The release of a compact distribution for building firewalls and network gateways pfSense 2.5.0 has taken place. The distribution is based on the FreeBSD codebase, utilizing developments from the m0n0wall project and actively employing pf and ALTQ. An ISO image has been prepared for the amd64 architecture, sized at 360 MB.
The distribution is managed via a web interface. For enabling user access to both wired and wireless networks, Captive Portal, NAT, can be utilized. VPN (IPsec, OpenVPN) and PPPoE. A wide range of capabilities is supported for bandwidth limitation, limiting the number of simultaneous connections, traffic filtering, and creating fault-tolerant configurations based on CARP. Operational statistics are displayed in graph or tabular form. Local user database authentication is supported, as well as RADIUS and LDAP.
Key changes:
- Core system components have been updated to FreeBSD 12.2 (the previous branch used FreeBSD 11).
- Transition to OpenSSL 1.1.1 and OpenVPN 2.5.0 with support for ChaCha20-Poly1305 has been implemented.
- A WireGuard VPN implementation has been added, operating at the kernel level.
- The IPsec backend of strongSwan has transitioned from ipsec.conf to using swanctl and VICI format. Tunnel settings have been improved.
- The interface for managing certificates has been enhanced. The ability to update entries in the certificate manager has been added. Notifications for certificate expiration have been provided. The option to export keys and PKCS #12 archives with password protection has been included. Support for certificates based on elliptic curves (ECDSA) has been added.
- The backend for connecting to the wireless network through the Captive Portal has been significantly changed.
- Tools for ensuring fault tolerance have been improved.

Source: opennet.ru
