Software-update: OPNsense 26.7.4
Het pakket OPNsense is een firewall met uitgebreide mogelijkheden. Het is gebaseerd op het besturingssysteem FreeBSD en is oorspronkelijk een fork van m0n0wall en pfSense. Het pakket kan volledig via een webinterface worden ingesteld en heeft onder andere ondersteuning voor mfa, OpenVPN, IPsec, CARP en captive portal. Daarnaast kan het packetfiltering toepassen en beschikt het over een traffic shaper. De ontwikkelaars achter OPNsense hebben de vierde update voor versie 26.7 uitgebracht en de releasenotes voor die uitgave kunnen hieronder worden gevonden.
OPNsense 26.7.4 releasedToday we are rolling out the wireless device MVC/API rework and a final push for better source NAT replacement over outbound NAT. Strongswan was updated to 6.1.0 and the GUI now offers a small recommended set of post-quantum key exchanges. You may also find the GUI tweaks for advanced option marker and a dialog search field helpful. There is a lot more going on as you can see from this changelog, but more on this and future plans later!
Here are the full patch notes:system: audit log injection via login username in auth_log()system: add pfsync version 1500 to HA settingssystem: add hidden services so they can be operated by pluginctl -ssystem: privlege separated reload in static PHP pagessystem: lower priority of automatic wg/ipsec gatewayssystem: fix disk widget loading issuesystem: add back the service widget linksystem: make compare operator in authTOTP() more strictinterfaces: migrate wireless configuration to MVC/APIinterfaces: return an empty string which cannot be an interface in convert_real_interface_to_friendly_interface_name()interfaces: ppp-ipv6.php may be executed before later stages of interface_configure()interfaces: provide "uuid" in legacy_config_get_interfaces()interfaces: split media and mediaopt with tabs instead of spacesinterfaces: a few config_read_array() replacementsinterfaces: refactor device matching around interface_parent_devices()interfaces: remove cua matching from PPP device patternfirewall: source NAT: add pool options and source hash keyfirewall: source NAT: fix port alias and well known port usage in target_portfirewall: make source and destination NAT automatic rules visible in GUIfirewall: implement JsonAuditField in all MVC componentsfirewall: update the internally reserved pf keywords for FreeBSD 15firewall: add source NAT migration banner to outbound NATfirewall: add private network exclusions to default IPv6 bogonsdnsmasq: leases sorting fixesfirmware: opnsense-bootstrap: fix bootstrap on FreeBSD 15 with pkgbasefirmware: opnsense-prefetch: new tool for sets prefetchingfirmware: opnsense-sign: shell compatibility updatefirmware: adjust the incompatible pkg testfirmware: disable FreeBSD-base repository and remove old definitionsintrusion detection: fix displaying URL in descriptionsipsec: add some hybrid post-quantum variants as additional key exchangekea: fix leases sortingopenvpn: moved legacy CARP hook to os-openvpn-legacy pluginacl: fix API patters for GIF/GRE device settingsacl: add missing and fix some issuesbackend: add CLOEXEC to a few file descriptor opens to avoid lock inheritancemvc: advanced marker for form/dialog fieldsmvc: fix stale imports for Message classesmvc: JsonAduditField: shared implementation for configuration revision trackingrc: add watchdog to shutdown, reboot and reload_all casesui: fix widget bottom gap in standard theme filesui: sidebar fixes and reworkui: remove spurious _formDialog portion of dialog IDsui: implement dialog search fieldui: ensure a minimum amount of rows to render in gridsplugins: os-acme-client 4.17plugins: os-theme-rebellion 1.9.8plugins: os-turnserver 1.4src: ciss: revert patch that added max physical targetsrc: pf: do not set a null rule pointer during testsrc: pf: fix securelevel off-by-onesrc: pfctl: fix printing of wildcard anchorssrc: e1000: more assorted upstream patches from stable/15src: ixgbe: assorted upstream patches from stable/15src: virtio_p9fs: disallow detach if a session is in progresssrc: route/fib_algo: free leaked radix_masks in radix_locklesssrc: netipsec: implement pr_disconnect for PF_KEY socketssrc: iflib: assorted upstream patches from stable/15src: net: add ifmedia support for 10GBase-BX BiDisrc: bnxt: report initialization failures to iflibsrc: bnxt: add led(4) identification supportsrc: ice: add led(4) identification supportsrc: ice: report initialization failures to iflibsrc: ice: add support for E835 CNSA 2.0 adapterssrc: ice: add two more 4-part IDs for E835 adapterssrc: if_vxlan: fix panic by validating unused drvspec valuessrc: qat: driver updates to enhance qat infrastructuresrc: ath10k: remove some early FreeBSD-specific debuggingsrc: ip(6)_mroute: assorted upstream patches from stable/15src: in_mcast: fix uninitialized variable usage in inm_merge()src: bind: lookup local address in current FIB if '*.bind_all_fibs' is activesrc: net: add fib-aware ifa_ifwithaddr()ports: ca_root_nss / nss 3.129ports: curl 8.22.0ports: dhcp6c fix for truncated env vars in dhcp6c-scriptports: expat 2.8.4ports: filterlog 0.9 support for pflog actions on FreeBSD 15ports: libxml 2.15.4ports: openldap 2.6.15ports: pcre2 10.48ports: php 8.5.10ports: phpseclib 3.0.57ports: strongswan 6.1.0
system: audit log injection via login username in auth_log()system: add pfsync version 1500 to HA settingssystem: add hidden services so they can be operated by pluginctl -ssystem: privlege separated reload in static PHP pagessystem: lower priority of automatic wg/ipsec gatewayssystem: fix disk widget loading issuesystem: add back the service widget linksystem: make compare operator in authTOTP() more strictinterfaces: migrate wireless configuration to MVC/APIinterfaces: return an empty string which cannot be an interface in convert_real_interface_to_friendly_interface_name()interfaces: ppp-ipv6.php may be executed before later stages of interface_configure()interfaces: provide "uuid" in legacy_config_get_interfaces()interfaces: split media and mediaopt with tabs instead of spacesinterfaces: a few config_read_array() replacementsinterfaces: refactor device matching around interface_parent_devices()interfaces: remove cua matching from PPP device patternfirewall: source NAT: add pool options and source hash keyfirewall: source NAT: fix port alias and well known port usage in target_portfirewall: make source and destination NAT automatic rules visible in GUIfirewall: implement JsonAuditField in all MVC componentsfirewall: update the internally reserved pf keywords for FreeBSD 15firewall: add source NAT migration banner to outbound NATfirewall: add private network exclusions to default IPv6 bogonsdnsmasq: leases sorting fixesfirmware: opnsense-bootstrap: fix bootstrap on FreeBSD 15 with pkgbasefirmware: opnsense-prefetch: new tool for sets prefetchingfirmware: opnsense-sign: shell compatibility updatefirmware: adjust the incompatible pkg testfirmware: disable FreeBSD-base repository and remove old definitionsintrusion detection: fix displaying URL in descriptionsipsec: add some hybrid post-quantum variants as additional key exchangekea: fix leases sortingopenvpn: moved legacy CARP hook to os-openvpn-legacy pluginacl: fix API patters for GIF/GRE device settingsacl: add missing and fix some issuesbackend: add CLOEXEC to a few file descriptor opens to avoid lock inheritancemvc: advanced marker for form/dialog fieldsmvc: fix stale imports for Message classesmvc: JsonAduditField: shared implementation for configuration revision trackingrc: add watchdog to shutdown, reboot and reload_all casesui: fix widget bottom gap in standard theme filesui: sidebar fixes and reworkui: remove spurious _formDialog portion of dialog IDsui: implement dialog search fieldui: ensure a minimum amount of rows to render in gridsplugins: os-acme-client 4.17plugins: os-theme-rebellion 1.9.8plugins: os-turnserver 1.4src: ciss: revert patch that added max physical targetsrc: pf: do not set a null rule pointer during testsrc: pf: fix securelevel off-by-onesrc: pfctl: fix printing of wildcard anchorssrc: e1000: more assorted upstream patches from stable/15src: ixgbe: assorted upstream patches from stable/15src: virtio_p9fs: disallow detach if a session is in progresssrc: route/fib_algo: free leaked radix_masks in radix_locklesssrc: netipsec: implement pr_disconnect for PF_KEY socketssrc: iflib: assorted upstream patches from stable/15src: net: add ifmedia support for 10GBase-BX BiDisrc: bnxt: report initialization failures to iflibsrc: bnxt: add led(4) identification supportsrc: ice: add led(4) identification supportsrc: ice: report initialization failures to iflibsrc: ice: add support for E835 CNSA 2.0 adapterssrc: ice: add two more 4-part IDs for E835 adapterssrc: if_vxlan: fix panic by validating unused drvspec valuessrc: qat: driver updates to enhance qat infrastructuresrc: ath10k: remove some early FreeBSD-specific debuggingsrc: ip(6)_mroute: assorted upstream patches from stable/15src: in_mcast: fix uninitialized variable usage in inm_merge()src: bind: lookup local address in current FIB if '*.bind_all_fibs' is activesrc: net: add fib-aware ifa_ifwithaddr()ports: ca_root_nss / nss 3.129ports: curl 8.22.0ports: dhcp6c fix for truncated env vars in dhcp6c-scriptports: expat 2.8.4ports: filterlog 0.9 support for pflog actions on FreeBSD 15ports: libxml 2.15.4ports: openldap 2.6.15ports: pcre2 10.48ports: php 8.5.10ports: phpseclib 3.0.57ports: strongswan 6.1.0
Source:
Tweakers.net