Software-update: OPNsense 24.1.4
Het pakket OPNsense is een firewall met uitgebreide mogelijkheden. Het is gebaseerd op het besturingssysteem FreeBSD en is oorspronkelijk een fork van m0n0wall en pfSense. Het pakket kan volledig via een webinterface worden ingesteld en heeft onder andere ondersteuning voor mfa, OpenVPN, IPsec, CARP en captive portal. Daarnaast kan het packetfiltering toepassen en beschikt het over een traffic shaper. De ontwikkelaars hebben OPNsense 24.1.3 uitgebracht en de releasenotes voor die uitgave kunnen hieronder worden gevonden.
OPNsense 24.1.4 releasedSuricata and Unbound have been updated to their latest versions. Support for dynamic DNS VTI connections has also been added amongst other things. We would like to thank Cedrik Pischem (Monviech) for upstreaming his Caddy plugin to the official packages. If you already have this plugin installed no further action has to be taken and updates should proceed through the standard firmware channel from now on. Documentation for it was added to the manual as well.
For 24.7, we are currently working on a DHCP-Relay replacement, a rewrite of the trust section in MVC as well as a new dashboard implementation. It has been busy and we will keep it that way.
Here are the full patch notes:system: allow 0 length voucher passwords in authentication serversystem: merge static logging settings into existing MVC pagesystem: fix handling of empty "serialusb" node set during importsystem: prevent empty "user" node to crash during bootinterfaces: prevent modal x-axis overflow on packet capture pagefirewall: refactor schedule matching and fix an end-of-the-month bugfirewall: fix incorrect packet counters statistics collectionintrusion detection: align performValidation()->count() to use count() insteadipsec: optionally hook VTI tunnel configuration to connection up event to support dynamic DNSisc-dhcp: do not add interfaces for non-Ethernet types to relayingkea-dhcp: add domain-search, time-servers and static-routes client options to subnet configurationopenvpn: various improvements for TAP serverswireguard: migrate non-netmask allowed IP entries and enforce them in validationwireguard: show proper names when public keys overlap between instancesmvc: fix PHP_FLOAT_MIN being unreliablemvc: Add simple Message class and remove the previous Phalcon dependencymvc: refactor HostnameField, remove HostValidator dependency and add unit testmvc: add new static Autoconf class to access information collected by ifctlmvc: fix rewind() stream not supporting seeking errormvc: add copy of our html_safe() and use it in the translatorui: adjust margin of hr elements to match __mX helpersui: add a button to allow textarea style edits of free-form tokenizersui: when an error is raised make sure it is always visibleui: fix copy/paste buttons not showing for tokenizers in some situationsplugins: os-bind 1.30plugins: os-caddy 1.5.2ports: expat 2.6.1ports: libpfctl 0.10ports: nss 3.98ports: phalcon 5.6.2ports: sqlite 3.45.1ports: suricata 7.0.4ports: unbound 1.19.3
system: allow 0 length voucher passwords in authentication serversystem: merge static logging settings into existing MVC pagesystem: fix handling of empty "serialusb" node set during importsystem: prevent empty "user" node to crash during bootinterfaces: prevent modal x-axis overflow on packet capture pagefirewall: refactor schedule matching and fix an end-of-the-month bugfirewall: fix incorrect packet counters statistics collectionintrusion detection: align performValidation()->count() to use count() insteadipsec: optionally hook VTI tunnel configuration to connection up event to support dynamic DNSisc-dhcp: do not add interfaces for non-Ethernet types to relayingkea-dhcp: add domain-search, time-servers and static-routes client options to subnet configurationopenvpn: various improvements for TAP serverswireguard: migrate non-netmask allowed IP entries and enforce them in validationwireguard: show proper names when public keys overlap between instancesmvc: fix PHP_FLOAT_MIN being unreliablemvc: Add simple Message class and remove the previous Phalcon dependencymvc: refactor HostnameField, remove HostValidator dependency and add unit testmvc: add new static Autoconf class to access information collected by ifctlmvc: fix rewind() stream not supporting seeking errormvc: add copy of our html_safe() and use it in the translatorui: adjust margin of hr elements to match __mX helpersui: add a button to allow textarea style edits of free-form tokenizersui: when an error is raised make sure it is always visibleui: fix copy/paste buttons not showing for tokenizers in some situationsplugins: os-bind 1.30plugins: os-caddy 1.5.2ports: expat 2.6.1ports: libpfctl 0.10ports: nss 3.98ports: phalcon 5.6.2ports: sqlite 3.45.1ports: suricata 7.0.4ports: unbound 1.19.3
Source:
Tweakers.net