The release of the pfSense CE 2.9.0 (Community Edition) distribution for creating firewalls and network gateways has been published. This distribution is based on the FreeBSD codebase, utilizing the developments of the m0n0wall project and the pf packet filter. To download the new version, use the installer.
The distribution is managed via a web interface. For enabling user access to both wired and wireless networks, Captive Portal, NAT, can be utilized. VPN (IPsec, OpenVPN) and PPPoE. A wide range of capabilities is supported for bandwidth limitation, limiting the number of simultaneous connections, traffic filtering, and creating fault-tolerant configurations based on CARP. Operational statistics are displayed in graph or tabular form. Local user database authentication is supported, as well as RADIUS and LDAP.
Key Changes:
- The core system components have been updated to FreeBSD 16-CURRENT. Updated versions of programs include PHP 8.5, OpenSSL 3.5.7, OpenSSH 10.3p1, Kea 3.0.2, Unbound 1.24.2, strongSwan 6.0.3.
- The SSH server now allows the use of post-quantum encryption algorithms and has disabled support for outdated and unreliable cryptographic algorithms.
- Support for cryptographic keys shorter than 2048 bits has been discontinued. If unreliable or expired access certificates are detected during the update process, the system will automatically generate and install a new certificate.
- A feature for the automatic renewal of self-signed certificates or certificates issued by the built-in Certificate Authority (CA) has been added.
- Partial experimental support for the new Address Translation mode 'Port Restricted Cone' has been added, implementing dynamic mapping between the client's source port and the external IP address (which works correctly in scenarios where multiple different clients use the same source port number when connecting to the same host).
Source: opennet.ru
