26.07 New Features and Changes

This is a regularly scheduled software release including new features and bug fixes.

Tip

Review the Upgrade Guide before performing any upgrade of pfSense software.

Netgate Nexus

This release contains new features exclusive to Netgate Nexus: CoreDNS, ThreatGate, and Snort 3.

CoreDNS

CoreDNS is an integrated component of Netgate Nexus which handles DNS-based tasks with extremely high performance. This component is based on the CoreDNS Project, but the functionality in Netgate Nexus is primarily focused on a new and exclusive CoreDNS plugin created by Netgate called rexdns.

ThreatGate

ThreatGate is an integrated component of Netgate Nexus which manages bulk lists of addresses and domains for use with firewall rules, aliases, and CoreDNS groups with high performance. ThreatGate collects addresses from internal and remote feeds and can block them entirely or allow administrators to build their own rules based on the content.

ThreatGate and CoreDNS were designed to integrate together and this allows them to quickly process and utilize huge lists of addresses even on small devices with low resources.

Snort 3

Snort version 3 is a new version of the popular open-source intrusion prevention system (IPS). It features a GUI redesigned from the ground-up, multi-threading support, and a faster rule syntax. Snort 3 is now available exclusively via the new Netgate Nexus controller GUI.

pfSense Plus

Changes in this version of pfSense Plus software.

Aliases / Tables

  • Fixed: URL tables cannot import content from tgz file URLs #16964

Captive Portal

  • Fixed: Captive Portal authentication failures from usernames containing special characters or long strings can cause ambiguous or confusing log messages #16922

DHCP (IPv4)

  • Added: Option to control Kea log level #16230

  • Changed: Kea attempts DNS Registration when Unbound is disabled #16865

DHCP Relay

  • Fixed: DHCP relay does not respect configured CARP VIP status #15017

DNS Resolver

  • Fixed: Unbound configuration may be generated with duplicate interface bindings #16906

Diagnostics

  • Changed: Add device_key to filtered tags list for status output #16959

Dynamic DNS

  • Fixed: All-Inkl Dynamic DNS responses are not parsed correctly #16218

  • Changed: Encode Dynamic DNS credentials when passed as URL parameters #16905

Gateway Monitoring

  • Changed: Improve gateway status consistency #16707

Gateways

  • Changed: Improve default gateway detection when gateways share the same address #16816

  • Fixed: Static route not removed when enabling dpinger_dont_add_static_route while a gateway monitor IP address is set #16861

IPsec

  • Fixed: IPsec Keep Alive does not update the gateway status #15087

IPv6 Router Advertisements (radvd/rtsold)

  • Fixed: IPv6 Track Interfaces ignores the Disabled Router Advertisements mode #16925

Interfaces

  • Fixed: VXLAN interfaces are configured with an incorrect MTU after re-saving their parent interface #16823

  • Added: Set IP Alias VIP as the Router Advertisement source #16914

OpenVPN

  • Fixed: Alert about missing MTU settings for OpenVPN DCO tunnels on every boot #16938

  • Fixed: RADIUS authentication fails when attribute contains an invalid ACL #16863

Operating System

  • Fixed: Kernel on armv7 can fail to parse loader configuration files #16746

  • Fixed: Loader menu does not display the logo properly #16726

RRD Graphs

  • Fixed: Multiple updaterrd.sh processes #16927

Rules / NAT

  • Fixed: Cannot add Port Forward with an unassociated filter rule #15346

  • Fixed: Same port forward on multiple WANs can generate a PF error due to Pure NAT mode NAT reflection #16783

  • Changed: Retain a copy of the failed ruleset when a filter reload fails #16796

  • Fixed: Filter rules created as part of NAT rules can have an invalid protocol value #16954

SNMP

  • Fixed: Memory leak in libpfctl causes bsnmpd memory usage to grow over time #16456

System Logs

  • Changed: Exclude nginx logs from system.log #16826

Traffic Graphs

  • Fixed: Traffic Graphs display option “Description” does not utilize DHCP static mapping descriptions #16979

Traffic Shaper (ALTQ)

  • Fixed: Traffic Shaper Wizard duplicates all firewall rules when no shaping options are enabled #16866

Wake on LAN

  • Changed: “Wake All” functionality on services_wol.php should only use POST #16961

Wireless

  • Fixed: Interfaces Status shows an invalid SSID value for Wi-Fi interfaces #16769