Software-update: OPNsense 23.1.4
Het pakket OPNsense is een firewall met uitgebreide mogelijkheden. Het is gebaseerd op het besturingssysteem FreeBSD en is oorspronkelijk een fork van m0n0wall en pfSense. Het pakket kan volledig via een webinterface worden ingesteld en heeft onder andere ondersteuning voor 2fa, openvpn, ipsec, carp en captive portal. Daarnaast kan het packetfiltering toepassen en beschikt het over een traffic shaper. De ontwikkelaars hebben OPNsense 23.1.4 uitgebracht en deze versie gaat vergezeld met de volgende aantekeningen:
OPNsense 23.1.4 releasedAnother stable update to fix a StrongSwan regression and two OpenVPN incompatibilities introduced prior. We have also improved the service handling code in multiple areas, fixed issues like the VIP migration problem with IP alias on a CARP VIP and improved/simplified the firmware settings now that cryptography flavours no longer exist.
Here are the full patch notes:system: address a number of web GUI startup problemssystem: service handling refactor, tweaks and improvementssystem: rework killbypid()/killbyname() behavioursystem: use system_resolver_configure() everywherereporting: simplify state collection for system-states.rrdinterfaces: fix an issue with a batch killbyname() in static ARP caseinterfaces: make sure output buffering is disabled when downloading a packet captureinterfaces: lock gateway save button while the request is being processedinterfaces: fix IP alias with VHID validation issuedhcp: several plumbing improvements in service handlingdnsmasq: remove now unused host configuration and refactorfirmware: responsiveness fix (contributed by kulikov-a)firmware: move settings handling to full-fledged modelfirmware: add advanced/help toggles, cancel button, subscription errorsmonit: add permanent include statement for custom configuration files (contributed by codiflow)openvpn: add ovpn_status.py script and configd action to fetch connected clientsopenvpn: reintroduce "cipher" keyword for older clientsopenvpn: add missing static-challenge parsing for auth framework introduced in 23.1.3unbound: adhere to restart logic during hosts configure and wait for service to startunbound: add infra-keep-probing advanced optionunbound: lowercase domain for case insensitive search in blocklistsmvc: fix PHP warnings and dance around null/0.0.0 ambiguity in migration codeplugins: os-api-backup 1.1plugins: os-theme-cicada 1.34 (contributed by Team Rebellion)plugins: os-theme-tukan 1.27 (contributed by Team Rebellion)plugins: os-theme-vicuna 1.45 (contributed by Team Rebellion)ports: curl 7.88.1ports: nss 3.89ports: php 8.1.17ports: py-vici 5.9.10ports: squid 5.8ports: strongswan EAP-TLS upstream fix
system: address a number of web GUI startup problemssystem: service handling refactor, tweaks and improvementssystem: rework killbypid()/killbyname() behavioursystem: use system_resolver_configure() everywherereporting: simplify state collection for system-states.rrdinterfaces: fix an issue with a batch killbyname() in static ARP caseinterfaces: make sure output buffering is disabled when downloading a packet captureinterfaces: lock gateway save button while the request is being processedinterfaces: fix IP alias with VHID validation issuedhcp: several plumbing improvements in service handlingdnsmasq: remove now unused host configuration and refactorfirmware: responsiveness fix (contributed by kulikov-a)firmware: move settings handling to full-fledged modelfirmware: add advanced/help toggles, cancel button, subscription errorsmonit: add permanent include statement for custom configuration files (contributed by codiflow)openvpn: add ovpn_status.py script and configd action to fetch connected clientsopenvpn: reintroduce "cipher" keyword for older clientsopenvpn: add missing static-challenge parsing for auth framework introduced in 23.1.3unbound: adhere to restart logic during hosts configure and wait for service to startunbound: add infra-keep-probing advanced optionunbound: lowercase domain for case insensitive search in blocklistsmvc: fix PHP warnings and dance around null/0.0.0 ambiguity in migration codeplugins: os-api-backup 1.1plugins: os-theme-cicada 1.34 (contributed by Team Rebellion)plugins: os-theme-tukan 1.27 (contributed by Team Rebellion)plugins: os-theme-vicuna 1.45 (contributed by Team Rebellion)ports: curl 7.88.1ports: nss 3.89ports: php 8.1.17ports: py-vici 5.9.10ports: squid 5.8ports: strongswan EAP-TLS upstream fix
Source:
Tweakers.net