The release of the OPNsense 21.7 distribution for creating firewalls has taken place. This is a branch of the pfSense project, developed to create a fully open distribution that could possess features on par with commercial solutions for deploying firewalls and network gateways. Unlike pfSense, the project is positioned as independent from any single company, developed with direct community involvement, and has a completely transparent development process, providing the opportunity to utilize any of its developments in third-party products, including commercial ones. The source texts of the distribution components, as well as the tools used for assembly, are distributed under the BSD license. The builds are prepared in the form of LiveCD and system images for writing to Flash drives (422 MB).
The basic filling of the distribution is based on HardenedBSD code, which supports a synchronized fork of FreeBSD, integrating additional security mechanisms and techniques to counteract vulnerability exploitation methods. OPNsense features a fully open build toolset, the ability to install packages on top of standard FreeBSD, load balancing tools, a web interface for organizing user connections (Captive portal), stateful connection tracking mechanisms based on pf, bandwidth limitation, traffic filtering, and creation. VPN based on IPsec, OpenVPN, and PPTP, LDAP and RADIUS integration, DDNS (Dynamic DNS) support, and a system of visual reports and charts.
The distribution provides tools for creating fault-tolerant configurations based on the CARP protocol, allowing for the launch of a backup node alongside the primary firewall, which will be automatically synchronized at the configuration level and take over the load in case of a primary node failure. A modern and simple interface for configuring the firewall is offered to the administrator, built using the Bootstrap web framework.
Among the changes:
- The distribution is based on HardenedBSD 12.1 developments. The upcoming 22.1 release plans to migrate to FreeBSD 13.
- A new installer has been proposed, providing built-in support for installation on partitions with the ZFS file system and suitable for operating in virtual machines, where UEFI is used.
- The interface for firmware updates has been redesigned.
- In the log reflecting traffic filtering activity, the actual rule identifiers are displayed to avoid misinterpretation after changing the rule set.
- In the templates that allow associating a set of networks, hosts, and ports with a specific symbolic name in firewall rules (aliases), the ability to specify wildcard masks in network masks has been added.

Source: opennet.ru
