Software-update: OPNsense 26.7
Het pakket OPNsense is een firewall met uitgebreide mogelijkheden. Het is gebaseerd op het besturingssysteem FreeBSD en is oorspronkelijk een fork van m0n0wall en pfSense. Het pakket kan volledig via een webinterface worden ingesteld en heeft onder andere ondersteuning voor mfa, OpenVPN, IPsec, CARP en captive portal. Daarnaast kan het packetfiltering toepassen en beschikt het over een traffic shaper. De ontwikkelaars achter OPNsense hebben versie 26.7 uitgebracht en de releasenotes voor die uitgave kunnen hieronder worden gevonden.
OPNsense 26.71 releasedFor over 11 a half years now, OPNsense is driving innovation through modularising and hardening the open source firewall, with simple and reliable firmware upgrades, multi-language support, fast adoption of upstream software updates, modern IPv6 support, as well as clear and stable 2-Clause BSD licensing.
26.7, nicknamed "Xenial Xenops", features interface assignments and gateway groups via MVC/API, firewall rules now defaulting to MVC/API, outbound NAT to source NAT migration assistant, captive portal IPv6 support, Kea DDNS/custom options/dynamic prefix delegation, FreeBSD 15.1, OpenVPN 2.7, PHP 8.5, Python 3.13, plus much more.
The upgrade path for 26.1 will likely be unlocked later today. We want to ensure the upgrade goes as smoothly as possible so please be patient! :)
Here are the full patch notes:system: remove periodic backups settings and backend codesystem: migrate gateway groups to MVC/APIsystem: new service widget flat tile layout (partially contributed by Konstantinos Spartalis)system: make LDAP auth adhere to bad login penalty as well (contributed by Matt Andreko)system: move ldap_escape() to caller for now to avoid side effectssystem: improve the log_archive script to also work on log subdirectoriessystem: change our version of "certctl" to emit files instead of links like it is the case in FreeBSD 15.1system: include interfaces widget in dashboard defaultsystem: adjust dashboard widget resize logic to observe border box instead of content boxreporting: migrate several settings pages to MVC/API and assorted changesreporting: do not show disabled interfaces in traffic graphs (contributed by Konstantinos Spartalis)interfaces: migrate interface assignments to MVC/APIinterfaces: fix faulty netmask on loopback address due to upstream changefirmware: remove overzealous cleansing in output_cmd to unhide individual character progressfirewall: move config.xml default LAN allow rules to new rules GUIfirewall: legacy rules pages move to pluginfirewall: restrict automatic DHCPv6 filter rules to plugin/track6 usefirewall: always set a sequence at the end of the rule set when cloning a NAT rulefirewall: remove unused "safepoint" actionsfirewall: fix automatic source NAT rules not displayed for PPPoE interfacesfirewall: flatten automatic source NAT rules into two per WAN type interfacefirewall: prevent deletion if a group is referenced in MVC rulesfirewall: constraint source NAT getAction() to only general page and align setAction() accordinglyfirewall: use proper path for one-to-one NAT rules for renaming operationsfirewall: avoid emitting reply-to on block rules as wellfirewall: change interface group render/apply orderfirewall: adjust MVC alias rename according to address_to_pconfig()firewall: adapt getAdvancedIds() to the sectioned form structurefirewall: invalidate rule stats cache for firewall utilities API endpointcaptive portal: move template actions out of the ServiceController into its own TemplateControllercaptive portal: adjust accounting interval to Acct-Interim-Intervaldnsmasq: possible use before define in lease watcherintrusion detection: rename "uncategorized" rule package to "adult" (contributed by Konstantinos Spartalis)monit: fix mail-format and poll-time validationunbound: missing NetMaskAllowed=N on override addresswireguard: add allowed-ips to reresolve-dns.py in case none are set yetacl: merge user management ACLs into one single privilegebackend: allow "strict" mode +TARGETS using the preamble "!"backend: swap "strict" template logic as it was reversedmvc: refactor base_dialog and parseFormNode() to simplify the templatemvc: remove unused argument from getFormGrid()mvc: BaseField: emit descriptions in getNodes() when they are not the same as the value to match getNodeContent()mvc: PortField: reject whitespaces in port ranges during validationmvc: ModelRelationField: remove grouped option handlingmvc: add file type to formsui: add "opnsense-auto" theme which switches between "opnsense" and "opnsense-dark" depending on browser settingui: decrease flashing in opnsense-auto theme when switching (contributed by Konstantinos Spartalis)ui: remove direct apply_btn_id usage in favour of base_apply_button template partialui: fix menu registration not setting "active"plugins: os-firewall-legacy 1.0 contains the static PHP firewall rules pagesplugins: os-ndproxy has been removed, use os-ndp-proxy-go insteadsrc: FreeBSD 15.1-RELEASE-p1 plus assorted stable/15 networking commitssrc: pf: do not mangle IP header before shared forwardingsrc: pf: stop resolving hosts via DNS that use ":" modifiersrc: pf: clear anchor after stepping into it in pf_match_translation_rule()src: pf: pf_route() "dst" no longer holds the gateway in 15.xports: libevent 2.1.13ports: lighttpd 1.4.85ports: openvpn 2.7.5ports: sqlite 3.53.3ports: suricata 8.0.6
system: remove periodic backups settings and backend codesystem: migrate gateway groups to MVC/APIsystem: new service widget flat tile layout (partially contributed by Konstantinos Spartalis)system: make LDAP auth adhere to bad login penalty as well (contributed by Matt Andreko)system: move ldap_escape() to caller for now to avoid side effectssystem: improve the log_archive script to also work on log subdirectoriessystem: change our version of "certctl" to emit files instead of links like it is the case in FreeBSD 15.1system: include interfaces widget in dashboard defaultsystem: adjust dashboard widget resize logic to observe border box instead of content boxreporting: migrate several settings pages to MVC/API and assorted changesreporting: do not show disabled interfaces in traffic graphs (contributed by Konstantinos Spartalis)interfaces: migrate interface assignments to MVC/APIinterfaces: fix faulty netmask on loopback address due to upstream changefirmware: remove overzealous cleansing in output_cmd to unhide individual character progressfirewall: move config.xml default LAN allow rules to new rules GUIfirewall: legacy rules pages move to pluginfirewall: restrict automatic DHCPv6 filter rules to plugin/track6 usefirewall: always set a sequence at the end of the rule set when cloning a NAT rulefirewall: remove unused "safepoint" actionsfirewall: fix automatic source NAT rules not displayed for PPPoE interfacesfirewall: flatten automatic source NAT rules into two per WAN type interfacefirewall: prevent deletion if a group is referenced in MVC rulesfirewall: constraint source NAT getAction() to only general page and align setAction() accordinglyfirewall: use proper path for one-to-one NAT rules for renaming operationsfirewall: avoid emitting reply-to on block rules as wellfirewall: change interface group render/apply orderfirewall: adjust MVC alias rename according to address_to_pconfig()firewall: adapt getAdvancedIds() to the sectioned form structurefirewall: invalidate rule stats cache for firewall utilities API endpointcaptive portal: move template actions out of the ServiceController into its own TemplateControllercaptive portal: adjust accounting interval to Acct-Interim-Intervaldnsmasq: possible use before define in lease watcherintrusion detection: rename "uncategorized" rule package to "adult" (contributed by Konstantinos Spartalis)monit: fix mail-format and poll-time validationunbound: missing NetMaskAllowed=N on override addresswireguard: add allowed-ips to reresolve-dns.py in case none are set yetacl: merge user management ACLs into one single privilegebackend: allow "strict" mode +TARGETS using the preamble "!"backend: swap "strict" template logic as it was reversedmvc: refactor base_dialog and parseFormNode() to simplify the templatemvc: remove unused argument from getFormGrid()mvc: BaseField: emit descriptions in getNodes() when they are not the same as the value to match getNodeContent()mvc: PortField: reject whitespaces in port ranges during validationmvc: ModelRelationField: remove grouped option handlingmvc: add file type to formsui: add "opnsense-auto" theme which switches between "opnsense" and "opnsense-dark" depending on browser settingui: decrease flashing in opnsense-auto theme when switching (contributed by Konstantinos Spartalis)ui: remove direct apply_btn_id usage in favour of base_apply_button template partialui: fix menu registration not setting "active"plugins: os-firewall-legacy 1.0 contains the static PHP firewall rules pagesplugins: os-ndproxy has been removed, use os-ndp-proxy-go insteadsrc: FreeBSD 15.1-RELEASE-p1 plus assorted stable/15 networking commitssrc: pf: do not mangle IP header before shared forwardingsrc: pf: stop resolving hosts via DNS that use ":" modifiersrc: pf: clear anchor after stepping into it in pf_match_translation_rule()src: pf: pf_route() "dst" no longer holds the gateway in 15.xports: libevent 2.1.13ports: lighttpd 1.4.85ports: openvpn 2.7.5ports: sqlite 3.53.3ports: suricata 8.0.6Migration notes, known issues and limitations:The privileges "page-system-groupmanager" and "page-system-usermanager-addprivs" were merged into "page-system-groupmanager" and are no longer available separately. This was done to avoid the misconception that access to a user management page gives constrained rights to each page, but that is not the case. User management is a process involving all 3 pages.The static PHP pages for firewall rule management have been moved to the "os-firewall-legacy" plugin which can be manually installed before or after the upgrade. All rules will continue to work regardless of the plugin being installed or not and are easily migrated using the given assistant.Hyper-V guests may be producing panics on certain hosts with more than one virtual processor assigned. Make sure to snapshot beforehand and stay on 26.1.x until the situation is clear.Since this is a major OS upgrade and OpenSSL changes from 3.0 to 3.5 third party repositories may interfere with your upgrade experience. Removing offending repositories and plugins may help; or wait for affirmation from the respective repository owners.
The privileges "page-system-groupmanager" and "page-system-usermanager-addprivs" were merged into "page-system-groupmanager" and are no longer available separately. This was done to avoid the misconception that access to a user management page gives constrained rights to each page, but that is not the case. User management is a process involving all 3 pages.The static PHP pages for firewall rule management have been moved to the "os-firewall-legacy" plugin which can be manually installed before or after the upgrade. All rules will continue to work regardless of the plugin being installed or not and are easily migrated using the given assistant.Hyper-V guests may be producing panics on certain hosts with more than one virtual processor assigned. Make sure to snapshot beforehand and stay on 26.1.x until the situation is clear.Since this is a major OS upgrade and OpenSSL changes from 3.0 to 3.5 third party repositories may interfere with your upgrade experience. Removing offending repositories and plugins may help; or wait for affirmation from the respective repository owners.
Source:
Tweakers.net