Release of the OPNsense 23.1 firewall distribution.

A release of the OPNsense 23.1 distribution for creating firewalls has been formed. This is a branch of the pfSense project, created to establish a fully open distribution that can offer functionality on par with commercial solutions for deploying firewalls and network gateways. Unlike pfSense, this project is positioned as not being controlled by a single company, developed with direct involvement from the community, and boasting a completely transparent development process. It also allows for the use of its developments in third-party products, including commercial ones. The source texts of the distribution components, as well as the tools used for assembly, are distributed under the BSD license. The builds are provided in the form of LiveCD and a system image for recording to Flash drives (399 MB).

The basic filling of the distribution is based on the FreeBSD code. Among the features of OPNsense, one can highlight a fully open build toolset, the ability to install as packages on top of standard FreeBSD, load balancing tools, a web interface for organizing user connections to the network (Captive portal), mechanisms for connection state tracking (stateful firewall based on pf), setting bandwidth limits, traffic filtering, and creating VPN based on IPsec, OpenVPN, and PPTP, LDAP and RADIUS integration, DDNS (Dynamic DNS) support, and a system of visual reports and charts.

The distribution provides tools for creating fault-tolerant configurations based on the CARP protocol, allowing for the launch of a backup node alongside the primary firewall, which will be automatically synchronized at the configuration level and take over the load in case of a primary node failure. A modern and simple interface for configuring the firewall is offered to the administrator, built using the Bootstrap web framework.

Among the changes:

  • Changes have been transferred from the FreeBSD 13-STABLE branch.
  • Updated versions of additional programs from ports, such as php 8.1.14 and sudo 1.9.12p2.
  • A new implementation of the blocklist based on DNS has been added, rewritten in Python, supporting various ad and malware blocklists.
  • Statistics for the operation of the DNS server Unbound have been accumulated and displayed, allowing for tracking DNS traffic associated with users.
  • A new type of BGP ASN firewalls has been added.
  • An isolated PPPoEv6 mode has been introduced for selective enabling of the IPv6 Control Protocol.
  • Support for WAN interfaces with SLAAC without DHCPv6 has been added.
  • The components for packet capture and IPsec management have been migrated to the MVC framework, enabling API management support.
  • IPsec settings have been moved to the swanctl.conf file.
  • The os-sslh plugin has been included, allowing multiplexing of HTTPS, SSH, OpenVPN, tinc, and XMPP connections through a single network port 443.
  • The os-ddclient (Dynamic DNS Client) plugin has gained the ability to use custom backends, including Azure.
  • The os-wireguard plugin with WireGuard VPN has been switched to use the kernel module by default (the old user-level operation mode has been moved to a separate os-wireguard-go plugin).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster