Software Update: OPNsense 20.1.7

Spread the love

The package OPNsense is a firewall with extensive opportunities. It is based on the FreeBSD operating system and is originally a fork of m0n0wall and pfSense. The package can be set up completely via a web interface and has support for 2fa, openvpn, ipsec, carp and captive portal, among others. In addition, it can apply packet filtering and has a traffic shaper. The developers previously released OPNsense 20.1.7 with the following announcement:

OPNsense 20.1.7 released

Today we move to PHP 7.3 in order to be able to complete testing for the 20.7-BETA online upgrades. Also included is a patch for the packet filter kernel code which could crash with shared forwarding when interfaces disappeared due to use after free in the default network stack path.

Here are the full patch notes:

  • system: default net.inet.icmp.reply_from_interface to 1
  • system: fix static gateway wizard handing
  • firewall: allow outbound NAT source and destination port ranges
  • interfaces: use interfaces_primary_address6() inside get_interface_ipv6()
  • dhcp: add AdvLinkMTU to router advertisements settings (contributed by Ilteris Eroglu)
  • unbound: prevent wildcard domains for the local system domain
  • backend: suppress inconsequential IDNA warnings for aliases
  • backend: add option to return a key value list for TLS ciphers
  • mvc: reference constraint pointing validation results to the wrong field
  • plugins: os-acme-client 1.32 adds Acmeproxy DNS support (contributed by Maarten den Braber)
  • src: added Novatel Wireless MiFi 8800/8000 support (contributed by rootless4real)
  • src: fix pf shared forwarding on non-existing interfaces
  • src: patch in tty 3wire autologin support
  • src: fix insufficient packet length validation in libalias
  • src: fix memory disclosure vulnerability in libalias
  • src: fix improper checking in SCTP-AUTH shared key update
  • src: fix use after free in cryptodev module
  • src: update to tzdata 2020a
  • ports: ca_root_nss 3.52
  • ports: curl 7.70.0
  • ports: dhcp6c v20200512
  • ports: hyperscan 5.2.1
  • ports: openldap 2.4.50
  • ports: pcre2 10.35
  • ports: php 7.3.18

Version number 20.1.7
Release status Final
Operating systems BSD
Website OPNsense
Download https://opnsense.org/download/
License type Conditions (GNU/BSD/etc.)
You might also like