The release of the OPNsense 22.7 distribution for creating firewalls has been published. This is a branch of the pfSense project, created with the goal of forming a fully open distribution that has the functionality comparable to commercial solutions for deploying firewalls and network gateways. Unlike pfSense, this project is positioned as not controlled by a single company, developed with direct community involvement, and has a completely transparent development process, as well as providing the opportunity to use any of its developments in third-party products, including commercial ones. The source texts of the distribution components, as well as the tools used for assembly, are distributed under the BSD license. The builds are prepared in the form of LiveCD and system images for writing to Flash drives (347 MB).
The basic filling of the distribution is based on the FreeBSD code. Among the features of OPNsense, one can highlight a fully open build toolset, the ability to install as packages on top of standard FreeBSD, load balancing tools, a web interface for organizing user connections to the network (Captive portal), mechanisms for connection state tracking (stateful firewall based on pf), setting bandwidth limits, traffic filtering, and creating VPN based on IPsec, OpenVPN, and PPTP, LDAP and RADIUS integration, DDNS (Dynamic DNS) support, and a system of visual reports and charts.
The distribution provides tools for creating fault-tolerant configurations based on the CARP protocol, allowing for the launch of a backup node alongside the primary firewall, which will be automatically synchronized at the configuration level and take over the load in case of a primary node failure. A modern and simple interface for configuring the firewall is offered to the administrator, built using the Bootstrap web framework.
Among the changes:
- Transition to the FreeBSD 13.1 branch has been completed.
- Updated versions of additional programs from the ports, for example, PHP 8.0.20, Phalcon 5, sqlite 3.39.0, suricata 6.0.6, unbound 1.16.1.
- Support for Intel QuickAssist (QAT) has been added.
- Support for Stacked VLAN technology (layered VLAN tag encapsulation) has been added.
- A DDoS protection mechanism has been implemented using SYN cookies.
- APCUPSD and CrowdSec plugins have been added.
Source: opennet.ru
