Het pakket OPNsense is een firewall met uitgebreide mogelijkheden. Het is gebaseerd op het besturingssysteem FreeBSD en is oorspronkelijk een fork van m0n0wall en pfSense. Het pakket kan volledig via een webinterface worden ingesteld en heeft onder andere ondersteuning voor mfa, OpenVPN, IPsec, CARP en captive portal. Daarnaast kan het packetfiltering toepassen en beschikt het over een traffic shaper. De ontwikkelaars achter OPNsense hebben de zesde update voor versie 26.7 uitgebracht en de releasenotes voor die uitgave kunnen hieronder worden gevonden.
OPNsense 26.7.6 releasedThis update finally brings interface settings to MVC/API! It also brings a number of fixes and improvements from FreeBSD stable/15 including a fix for previous Hyper-V boot issues and hopefully also fixes ice driver DDP issues with newer firmware versions. For the interface settings MVC/API there a few things to keep in mind:
Here are the full patch notes:
- You can find them on the assignments page integrated into the existing grid.
- Commonly required DHCP advanced options not in basic mode have been made available.
- Advanced/file based modes for DHCP are gone and will reset on save.
- Saving settings queues them for reconfiguration and storage.
- A reboot without apply will discard the previously saved changes.
- Apply works similar to the old interfaces.php page but uses a rewritten backend sequence.
- The old interfaces.php page is still available retaining the old style settings.
- The old interfaces.php page will likely move to a plugin for 27.1.
- system: use correct type for IP when killing active states in "lockout_handler"
- system: reject a null gateway in getGatewayAction()
- system: add "latency_avg" as sanity check for running dpinger
- system: missing chown in backup call for proper non-root web GUI access
- system: do not allow system scope users to be renamed
- reporting: unbound: add DNSSEC status column in details grid
- interfaces: add interface configuration settings in new assignments page
- interfaces: prevent interface_configure() from reloading non-interface hooks when in batch mode
- interfaces: improve queue build sequence in interfaces_dependencies()
- interfaces: remove stale VIP address after update
- interfaces: be more conservative with -no_dad
- interfaces: add a new 'updateip' hook
- firewall: aliases: reject reversed port ranges
- firewall: destination NAT: fix destination for no-rdr rules
- firewall: destination NAT: add safety guards for calculated port ranges
- ipsec: add "replay_window" option to children
- monit: log from the first line and reconfigure through the base class
- openvpn: default keepalive to "10 60" in server mode and improve validation
- bootgrid: upgrade Tabulator to version 6.5.3
- mvc: disable Nginx reverse proxy buffering on configd streams
- mvc: dispatch failed message during reconfiguredAction()
- mvc: PortField: keep the first well-known service in the option list
- mvc: PortField: always return a string for normalizedPort()
- mvc: UidField: allow an arbitrarily specified UID for system scope users upon creation
- ui: do not add the spinner again when it fails
- plugins: add error returns to plugins_configure()
- plugins: os-ndp-proxy-go 1.5
- src: sysvsem: heap out-of-bounds access in semop(2)
- src: ktls: remote DoS via receive-side kernel TLS
- src: udp: IPv6 UDP sendto(2) bypasses jail loopback restriction
- src: vfs: multiple jail filesystem root escapes
- src: openssl: out-of-bounds read in OpenSSL DTLS retransmission
- src: kqueue: memory safety bugs in kqueue copy-on-fork implementation
- src: syslogd: fix leaking child processes when logging to a pipe
- src: iflib: do not hold the ifnet lock across registration
- src: ixgbe: correct Wake-on-LAN configuration
- src: dummynet: do not overflow the points
- src: pf: mark non-port packets to require IP checksumming
- src: pf: set the correct type for rule timeouts
- src: loopback: improve checksum offloading
- src: vlan: use the exclusive lock everywhere
- src: routing: initialize V_rt_numfibs earlier during boot
- src: raw ip: clear sin_port on bind(2)
- src: nd6: fix regeneration of temp addresses in detached state
- src: hyperv: fix single page invalidation path
- src: route/fib_algo: fix nexthop index collision across families
- src: ice: do not leave device non-functional if Tx scheduler config fails
- src: netipsec: fix V_spd_size updates
- src: bnxt: assorted updates from stable/15
- src: ixl: assorted updates from stable/15
- src: linxkpi: assorted updates from stable/15
- src: net80211: assorted updates from stable/15
- src: pci: assorted updates from stable/15
- ports: ca_root_nss / nss 3.130
- ports: expat 2.8.5
- ports: pcre2 10.49
- ports: phalcon 5.22.1
- ports: php 8.5.11
- ports: py-duckdb 1.5.6
:strip_exif()/i/2007222016.jpeg?f=imagenormal)