Release of the pfSense firewall distribution 2.4.5

Took place Release of a compact distribution for creating firewalls and network gateways pfSense 2.4.5. The distribution is based on the FreeBSD codebase, utilizing developments from the m0n0wall project and actively employing pf and ALTQ. For download available several images for the amd64 architecture, ranging in size from 300 to 360 MB, including LiveCD and installation image for USB Flash.

Management of the distribution is carried out through a web interface. For enabling user access in wired and wireless networks, Captive Portal, NAT, VPN (IPsec, OpenVPN), and PPPoE can be used. A wide range of capabilities is supported for bandwidth limitation, limiting the number of simultaneous connections, traffic filtering, and creating fault-tolerant configurations based on CARP. Performance statistics are displayed in graph or tabular form. Support is provided for authorization via a local user database as well as through RADIUS and LDAP.

Key changes:

  • The components of the base system have been upgraded to FreeBSD 11-STABLE;
  • On some pages of the web interface, including the certificate manager, DHCP binding list, and ARP/NDP tables, support for sorting and searching has been added;
  • A DNS resolver based on Unbound has been added to the Python script integration tools;
  • For IPsec DH (Diffie-Hellman) and PFS (Perfect Forward Secrecy), the following have been added Diffie–Hellman groups 25, 26, 27, and 31;
  • In UFS filesystem settings for new systems, the noatime mode is enabled by default to minimize unnecessary write operations;
  • An attribute 'autocomplete=new-password' has been added to authentication forms to disable autofilling fields with sensitive information;
  • New dynamic DNS record providers have been added — Linode and Gandi;
  • Several vulnerabilities have been fixed, including an issue in the web interface that allowed an authenticated user with access to the image upload widget to execute arbitrary PHP code and gain access to privileged pages in the admin interface.
    Additionally, the possibility of cross-site scripting (XSS) has been eliminated in the web interface.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster