Software-update: OPNsense 26.1.2
Het pakket OPNsense is een firewall met uitgebreide mogelijkheden. Het is gebaseerd op het besturingssysteem FreeBSD en is oorspronkelijk een fork van m0n0wall en pfSense. Het pakket kan volledig via een webinterface worden ingesteld en heeft onder andere ondersteuning voor mfa, OpenVPN, IPsec, CARP en captive portal. Daarnaast kan het packetfiltering toepassen en beschikt het over een traffic shaper. De ontwikkelaars achter OPNsense hebben versie 26.1.2 uitgebracht en de releasenotes voor die uitgave kunnen hieronder worden gevonden.
OPNsense 26.1.2 releasedThis is a smallish update with a number of fixes and another round of Python CVEs addressed. New images based on this stable version are planned for next week. At the moment work focuses on the IPv6 support for the captive portal which should not be too far away now. The 26.7 roadmap will also be published at the end of this month.
Here are the full patch notes:system: remove "upstream" from gateway grid as priority already reflects the proper datasystem: adjust gateway group priority (tier) wordinginterfaces: fix wlanmode argument usagefirewall: fix target mapping inconsistency leading to references not being processed in destination NATfirewall: use local-port as target when specified in destination NATfirewall: fix missing reply-to when not specifically set in new rulesfirewall: live view: fix parsing of combined filters stored as converted stringsfirewall: fix group rename in source_net, destination_net and SNAT/DNAT target fieldsfirewall: add tcpflags_any in new rules GUI for parity with legacy rulesfirewall: exclude loopback from interface selectpicker in new rules GUIfirewall: well known ports added to filter rule selectionfirewall: undefined is also "*" in new rules gridfirewall: add download button for validation errors in rule importfirewall: allow TTL usage on host entriesfirmware: avoid update-hook background cleanupsfirmware: revoke 25.7 fingerprintkea: fix subnets GUI missing root noderadvd: change tabs to spaces in radvd.conf for better maintenanceunbound: safeguard the blocklist tester against empty configuration testingmvc: add $separator as parameter for CSV export and switch the default to a semicolonmvc: InterfaceField: minor adjustments and add resetStaticOptionList()mvc: catch empty data in CSV importtests: Shell: add testing frameworkplugins: os-haproxy 5.0ports: expat 2.7.4ports: hostwatch 1.0.12 now rate-limits database writes for recently seen hostsports: ldns 1.9.0ports: nss 3.120ports: openldap 2.6.12ports: openvpn 2.6.19ports: py-duckdb 1.4.4ports: python additional security fixes
system: remove "upstream" from gateway grid as priority already reflects the proper datasystem: adjust gateway group priority (tier) wordinginterfaces: fix wlanmode argument usagefirewall: fix target mapping inconsistency leading to references not being processed in destination NATfirewall: use local-port as target when specified in destination NATfirewall: fix missing reply-to when not specifically set in new rulesfirewall: live view: fix parsing of combined filters stored as converted stringsfirewall: fix group rename in source_net, destination_net and SNAT/DNAT target fieldsfirewall: add tcpflags_any in new rules GUI for parity with legacy rulesfirewall: exclude loopback from interface selectpicker in new rules GUIfirewall: well known ports added to filter rule selectionfirewall: undefined is also "*" in new rules gridfirewall: add download button for validation errors in rule importfirewall: allow TTL usage on host entriesfirmware: avoid update-hook background cleanupsfirmware: revoke 25.7 fingerprintkea: fix subnets GUI missing root noderadvd: change tabs to spaces in radvd.conf for better maintenanceunbound: safeguard the blocklist tester against empty configuration testingmvc: add $separator as parameter for CSV export and switch the default to a semicolonmvc: InterfaceField: minor adjustments and add resetStaticOptionList()mvc: catch empty data in CSV importtests: Shell: add testing frameworkplugins: os-haproxy 5.0ports: expat 2.7.4ports: hostwatch 1.0.12 now rate-limits database writes for recently seen hostsports: ldns 1.9.0ports: nss 3.120ports: openldap 2.6.12ports: openvpn 2.6.19ports: py-duckdb 1.4.4ports: python additional security fixes
Source:
Tweakers.net