A new version of the IPFire firewall distribution 2.23 has been released.
In the new version:
- SSH agent forwarding: can be enabled in the IPFire SSH service, allowing administrators to connect to the firewall and use SSH agent authentication when using IPFire as a bastion host and subsequently connecting to an internal server.
- When creating multiple hosts for rewriting the local DNS zone, a PTR record was automatically created. Sometimes hosts can have multiple names, and creating a PTR record for an alias can be undesirable. This is now configurable with an additional checkbox.
- A bug in the UI that caused rules on the configuration page to not display if the GeoIP database had not yet been loaded has been fixed. This issue occurred when the system was set up but never connected to the internet.
- On systems with a large number of DHCP lease times, the script that imports them into the DNS system has been optimized to ensure the speed of their import and that a partially written file never reaches the disk, which could lead to a crash in certain circumstances.
- Minor UI bugs on IPsec pages have been fixed. VPN.
- IPFire no longer attempts to search for temperature sensors on AWS, as this led to a large number of error messages in the system log.
- New IPS settings based on the Suricata project. It provides greater security and performance compared to the previous Snort-based system.
- New kernel version: linux kernel 4.14.113.
- New package versions: gnutls 3.6.7.1, lua 5.3.5, nettle 3.4.1, ntp 4.2.8p13, rrdtool 1.7.1, unbound 1.9.1.
- New package versions with enhancements: borgbackup 1.1.9, dnsdist 1.3.3, freeradius 4.0.18, nginx 1.15.9, postfix 3.4.5, zabbix_agentd 4.2.0.
- New rules for filtering outgoing traffic for Tor.
- The ability to use isolation in the wireless access point to prevent interaction between clients connected to this point.
- The flashrom package has been added — a tool for updating firmware.
Source: linux.org.ru
