Software-update: OPNsense 24.1.2
Het pakket OPNsense is een firewall met uitgebreide mogelijkheden. Het is gebaseerd op het besturingssysteem FreeBSD en is oorspronkelijk een fork van m0n0wall en pfSense. Het pakket kan volledig via een webinterface worden ingesteld en heeft onder andere ondersteuning voor mfa, OpenVPN, IPsec, CARP en captive portal. Daarnaast kan het packetfiltering toepassen en beschikt het over een traffic shaper. De ontwikkelaars hebben OPNsense 24.1.2 uitgebracht en de releasenotes voor die uitgave kunnen hieronder worden gevonden.
OPNsense 24.1.2 releasedIt is time to move back to Suricata version 7 after identifying the relevant default option changes in order to keep IPS/Netmap happy when running it. Kea also received a number of tweaks and updates as well as our VPN service integrations. Last but not least this includes FreeBSD 13.2-p10 and the recent DNS denial of service attack mitigation.
Here are the full patch notes:system: accept colon character in log queriessystem: add issuer and logo to OTP linksystem: fix gateway migration issue causing individual items to be skippedreporting: update traffic graph colors to be contrast and consistent (contributed by brotherla)interfaces: fix strpos() deprecation null haystackinterfaces: add missing ACL entries for ARP/NDP tablesinterfaces: fix VXLAN validationfirewall: change default traffic normalization behavior and choose "in" as standard direction for manual rulesfirewall: make select width more consistent on alias diagnostics table selectiondhcp: set RemoveAdvOnExit to off in CARP mode for router advertisementsdhcp: make sure the register DNS leases options reflect that this is only supported for ISC DHCPdhcp: make option_data_autocollect option more explicit in Keadhcp: gather missing Kea leases another way since the logs are unreliabledhcp: add address constraint to Kea reservationsdhcp: add unique constraint for MAC address + subnet in Keadhcp: add domain-name to client configuration in Keadhcp: loosen constraints for TFTP boot in Keaintrusion detection: adjust for default behaviour changes in Suricata 7ipsec: improve enable button placement on connections pageipsec: show EAP-RADIUS settings only when legacy tunnels are being usedipsec: allow % to support %any in ID for connectionsopenvpn: when "cert_depth" is left empty it should ignore the valueopenvpn: data-ciphers-fallback should be a single optionopenvpn: fix support for /30 p2p/net30 instancesopenvpn: add "various_push_flags" field for simple boolean server push options in connectionsunbound: prevent os.write() on None when another thread closed the pipe in Python modulewireguard: key constraints should only apply on peers and not instanceswireguard: peer uniqueness should depend on pubkey + endpointwireguard: skip attached instance address routeswireguard: remove duplicate ID columnsmvc: fix Phalcon 5.4 and upsrc: jail: fix information leaksrc: bhyveload: use a dirfd to support -hsrc: EVFILT_SIGNAL: do not use target process pointer on detachsrc: setusercontext(): apply personal settings only on matching effective UIDsrc: re: generate an address if there is none in the EEPROMsrc: wg: detect loops in netmap modesrc: wg: detach bpf upon destroy as wellsrc: wg: fix access to noise_local->l_has_identity and l_privatesrc: wg: fix erroneous calculation in calculate_padding() for p_mtu == 0plugins: os-acme-client 4.1plugins: os-ddclient 1.21plugins: os-dnscrypt-proxy 1.15ports: dnsmasq 2.90ports: openvpn 2.6.9ports: phalcon 5.6.1ports: radvd adds upstream patch for RemoveAdvOnExit optionports: suricata 7.0.3ports: unbound 1.19.1
system: accept colon character in log queriessystem: add issuer and logo to OTP linksystem: fix gateway migration issue causing individual items to be skippedreporting: update traffic graph colors to be contrast and consistent (contributed by brotherla)interfaces: fix strpos() deprecation null haystackinterfaces: add missing ACL entries for ARP/NDP tablesinterfaces: fix VXLAN validationfirewall: change default traffic normalization behavior and choose "in" as standard direction for manual rulesfirewall: make select width more consistent on alias diagnostics table selectiondhcp: set RemoveAdvOnExit to off in CARP mode for router advertisementsdhcp: make sure the register DNS leases options reflect that this is only supported for ISC DHCPdhcp: make option_data_autocollect option more explicit in Keadhcp: gather missing Kea leases another way since the logs are unreliabledhcp: add address constraint to Kea reservationsdhcp: add unique constraint for MAC address + subnet in Keadhcp: add domain-name to client configuration in Keadhcp: loosen constraints for TFTP boot in Keaintrusion detection: adjust for default behaviour changes in Suricata 7ipsec: improve enable button placement on connections pageipsec: show EAP-RADIUS settings only when legacy tunnels are being usedipsec: allow % to support %any in ID for connectionsopenvpn: when "cert_depth" is left empty it should ignore the valueopenvpn: data-ciphers-fallback should be a single optionopenvpn: fix support for /30 p2p/net30 instancesopenvpn: add "various_push_flags" field for simple boolean server push options in connectionsunbound: prevent os.write() on None when another thread closed the pipe in Python modulewireguard: key constraints should only apply on peers and not instanceswireguard: peer uniqueness should depend on pubkey + endpointwireguard: skip attached instance address routeswireguard: remove duplicate ID columnsmvc: fix Phalcon 5.4 and upsrc: jail: fix information leaksrc: bhyveload: use a dirfd to support -hsrc: EVFILT_SIGNAL: do not use target process pointer on detachsrc: setusercontext(): apply personal settings only on matching effective UIDsrc: re: generate an address if there is none in the EEPROMsrc: wg: detect loops in netmap modesrc: wg: detach bpf upon destroy as wellsrc: wg: fix access to noise_local->l_has_identity and l_privatesrc: wg: fix erroneous calculation in calculate_padding() for p_mtu == 0plugins: os-acme-client 4.1plugins: os-ddclient 1.21plugins: os-dnscrypt-proxy 1.15ports: dnsmasq 2.90ports: openvpn 2.6.9ports: phalcon 5.6.1ports: radvd adds upstream patch for RemoveAdvOnExit optionports: suricata 7.0.3ports: unbound 1.19.1
Source:
Tweakers.net