote 0
              • T
                topoldo
                last edited by

                @topoldo:

                Hi all.
                I have the same problem with this configuration:

                • No proxy
                • No IPv6

                [skip…]

                Solved! It was my fault, I was wrong in setting the gateway.
                Now it works with the Override Host in DNS forwarders trick.
                Topoldo

                1 Reply Last reply Reply Quote 0
                • A
                  acald
                  last edited by

                  Solved!

                  We have multiple subnets and one uses its own DNS server instead of using the DNS forwarder.  Because of this we adjusted the interfaces that the DNS forwarder listens on.  In the process we must have killed pfSense's ability to reach the update servers because once I tried changing it to ALL, it perked right up and displayed the update's availability.

                  Happily updated ti 2.1.3.  Thanks guys!

                  1 Reply Last reply Reply Quote 0
                  • X
                    xhark
                    last edited by

                    Sorry but I use the 2.1.4 and the bug is always the same, can't contact the server.

                    However the file is correctly patched cf https://redmine.pfsense.org/projects/pfsense/repository/revisions/1930a63e811915da210555804925e67ec419d662

                    (The workaround with /etc/inc/global.inc.php works)

                    No idea ?

                    SysNetAdmin & Blogger on http://blogmotion.fr

                    1 Reply Last reply Reply Quote 0
                    • N
                      nut 0
                      last edited by

                      2.1.4-RELEASE (i386)

                      Can't still work with Package Manager!

                      -> "Unable to communicate with https://packages.pfsense.org. …"

                      :'(

                      Any Ideas?

                      Edit:

                      Seems to be a Problem of packages.pfsense.org.
                      https://packages.pfsense.org/xmlrpc.php is still giving error:
                      faultCode 105 faultString XML error: Invalid document end at line 1

                      1 Reply Last reply Reply Quote 0
                      • S
                        Supermule Banned
                        last edited by

                        I dont have that issue at all with 2.1.4

                        Works fine from Denmark…

                        1 Reply Last reply Reply Quote 0
                        • E
                          eduardogoncalves
                          last edited by

                          Same here:

                          2.1.4-RELEASE (i386)
                          built on Fri Jun 20 12:59:29 EDT 2014
                          FreeBSD 8.3-RELEASE-p16
                          You are on the latest version.

                          But on packages page:

                          Unable to communicate with https://packages.pfsense.org. Please verify DNS and interface configuration, and that pfSense has functional Internet connectivity.

                          1 Reply Last reply Reply Quote 0
                          • D
                            denizv
                            last edited by

                            Today, i backed up my configuration. I switched from embedded version of pfsense (on usb) to regular version (on hdd).
                            This problem suddenly appared.
                            I tried

                            1. http://packages.pfsense.org
                            2. Checked gateways, dns forwarder settings, dns servers, tried different settings
                            3. I can ping packages.pfsense.org on wan
                            4. "You are on the latest version" is visible
                            5. No ipv6, no proxy
                            6. I pretty much tried everything i have read and think of

                            I'm thinking either there is difference between LiveCD and NanoBSD version or this site might be bugged/down. What should i do next?

                            1 Reply Last reply Reply Quote 0
                            • S
                              Supermule Banned
                              last edited by

                              I got this as well now. :(

                              NOT good….

                              1 Reply Last reply Reply Quote 0
                              • B
                                bennyc
                                last edited by

                                linked with this topic:

                                https://forum.pfsense.org/index.php?topic=78276.0

                                Same issue imho. There's something still not right.

                                4x XG-7100 (2xHA), 1x SG-4860, 1x SG-2100
                                1x PC Engines APU2C4, 1x PC Engines APU1C4

                                1 Reply Last reply Reply Quote 0
                                • B
                                  bennyc
                                  last edited by

                                  @cmb:

                                  It should still be using the proxy, the only thing functionally different is using HTTPS instead of HTTP. If you change "xmlrpcbaseurl" in /etc/inc/globals.inc from HTTPS to HTTP does it work through the proxy?

                                  To to confirm, this workaround also worked here. Just changing to http got me access to the available package pages.

                                  Seem to me there is some issue with the proxy!

                                  –edit: using 2.1.4-RELEASE (amd64) on APU1C4--

                                  4x XG-7100 (2xHA), 1x SG-4860, 1x SG-2100
                                  1x PC Engines APU2C4, 1x PC Engines APU1C4

                                  1 Reply Last reply Reply Quote 0
                                  • D
                                    denizv
                                    last edited by

                                    Problem solved itself this morning, i think it was server related

                                    1 Reply Last reply Reply Quote 0
                                    • ?
                                      Guest
                                      last edited by

                                      Nope.

                                      Someone whom should have known better got the CARP addresses wrong for v6 late last week.

                                      Since we're moving racks in the data center, the problem didn't surface until we failed over while moving one of the last pieces of gear to the new rack, the. Fee stablished the primary.

                                      1 Reply Last reply Reply Quote 0
                                      • K
                                        kejianshi
                                        last edited by

                                        Download the update you need and browse to that file locally if you need.

                                        1 Reply Last reply Reply Quote 0
                                        • F
                                          finalcut
                                          last edited by

                                          After while i can say it clear and loud

                                          PFSENSE as firewall IS GREAT CLEAR OF BUGS BETTER THAN HOLY S*** CISCO ASA have multiple option than juniper

                                          But the only thing i dream in is stable version of squid3-dev with easy way to add and authenticate users (using UI)

                                          1 Reply Last reply Reply Quote 0
                                          • M
                                            msmith9xr4
                                            last edited by

                                            confirmed works disabling ipv6 on 2.1.5 and 2.2.4 for me, 2 different WAN providers.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.