After 6 months of development the release of the distribution for creating firewalls , which is a branch of the pfSense project, created to form a fully open distribution capable of providing commercial-level functionality for deploying firewalls and network gateways. Unlike pfSense, the project is positioned as not controlled by any single company, developed with the direct participation of the community, and possesses a completely transparent development process, as well as providing the ability to use any of its developments in third-party products, including commercial ones. The source texts for the distribution components, as well as the tools used for assembly, under the BSD license. Builds in LiveCD form and as a system image for writing to Flash drives (290 MB).
The basic framework of the distribution is based on the code , which supports a synchronized fork of FreeBSD, integrating additional protection mechanisms and techniques against vulnerability exploitation methods. Among of OPNsense, one can highlight the fully open build toolkit, the ability to install in the form of packages over standard FreeBSD, load balancing tools, a web interface for organizing user connections to the network (Captive portal), mechanisms for tracking connection states (stateful firewall based on pf), setting bandwidth limits, traffic filtering, creating VPNs based on IPsec, OpenVPN, and PPTP, integration with LDAP and RADIUS, support for DDNS (Dynamic DNS), and a system of visual reports and graphs.
Additionally, the distribution provides tools for creating fault-tolerant configurations, based on the use of the CARP protocol, allowing a backup node to be launched alongside the primary firewall, which will be automatically synchronized at the configuration level and take on the load in case of a primary node failure. For the administrator, a modern and simple interface for configuring the firewall is offered, built using the Bootstrap web framework.
In the new version:
- Built-in ability to send logs to a remote server using Syslog-ng;
- Added a separate list for viewing automatically generated packet filter rules;
- Added statistics for all packet filter rules;
- Improved management of in firewall rules (allowing the use of variables instead of hosts, port numbers, and subnets). Added the ability to import and export aliases in JSON format. An optional feature for tracking statistics for aliases is now available;
- Rewritten code for gateway handling and switching;
- Implemented the ability to synchronize LDAP groups;
- Added the ability to send certificate signing requests;
- Added support for routing through IPsec (VTI);
- Through XMLRPC, alias synchronization, VHID, and widgets have been implemented;
- Added authentication in Web proxy and IPsec through PAM;
- Added support for connection through a proxy chain;
- Introduced the ability to use groups for configuring proxy connection privileges;
- Plugins for Netdata, WireGuard, Maltrail, and Mail-Backup (PGP) have been prepared. Dpinger and DHCP servers have been ported to the plugin system;
- Translations into Russian have been updated;
- New versions of Bootstrap 3.4, LibreSSL 2.9, Unbound 1.9, PHP 7.2, Python 3.7, and Squid 4 have been implemented.
Source: opennet.ru
