Het pakket m0n0wall is een firewall met uitgebreide mogelijkheden. Het is gebaseerd op het besturingssysteem Freebsd 6.x en kan volledig via een webinterface worden ingesteld. M0n0wall heeft onder andere ondersteuning voor 802.1Q-vlan, nat/pat, ipsec/vpn-tunnels en pptp-vpn. Daarnaast kan het ook packet filtering toepassen en beschikt het over een traffic shaper. De ontwikkelaars hebben alweer de zestiende bètaversie van m0n0wall 1.3 de deur uitgedaan met de volgende lijst van aanpassingen:
Version 1.3b16:
WARNING: this version (any platform) no longer fits on 8 MB CF cards! (>= 16 MB required)
When upgrading from generic-pc 1.2x, you must install 1.3b7 first before you install this image. Other platforms are not affected.Version 1.3b15:
- opened firewall rules for link-local IPv6 addresses on optional and LAN interfaces
- initial basic support for secondary IP addresses
- added DHCPv6 support
- added additional RA options for LAN and Optional interfaces, required for DHCPv6
- added all-servers option to dnsmasq and removed overlap check as having multiple nameservers per domain is a valid configuration
- changed interface status page to list all IP addresses on an interface
- allow RA support on WAN interface, and add feature to automatically suggest an IPv6 address for the LAN interface, based on an RA received from WAN/ISP (contributed by Andrew White)
- added IPv6 support to mini_httpd (for the webGUI)
- allow IPv6 addresses for DNS servers on System: General setup page, and for hosts on the DNS forwarder setup page (contributed by Andrew White)
- allow the remote syslog port to be changed (requested by Martin Desormeaux for m0n0log project)
- added kernel security patch FreeBSD-SA-08:11.arc4random
- added support for Broadcom BCM5722 NIC (suggested by Sebastian Lemke)
- fixed display of firewall rules and static routes pages in group manager (reported by Peter Allgeyer)
- added support for AICCU (a tool for dynamically configuring IPv6 tunnels from SixXS, allowing users with dynamic WAN IP addresses to use tunnels) Note that only heartbeat tunnels are supported at this time (no AYIYA)
- updated kernel to 6.3-RELEASE-p5 (ICMPv6 denial of service fix; IPv6 NDP routing vulnerability fix)
- fixed IPv6-ICMP firewall rule type matching
- added patch to enable custom next-server and filename options for static mappings in DHCP server (by Stephen Erisman)
- made PPPoE MTU on WAN configurable
- removed SIP proxy logging remnants