Software-update: OPNsense 23.1.8
Het pakket OPNsense is een firewall met uitgebreide mogelijkheden. Het is gebaseerd op het besturingssysteem FreeBSD en is oorspronkelijk een fork van m0n0wall en pfSense. Het pakket kan volledig via een webinterface worden ingesteld en heeft onder andere ondersteuning voor 2fa, openvpn, ipsec, carp en captive portal. Daarnaast kan het packetfiltering toepassen en beschikt het over een traffic shaper. De ontwikkelaars hebben OPNsense 23.1.8 uitgebracht en de releasenotes voor die uitgave kunnen hieronderworden gevonden.
OPNsense 23.1.8 releasedThis update improves IPv6 connectivity, extends module support for the axgbe network driver and fixes a panic with IPv6 refragmentation over policy-based routes amongst others. We are currently testing FreeBSD 13.2 for the upcoming OPNsense 23.7 and it looks promising. Watch out for roadmap updates over the next few weeks as more MVC page conversions are being carried out.
Here are the full patch notes:system: calling return_down_gateways() depends on default gateway switch settingsystem: open new session if missing to prevent spurious CRSF errors in static pagessystem: add device hint to empty interface address message in case of mismatch during default route attemptsystem: add kernel messages to the general system logsystem: make sure routing log messages all use "ROUTING:" prefixsystem: print warning for duplicated gateway namesystem: prefix API key filename with FQDN of this hostinterfaces: deal with "prefixv6" as an arrayinterfaces: improve address cleanup when handling VIP modificationsinterfaces: explicitly report current IP address during renewal avoidanceinterfaces: patch in appropriate rebind/renew DHCPv6 handlinginterfaces: for static "Use IPv4 connectivity" on PPPoE bring up IPv6 routes as wellinterfaces: ifctl: fix typo causing content to be printed while adding itinterfaces: ifctl: avoid null route on fragile /64 prefix delegationinterfaces: ifctl: do not flush name server routesfirewall: add "set debug" and "set keepcounters" options to advanced optionsdhcp: provide run task "static_mapping" to avoid polluting unrelated pluginsdnsmasq: use new run task "static_mapping" to collect static mappings from DHCPfirmware: show support tiers in plugin listfirmware: now that we have a full data model do not overdo cleanup during plugin registrationintrusion detection: minor performance improvements when parsing metadata from rulesopenvpn: fix a warning by passing a desirable empty input containing a slashunbound: fix migration edge case in model version 1.0.3unbound: remove DNS blocklist start syshook causing an unnecessary download during bootupunbound: when called via GET during override creation encode using URLSearchParams()wizard: do not end up duplicating WAN_GW entrymvc: add CIDRToMask() to utilitiesmvc: prevent config restore when writer has flushed or partly written the filemvc: format BaseModel logger to avoid duplicate timestampsplugins: os-crowdsec 1.0.5plugins: os-acme-client 3.17src: axgbe: fix link issues for gigabit external SFP PHYs and 100/1000 fiber modulessrc: axgbe: apply RRC to miibus attached PHYs and add support for variable bitrate 25G SFP+ DACssrc: axgbe: properly release resource in error casesrc: ifconfig: improve VLAN identifier parsingsrc: pfsync: hold b_mtx for callout_stop(pd_tmo)src: pf: remove pd_refs from pfsyncsrc: pf: deal with KPI change bug on stable/13 by redirecting otherwise crashing traffic through ip6_output()ports: curl 8.1.0ports: dhcp6c 20230523ports: lighttpd 1.4.70ports: nss 3.89.1ports: openvpn 2.6.4ports: php 8.1.19ports: suricata 6.0.12
system: calling return_down_gateways() depends on default gateway switch settingsystem: open new session if missing to prevent spurious CRSF errors in static pagessystem: add device hint to empty interface address message in case of mismatch during default route attemptsystem: add kernel messages to the general system logsystem: make sure routing log messages all use "ROUTING:" prefixsystem: print warning for duplicated gateway namesystem: prefix API key filename with FQDN of this hostinterfaces: deal with "prefixv6" as an arrayinterfaces: improve address cleanup when handling VIP modificationsinterfaces: explicitly report current IP address during renewal avoidanceinterfaces: patch in appropriate rebind/renew DHCPv6 handlinginterfaces: for static "Use IPv4 connectivity" on PPPoE bring up IPv6 routes as wellinterfaces: ifctl: fix typo causing content to be printed while adding itinterfaces: ifctl: avoid null route on fragile /64 prefix delegationinterfaces: ifctl: do not flush name server routesfirewall: add "set debug" and "set keepcounters" options to advanced optionsdhcp: provide run task "static_mapping" to avoid polluting unrelated pluginsdnsmasq: use new run task "static_mapping" to collect static mappings from DHCPfirmware: show support tiers in plugin listfirmware: now that we have a full data model do not overdo cleanup during plugin registrationintrusion detection: minor performance improvements when parsing metadata from rulesopenvpn: fix a warning by passing a desirable empty input containing a slashunbound: fix migration edge case in model version 1.0.3unbound: remove DNS blocklist start syshook causing an unnecessary download during bootupunbound: when called via GET during override creation encode using URLSearchParams()wizard: do not end up duplicating WAN_GW entrymvc: add CIDRToMask() to utilitiesmvc: prevent config restore when writer has flushed or partly written the filemvc: format BaseModel logger to avoid duplicate timestampsplugins: os-crowdsec 1.0.5plugins: os-acme-client 3.17src: axgbe: fix link issues for gigabit external SFP PHYs and 100/1000 fiber modulessrc: axgbe: apply RRC to miibus attached PHYs and add support for variable bitrate 25G SFP+ DACssrc: axgbe: properly release resource in error casesrc: ifconfig: improve VLAN identifier parsingsrc: pfsync: hold b_mtx for callout_stop(pd_tmo)src: pf: remove pd_refs from pfsyncsrc: pf: deal with KPI change bug on stable/13 by redirecting otherwise crashing traffic through ip6_output()ports: curl 8.1.0ports: dhcp6c 20230523ports: lighttpd 1.4.70ports: nss 3.89.1ports: openvpn 2.6.4ports: php 8.1.19ports: suricata 6.0.12
Source:
Tweakers.net