Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IGMP proxy no longer works reliably after 2.7.1 update

    Scheduled Pinned Locked Moved Routing and Multi WAN
    80 Posts 15 Posters 23.5k Views 21 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      haraldinho @vjizzle
      last edited by

      This post is deleted!
      1 Reply Last reply Reply Quote 0
      • H Offline
        haraldinho @vjizzle
        last edited by haraldinho

        @vjizzle said in IGMP proxy no longer works reliably after 2.7.1 update:

        Release 24.03…wow. So the fix is targeted to be here somewhere in the next 6 months orso?

        Is it possible to run the igmp proxy package from 2.6 on 2.7? That would be a workaround perhaps for the time being.

        @vjizzle This is typically how it is done. A separate fix is created and made available asap, usually within days or weeks. You can install the fix through the Patch option in your pfSense System-->Patches. Then, in the next big release the fix is incorporated in the main release and the patch can be dropped. Depending a bit also on where the fix should be made, not everything is under control of the pfSense team.

        This was at least my experience around IGMPproxy issues, there have been some in the past. Everybody keeps saying that IGMPproxy is just a simple service passing packets along, however given the amount of issues I guess it is either more complex than everybody thinks or a good set of regression tests are missing.

        V 1 Reply Last reply Reply Quote 0
        • V Offline
          vjizzle @haraldinho
          last edited by

          @haraldinho
          Yes, that is also how I expect things to work, however setting a delivery date that far in the future is not how you manage expectations realistically. Nonetheless, for now, running fine on 2.6.

          R 1 Reply Last reply Reply Quote 0
          • R Offline
            Rai80 @vjizzle
            last edited by Rai80

            With the latest kernel patch from Kristof Provost this issue is solved! 👏

            See: https://redmine.pfsense.org/issues/15043

            C 1 Reply Last reply Reply Quote 0
            • C Offline
              Cornel @Rai80
              last edited by

              @Rai80 great news!!
              I get a file not found error on opening that next cloud link. Anyway assuming that link is restored. How do you install that image?

              R 1 Reply Last reply Reply Quote 0
              • R Offline
                Rai80 @Cornel
                last edited by

                @Cornel Just download the file [pfSense-kernel-pfSense-2.7.2.r.20231212.1754.pkg] to your pfSense box. When the link is working again.
                Install it with: pkg add -f pfSense-kernel-pfSense-2.7.2.r.20231212.1754.pkg
                Reboot

                And done!

                H 1 Reply Last reply Reply Quote 2
                • H Offline
                  haraldinho @Rai80
                  last edited by

                  @Rai80 not sure what exactly the difference is, but Kristof suggested the following to install:

                  “Backup your device, download the pkg file to it, "pkg install -U <patchname>.pkg" and reboot.”

                  1 Reply Last reply Reply Quote 0
                  • R Offline
                    Rai80
                    last edited by Rai80

                    Since the former link is not working anymore I uploaded the patched kernel: https://file.io/f2Xmr5QlCTnF

                    C 1 Reply Last reply Reply Quote 0
                    • C Offline
                      Cornel @Rai80
                      last edited by

                      @Rai80 thanks for sharing! Did you by any chance also get the 23.09.1 package?

                      R 1 Reply Last reply Reply Quote 0
                      • R Offline
                        Rai80 @Cornel
                        last edited by

                        @Cornel No sorry. I saw it was there, I think you have to wait for Kristof to make the link available again.

                        C 1 Reply Last reply Reply Quote 0
                        • H Offline
                          haraldinho
                          last edited by

                          In any case I think it is better to wait a couple of days until the official patch will be available to be installed through the regular patch options.

                          1 Reply Last reply Reply Quote 2
                          • C Offline
                            Cornel @Rai80
                            last edited by

                            @Rai80 No problem - in hindsight I'll wait for either a patch or a package specific for my architecture. Happy to see the Netgate team and the community on the ball. Great to see that a solution might be available soon.

                            1 Reply Last reply Reply Quote 0
                            • U Offline
                              UlfMerbold
                              last edited by

                              @Rai80 said in IGMP proxy no longer works reliably after 2.7.1 update:

                              pfSense-kernel-pfSense-2.7.2.r.20231212.1754.pkg

                              And now? The pkg isnt available anymore!

                              The guys which are lucky enough to download it quickly have reliable iptv and the rest of us are fxxked?

                              Fun enough the maintainers "forgot" kernelside iptv elements in their maintenance releases...

                              Now we have to wait a year again to see an kernel which is obvious ready? Rofl

                              M 1 Reply Last reply Reply Quote 0
                              • M Offline
                                michmoor LAYER 8 Rebel Alliance @UlfMerbold
                                last edited by

                                @UlfMerbold
                                I think the updated kernel fix is in the latest CE snapshots.

                                Firewall: NetGate,Palo Alto-VM,Juniper SRX
                                Routing: Juniper, Arista, Cisco
                                Switching: Juniper, Arista, Cisco
                                Wireless: Unifi, Aruba IAP
                                JNCIP,CCNP Enterprise

                                1 Reply Last reply Reply Quote 0
                                • I Offline
                                  ikkeniet
                                  last edited by

                                  Well, in my opinion this issue could have been handled better.
                                  At first, it seemed a patch would be made available as "system patch" in pfsense.
                                  But as the fix is kernel based, it can't be made available as a patch?

                                  The patch that was uploaded has since been removed and the mirror has also been deleted.
                                  As said, we now have two options:

                                  1. Install a snapshot, something that is far from ideal on a production system
                                  2. Wait for CE 2.8 release, that can take 6 months+.

                                  Furthermore, IGMP proxy have been plagued with issues in the last CE (and plus) releases.
                                  The previous issue https://redmine.pfsense.org/issues/12079 was never resolved and has been closed due to lack of feedback.
                                  Feedback which could only have been provided after installing a snapshot version.

                                  It's hard to understand why the devs won't release the patched kernel.
                                  I've been without live TV for months now. I'd really like to try a fixed kernel for 2.7.2.

                                  Cheers.

                                  1 Reply Last reply Reply Quote 0
                                  • U Offline
                                    UlfMerbold
                                    last edited by

                                    But why the heck they removed the package?

                                    Install a fixed package is far more secure as going to an full dev snapshot.

                                    They left the userbase alone, paying or not, with an error they made is an slap into our faces.

                                    I need reliability, not just in running pfsense as it is, also in patch quality!
                                    How "good" a business is, we see if we look onto their awarness for such "problems"...and this makes me happy NOT to be in a paid subscription plan

                                    M 1 Reply Last reply Reply Quote 0
                                    • M Offline
                                      mistergefahrensucher @UlfMerbold
                                      last edited by

                                      @UlfMerbold

                                      i'm also disapointed regarding handeling this issue. The rollback from netgate for free Lab/home use of pfsense+ is bad too.
                                      For homeuser paying 129 bugs/year is totally overrated. Yes of course i agree and thought about to pay for support. Maybe like other guys with donation or a small lifetime subscription.
                                      And what i hell should prevent a 3. Party supplier to install pfsense CE on their products and if the byer will have mor support they can bye a subscription.
                                      But as you can see also pfsense+ user are leaved alone. (i had migrated to pfsense+home a while ago, now i'm back at 2.7.0 an stay as long as i can on this version)
                                      If you have a look at other FW creators they, for example SOPHOS they offer home use for free on own hardware. Ok SOPHOS is no and good example. ;)
                                      But they don't fear th dark. They support homeuser because of mind branding. As a homeuser you get the same updates as business user, only the features are smaller.
                                      Netgate shall think about that the community test and find bugs for them as you can see with this issue. To create a 2.7.3 with a fixes Kernal cold not be a geat effort. So where is the problem ?
                                      In the past before netgate this where th case.

                                      1 Reply Last reply Reply Quote 0
                                      • M Offline
                                        michmoor LAYER 8 Rebel Alliance
                                        last edited by

                                        A few weeks ago or maybe a month when this issue was brought up I did post a link here that outlines what the supported packages are in pfsense
                                        https://www.netgate.com/supported-pfsense-plus-packages

                                        There are caveats to this list but the main point being if your package isn’t here it’s not supported. If it is here AND it explicitly states it is supported by Netgate then it’s good to install otherwise stay away from any package .

                                        I agree with all points here and communication should’ve been clearer. Let’s hope they are reading this and provide an update.

                                        Firewall: NetGate,Palo Alto-VM,Juniper SRX
                                        Routing: Juniper, Arista, Cisco
                                        Switching: Juniper, Arista, Cisco
                                        Wireless: Unifi, Aruba IAP
                                        JNCIP,CCNP Enterprise

                                        U 1 Reply Last reply Reply Quote 0
                                        • R Offline
                                          Rai80
                                          last edited by Rai80

                                          I saw my previous link has expired. I just uploaded the patched kernel again to filetransfer.io. For anyone who doesn't want to wait you can download here: https://filetransfer.io/data-package/MEWJVf0K

                                          I'm running this patched kernel now for a few weeks without any problems with IPTV / IGMPProxy

                                          1 Reply Last reply Reply Quote 1
                                          • U Offline
                                            UlfMerbold @michmoor
                                            last edited by UlfMerbold

                                            @michmoor said in IGMP proxy no longer works reliably after 2.7.1 update:

                                            A few weeks ago or maybe a month when this issue was brought up I did post a link here that outlines what the supported packages are in pfsense
                                            https://www.netgate.com/supported-pfsense-plus-packages

                                            There are caveats to this list but the main point being if your package isn’t here it’s not supported. If it is here AND it explicitly states it is supported by Netgate then it’s good to install otherwise stay away from any package .

                                            I agree with all points here and communication should’ve been clearer. Let’s hope they are reading this and provide an update.

                                            The point is, igmpproxy is included(in this case without any addon/package installation), so we can assume its fully supported by the whole appliance.(and changes tested against!)

                                            For sure Netgate are not the maintainers of igmpproxy, but it has to be tested against the changes and in this case something in pfsense-(hardened?)kernel was missing obviously

                                            And if something got broke, a fix must available shorter timelines, esp when its an primary feature for most home users, with payment or not.

                                            The handling of such problems makes the difference of an project claiming "Pro" abilities.
                                            And we use the software cause we believe in the vision of "pfsense", not simply cause its "free"!

                                            And as my personal statement, if i had an subscription plan with Netgate, i wouldnt be just any person. I would be really angry now! Netgate had to fix it in hours cause the new kernel broke the usage, maintainer of this package or not.
                                            Its an routing, firewalling internet appliance, home and business case use...iptv is as much part of this game as firewalling or an vpn-endpoint it does

                                            btw THX Rai80 for the download (fyi got an trojan message from malwarebytes for this download)

                                            1 Reply Last reply Reply Quote 2
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.