Showing posts with label OPNsense. Show all posts
Showing posts with label OPNsense. Show all posts

OPNsense 16.7 released with UEFI support

The OPNsense team has released OPNsense 16.7, latest stable version of FreeBSD based, open source, user friendly firewall and routing platform. OPNsense 16.7 is a major release after 6 months. Within this 6 months, project has released 20 minor releases.


OPNsense 16.7 which named as Dancing Dolphin comes with several updated packages and some new features. Following are some notable highlights of this release.
  • Suricata 3.1.1 with Intel Hyperscan support
  • NetFlow-based reporting and export
  • Traffic shaping using CoDel / FQ-CoDel
  • Two-factor authentication based on RFC 6238 (TOTP)
  • HTTPS and ICAP support in the proxy server
  • FreeBSD 10.3 with full integration of HardenedBSD ASLR
  • UEFI boot and installation modes
  • Substantial updates tour language packs: Japanese, Russian, German, French, Chinese
For more information on this release, checkout release announcement published in OPNsense forum.

OPNsense Firewall 16.1.9 released

The OPNsense team announced release of OPNsense 16.1.9, latest stable update of fully featured, user friendly, FreeBSD based firewall and routing system. It comes with most of the features available in costly commercial firewalls or even more than that.

New release of OPNsense has improved translations, which includes comprehensive russian translation, and japanese translation work is in progress. Also, this release comes with HTTPS support in proxy server. Another highlight is StrongSwan 5.4.0, which helps to address IPSec status page hang bug observed with complex configurations.


Some other features in this release includes:
  • src: tzdata updated to 2016c[1]
  • src: prevent kernel panic on ipfw/dummynet module unload
  • src: let ng_ether_attach() only attach to supported types to avoid kernel panics
  • ports: curl 7.48.0[2], strongswan 5.4.0[3], pcre 8.38 (patched CVE-2016-1283)[4], php 5.6.20[5]
  • languages: added Russian to the release, now 60% complete (contributed by Smart-Soft Ltd.)
  • languages: updated Japanese, now 70% complete (contributed by Chie Taguchi)
  • languages: updated German, now 81% complete
  • languages: updated French, now 50% complete
  • firewall: allow editing of up to 5000 aliases
  • firewall: remove link to associated filter rule edit as edit is not allowed
  • firewall: add port range check to aliases edit
  • firewall: when alias URL SSL verification is off, do not verify the hostname either
  • firewall: condense alias pages into a single view
  • firewall: remember scrolling position to return to the previous position after edit
  • firewall: alias import now supports type selection (network and host types)
  • firmware: added German-based mirror (contributed by Alexander Lauster)
  • system: load modules before setting tunables to support settings for modules
  • system: fix boot issue that prevented SSH from starting up in some instances
  • interface: do not show wireless parents on the assignment page as it cannot be assigned
  • ipsec: individual collapse/expand for status page
  • dhcp: allow backwards-compatibility with imported configs
  • captive portal: fix missing busyTimeout on voucher database access
  • openvpn: remember scrolling position to return to the previous position after edit
  • proxy: HTTPS support added
  • proxy: added ability to change the hostname and admin email (contributed by Frederic Lietart)
  • proxy: avoid race condition on cache dir creation (contributed by Frederic Lietart)
  • development: allow hiding of menu entries using the Visibility=”delete” attribute
Read original release announcement in OPNsense blog.