Het pakket OPNsense is een firewall met uitgebreide mogelijkheden. Het is gebaseerd op het besturingssysteem FreeBSD en is oorspronkelijk een fork van m0n0wall en pfSense. Het pakket kan volledig via een webinterface worden ingesteld en heeft onder andere ondersteuning voor 2fa, openvpn, ipsec, carp en captive portal. Daarnaast kan het packetfiltering toepassen en beschikt het over een traffic shaper. De ontwikkelaars hebben OPNsense 20.7.8 uitgebracht met de volgende aankondiging:
OPNsense 20.7.8 releasedThe particular volume of this stable update foreshadows the end of the 20.7 series in less than two weeks.One longstanding issue with radvd on FreeBSD 12.1 has been resolved according to multiple user feedback. The mailing lists have been archived and will no longer be used. And before there are questions: yes, consumers of the development version are now able to upgrade to 21.1-RC1.
Here are the full patch notes:
- system: allow to recover from bad TLS certificate and/or bad settings in console interface assign
- system: display destination port number in firewall log widget
- system: keep compatible TLS 1 defaults for web GUI on 20.7 series
- system: set default certificate lifetime to 397 days
- firewall: add type 128 to outgoing IPv6 RFC4890 requirements
- firewall: add manual refresh button to live log
- firewall: fix typo in ICMPv6 validation
- firewall: fix minor regression in maintaining target alias file
- firewall: fix all state value in pfTop
- firewall: remove duplicated destination field in live log
- firewall: add readonly actions to aliases permission
- firewall: category selector missing caption
- reporting: add top talkers to revamped traffic graph page
- reporting: fix name resolution filter change in insight
- reporting: persist interface selection on traffic graph page
- captive portal: disable faulty TLS on HTTP since lighttpd 1.4.56
- dhcp: fix sorting of IPv6 static mappings
- dhcp: fix incorrect parsing of DUID
- firmware: opnsense-code now updates the current directory if nothing was specified
- firmware: opnsense-code now uses flexible make.conf target from tools.git
- firmware: opnsense-update now supports snapshot access via -z option
- firmware: opnsense-update now fixes missing dependencies on the fly
- firmware: fix some issues with missing repository on server
- firmware: add version output and date to audit logs
- ipsec: display remote host in status overview
- opendns: add standalone mode
- openssh: honour MAX_LISTEN_SOCKS
- openvpn: set default certificate lifetime to 397 days in wizard
- unbound: generate all configuration files in service controller
- unbound: fix broken lines in large files
- web proxy: lock ACL download to prevent duplicate execution
- mvc: allow underscore in filter string
- plugins: os-haproxy 2.26
- plugins: os-hw-probe 1.0
- plugins: os-maltrail fixes sensor start without server
- plugins: os-nginx 1.20
- plugins: os-tinc fixes for latest version
- src: fix OpenSSL NULL pointer de-reference
- src: fix partial scrub of multicast packages
- src: free full mbuf chains in iflib when draining transmit queues
- src: initialize oifp to avoid bogus results/panics in edge cases
- src: 10Gigabit Ethernet driver for AMD SoC
- ports: libressl 3.2.3
- ports: nss 3.60.1
- ports: php 7.3.26
- ports: pkg fix for shell keyword by opening root file descriptor
- ports: radvd 2.19
- ports: sudo 1.9.5p1