OPNsense 24.1 firewall distribution release.

The release of the OPNsense 24.1 firewall distribution has been formed, which is a branch of the pfSense project, created with the aim of developing a fully open distribution capable of providing functionality at the level of commercial solutions for deploying firewalls and network gateways. Unlike pfSense, this project is positioned as not controlled by a single company, developed with direct community involvement, and possesses a completely transparent development process, as well as allowing the use of its developments in third-party products, including commercial ones. The source texts of the distribution components, as well as the tools used for assembly, are distributed under the BSD license. Builds are available in the form of LiveCD and as an image for writing to Flash drives (443 MB).

The basic filling of the distribution is based on the FreeBSD code. Among the features of OPNsense, one can highlight a fully open build toolset, the ability to install as packages on top of standard FreeBSD, load balancing tools, a web interface for organizing user connections to the network (Captive portal), mechanisms for connection state tracking (stateful firewall based on pf), setting bandwidth limits, traffic filtering, and creating VPN based on IPsec, OpenVPN, and PPTP, LDAP and RADIUS integration, DDNS (Dynamic DNS) support, and a system of visual reports and charts.

The distribution provides tools for creating fault-tolerant configurations based on the CARP protocol, allowing for the launch of a backup node alongside the primary firewall, which will be automatically synchronized at the configuration level and take over the load in case of a primary node failure. A modern and simple interface for configuring the firewall is offered to the administrator, built using the Bootstrap web framework.

Among the changes:

  • Transition to the OpenSSL 3 library has been made.
  • A new branch of the Suricata 7 intrusion detection system has been implemented.
  • By default, a kernel module with Wireguard VPN, provided in FreeBSD 13.2, is pre-installed.
  • Experimental support for netmap has been implemented for Wireguard.
  • The core includes the os-firewall and os-wireguard plugins. Support for the os-wireguard-go plugin has been discontinued.
  • The option to use the Kea DHCP server, which supports failover, instead of ISC DHCP has been added.
  • Updated versions of libxml 2.11.6, php 8.2.15, py-duckdb 0.9.2, and sqlite 3.45.0.
  • Access to the command shell and backups has been prohibited for users without administrator rights.
  • Support for the OCSP (Online Certificate Status Protocol) has been added to check for certificate revocation.
  • The overview page and components for configuring the gateway, NPTv6, ARP, and NDP have been migrated to the MVC framework, allowing for management through the API.
  • The 'maxfilesize' setting has been added for log rotation after reaching a certain size.
  • Integration with the web proxy has been moved to the os-squid plugin.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster