{"id":16080,"date":"2018-11-30T16:15:56","date_gmt":"2018-11-30T16:15:56","guid":{"rendered":"https:\/\/www.firewallhardware.it\/pfsense-2-4-3-ultima-versione\/"},"modified":"2019-11-11T10:57:49","modified_gmt":"2019-11-11T10:57:49","slug":"pfsense-2-4-3-last-version","status":"publish","type":"page","link":"https:\/\/blog.miniserver.it\/en\/pfsense-2-4-3-last-version\/","title":{"rendered":"pfSense\u00ae 2.4.3 [last version]"},"content":{"rendered":"<p>[vc_row full_width=&#8221;stretch_row&#8221; css=&#8221;.vc_custom_1522327087646{margin-top: 60px !important;}&#8221;][vc_column width=&#8221;2\/3&#8243; css=&#8221;.vc_custom_1522327136322{margin-bottom: 30px !important;}&#8221;]<\/p>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 30px;\">pfSense\u00ae 2.4.3 last version<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<img decoding=\"async\" class=\"alignleft size-full wp-image-14238\" src=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardware-pfSense-sistema-operativo.png\" alt=\"pfSense\" width=\"311\" height=\"90\" srcset=\"https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardware-pfSense-sistema-operativo-300x87.png 300w, https:\/\/blog.miniserver.it\/wp-content\/uploads\/firewallhardware-pfSense-sistema-operativo.png 311w\" sizes=\"(max-width: 311px) 100vw, 311px\" \/><strong>pfSense\u00ae<\/strong>\u00a0is a free distribution based on\u00a0<strong>FreeBSD open-source<\/strong>, customized to be a\u00a0<strong>firewall<\/strong>\u00a0and\u00a0<strong>router<\/strong>. Besides being a powerful\u00a0<strong>firewall<\/strong>\u00a0and\u00a0<strong>router<\/strong>\u00a0platform, it includes a long list of packages that allow you to easily expand the functionality without compromising system security.JTVCYWRyb3RhdGUlMjBiYW5uZXIlM0QlMjIzJTIyJTVE<\/p>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">Security \/ Errata<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li><a class=\"reference external\" href=\"https:\/\/security.freebsd.org\/advisories\/FreeBSD-SA-18:01.ipsec.asc\" target=\"_blank\" rel=\"noopener noreferrer\">FreeBSD-SA-18:01.ipsec<\/a><\/li>\n<li>Kernel PTI mitigations for Meltdown (optional tunable)\u00a0<a class=\"reference external\" href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-18:03.speculative_execution.asc\" target=\"_blank\" rel=\"noopener noreferrer\">FreeBSD-SA-18:03.speculative_execution.asc<\/a><\/li>\n<li>IBRS mitigation for Spectre V2 (requires updated CPU microcode)\u00a0<a class=\"reference external\" href=\"https:\/\/www.freebsd.org\/security\/advisories\/FreeBSD-SA-18:03.speculative_execution.asc\" target=\"_blank\" rel=\"noopener noreferrer\">FreeBSD-SA-18:03.speculative_execution.asc<\/a><\/li>\n<li>Added a CPU Microcode update mechanism (cpuctl module, sysutils\/devcpu-data port)<\/li>\n<li>Imported a FreeBSD patch to fix boot issues when running as a hypervisor guest on AMD Family 15h processors (<a class=\"reference external\" href=\"https:\/\/bugs.freebsd.org\/bugzilla\/show_bug.cgi?id=213155\" target=\"_blank\" rel=\"noopener noreferrer\">FreeBSD PR #213155<\/a>)<\/li>\n<li>Added validation for RRD parameters to ensure passed filenames are valid\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8269\" target=\"_blank\" rel=\"noopener noreferrer\">#8269<\/a><\/li>\n<li>Fixed a potential XSS vector in RRD error output encoding\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8269\" target=\"_blank\" rel=\"noopener\">#8269<\/a>\u00a0<a class=\"reference external\" href=\"https:\/\/www.pfsense.org\/security\/advisories\/pfSense-SA-18_01.packages\" target=\"_blank\" rel=\"noopener noreferrer\">pfSense-SA-18_01.packages<\/a><\/li>\n<li>Fixed a potential XSS vector in diag_system_activity.php output encoding\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8300\" target=\"_blank\" rel=\"noopener\">#8300<\/a>\u00a0<a class=\"reference external\" href=\"https:\/\/www.pfsense.org\/security\/advisories\/pfSense-SA-18_02.webgui\" target=\"_blank\" rel=\"noopener noreferrer\">pfSense-SA-18_02.webgui<\/a><\/li>\n<li>Fixed a potential XSS vector in traffic_graphs.widget.php settings\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8302\" target=\"_blank\" rel=\"noopener\">#8302<\/a>\u00a0<a class=\"reference external\" href=\"https:\/\/www.pfsense.org\/security\/advisories\/pfSense-SA-18_03.webgui\" target=\"_blank\" rel=\"noopener noreferrer\">pfSense-SA-18_03.webgui<\/a><\/li>\n<li>Fixed a potential CSRF issue in service control request processing\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8296\" target=\"_blank\" rel=\"noopener noreferrer\">#8296<\/a><\/li>\n<li>Enabled CSRF protection for all dashboard widgets\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8301\" target=\"_blank\" rel=\"noopener noreferrer\">#8301<\/a><\/li>\n<li>Added encoding for firewall schedule range descriptions\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8259\" target=\"_blank\" rel=\"noopener noreferrer\">#8259<\/a><\/li>\n<li>Changed sshd to use delayed compression\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8245\" target=\"_blank\" rel=\"noopener noreferrer\">#8245<\/a><\/li>\n<li>Increased PHP-FPM resources on systems with over 1GB RAM to improve performance\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8125\" target=\"_blank\" rel=\"noopener noreferrer\">#8125<\/a><\/li>\n<li>Imported a netstat fix for ARM platforms to improve performance and reduce CPU usage, especially on the Dashboard\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8237\" target=\"_blank\" rel=\"noopener noreferrer\">#8237<\/a><\/li>\n<li>Fixed a memory leak in the pfSense_getall_interface_addresses() function in the pfSense PHP module\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8249\" target=\"_blank\" rel=\"noopener noreferrer\">#8249<\/a><\/li>\n<li>Hardware support for the XG-7100, including:\n<ul>\n<li>C3000 NIC support (factory installations only)<\/li>\n<li>C3000 SoC support (factory installations only)<\/li>\n<li>Marvell 88E6190 switch support (factory installations only)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">Traffic Shaping \/ Limiters<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Fixed hangs due to Limiters and pfsync in HA\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/4310\" target=\"_blank\" rel=\"noopener noreferrer\">#4310<\/a><\/li>\n<li>Added the Chelsio\u00a0<em>cxl<\/em>\u00a0driver to the list of ALTQ capable interfaces\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/7607\" target=\"_blank\" rel=\"noopener noreferrer\">#7607<\/a><\/li>\n<li>Fixed an issue with limiters that had fractional bandwidth values\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8091\" target=\"_blank\" rel=\"noopener noreferrer\">#8091<\/a><\/li>\n<li>Changed status_queues.php to provide \u2018realtime\u2019 statistics\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8185\" target=\"_blank\" rel=\"noopener noreferrer\">#8185<\/a><\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">IPsec<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Changed IPsec Phase 1 to allow selecting both IPv4 and IPv6 so the local side can allow inbound connections to either address family\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/6886\" target=\"_blank\" rel=\"noopener noreferrer\">#6886<\/a><\/li>\n<li>Changed IPsec Phase 1 to allow configuration of multiple IKE encryption algorithms, key lengths, hashes, and DH groups\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8186\" target=\"_blank\" rel=\"noopener noreferrer\">#8186<\/a><\/li>\n<li>Fixed a problem when IPsec bypasslan was enabled while the LAN interface is disabled or doesn\u2019t have an IP address\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8239\" target=\"_blank\" rel=\"noopener noreferrer\">#8239<\/a><\/li>\n<li>Added IPv6 LAN Network to the IPsec LAN bypass list\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8321\" target=\"_blank\" rel=\"noopener noreferrer\">#8321<\/a><\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">OpenVPN<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Fixed an error message encountered by a few users when manually killing OpenVPN connections\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8266\" target=\"_blank\" rel=\"noopener noreferrer\">#8266<\/a><\/li>\n<li>Added an OpenVPN tap bridge configuration option to push the bridged interface address to clients as a route-gateway for routes\/redirects\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8267\" target=\"_blank\" rel=\"noopener noreferrer\">#8267<\/a><\/li>\n<li>Added an option to the DNS Resolver which allows registering the CN of OpenVPN clients as hostnames\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/6847\" target=\"_blank\" rel=\"noopener noreferrer\">#6847<\/a><\/li>\n<li>Added an option to OpenVPN clients and servers to suppress creation of IPv4 or IPv6 gateway addresses for an interface\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/6848\" target=\"_blank\" rel=\"noopener noreferrer\">#6848<\/a><\/li>\n<li>Fixed issues with OpenVPN when using a \/31 IPv4 Tunnel Network\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8261\" target=\"_blank\" rel=\"noopener noreferrer\">#8261<\/a><\/li>\n<li>Updated the OpenVPN wizard with the current UDP and TCP protocol selections\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8298\" target=\"_blank\" rel=\"noopener noreferrer\">#8298<\/a><\/li>\n<li>Added the interface for a VPN to the OpenVPN client and server list screens<\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">Notifications<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Changed SMTP notifications handling so they are batched, to avoid sending multiple e-mail messages in a short amount of time\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/4031\" target=\"_blank\" rel=\"noopener noreferrer\">#4031<\/a><\/li>\n<li>Added a notification when the firewall boot sequence is complete\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/7643\" target=\"_blank\" rel=\"noopener noreferrer\">#7643<\/a><\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">Dashboard<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Fixed issues with the IPsec dashboard widget causes GUI failure\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/6318\" target=\"_blank\" rel=\"noopener noreferrer\">#6318<\/a><\/li>\n<li>Changed the Dynamic DNS Widget so it shows the description of custom entries to identify them\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/7843\" target=\"_blank\" rel=\"noopener noreferrer\">#7843<\/a><\/li>\n<li>Fixed a reference to deprecated updateGatewayDisplays() function in the Gateways dashboard widget\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8303\" target=\"_blank\" rel=\"noopener noreferrer\">#8303<\/a><\/li>\n<li>Added a setting to the temperature widget to display readings in Fahrenheit\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8205\" target=\"_blank\" rel=\"noopener noreferrer\">8205<\/a><\/li>\n<li>Changed the picture widget so the picture is stored on the firewall filesystem and not in config.xml to reduce the size of backup data\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8371\" target=\"_blank\" rel=\"noopener noreferrer\">#8371<\/a>\n<ul>\n<li>On upgrade, pictures will be moved out of config.xml, so backup this file separately if it is important<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">DHCP<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Added an option to the DHCP Server Dynamic DNS configuration to set the server key algorithm\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/6621\" target=\"_blank\" rel=\"noopener noreferrer\">#6621<\/a><\/li>\n<li>Added DDNS Client Updates option to DHCPv4\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/7131\" target=\"_blank\" rel=\"noopener noreferrer\">#7131<\/a><\/li>\n<li>Fixed handling of the DHCPv6 DDNS reverse zone key\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/6319\" target=\"_blank\" rel=\"noopener noreferrer\">#6319<\/a><\/li>\n<li>Fixed DHCPv4 static mappings so that multiple MAC for same DHCP address or hostname are allowed\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8220\" target=\"_blank\" rel=\"noopener noreferrer\">#8220<\/a><\/li>\n<li>Fixed a potential issue in detecting primary\/secondary node in a failover configuration<\/li>\n<li>Improved DHCP relay destination interface discovery<\/li>\n<li>Fixed DHCPv6 lease display for entries that were not parsed properly from the lease database<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/7413\" target=\"_blank\" rel=\"noopener noreferrer\">#7413<\/a><\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">Dynamic DNS<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Added an option for RFC 2136 Dynamic DNS server key algorithm\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8244\" target=\"_blank\" rel=\"noopener noreferrer\">#8244<\/a><\/li>\n<li>Added an option for RFC 2136 source address used to send updates\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8278\" target=\"_blank\" rel=\"noopener noreferrer\">#8278<\/a><\/li>\n<li>Fixed issues with Dynamic DNS updates using a gateway group when the primary route is down<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8333\" target=\"_blank\" rel=\"noopener noreferrer\">#8333<\/a><\/li>\n<li>Added GoDaddy Dynamic DNS provider<\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">Interfaces \/ VIPs<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Fixed issues on assign_interfaces.php with large numbers of interfaces\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/6400\" target=\"_blank\" rel=\"noopener noreferrer\">#6400<\/a><\/li>\n<li>Fixed handling of CARP VIPs on disabled interfaces at boot time\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/6677\" target=\"_blank\" rel=\"noopener noreferrer\">#6677<\/a><\/li>\n<li>Fixed issues with radvd being enabled on a disconnected interface\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/6974\" target=\"_blank\" rel=\"noopener noreferrer\">#6974<\/a><\/li>\n<li>Fixed issues with rtsold on VLAN interfaces\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/7412\" target=\"_blank\" rel=\"noopener noreferrer\">#7412<\/a><\/li>\n<li>Fixed issues with dhcp6c lock files after unclean shutdown when using \u201cDo not wait for an RA\u201d on IPv6 WAN interface\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8106\" target=\"_blank\" rel=\"noopener noreferrer\">#8106<\/a><\/li>\n<li>Added a feature to allow pppoe on a CARP VIP so it will only be active on whichever node is master\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8184\" target=\"_blank\" rel=\"noopener noreferrer\">#8184<\/a><\/li>\n<li>Fixed an error when editing PPP interfaces on a system with no VIPs\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8322\" target=\"_blank\" rel=\"noopener noreferrer\">#8322<\/a><\/li>\n<li>Added VLAN priority tagging for DHCPv6 client requests\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8200\" target=\"_blank\" rel=\"noopener noreferrer\">#8200<\/a><\/li>\n<li>Added support for configuring the DUID type for an IPv6 interfaces\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8191\" target=\"_blank\" rel=\"noopener noreferrer\">#8191<\/a><\/li>\n<li>Allow custom INIT string for PPP modem SIM Pin and APN settings<\/li>\n<li>Added an indicator for disabled interfaces on status_interfaces.php<\/li>\n<li>Fixed an issue with the PPP linkup and linkdown scripts and cellular modems<\/li>\n<li>Fixed an issue where the combination of CARP with bridging could lead to a deadlock\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8056\" target=\"_blank\" rel=\"noopener noreferrer\">#8056<\/a><\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">Packages<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Fixed reinstall process for missing packages\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8183\" target=\"_blank\" rel=\"noopener noreferrer\">#8183<\/a><\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">Captive Portal<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Fixed Pass-through MAC automatic additions so it does not add duplicate entries\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8226\" target=\"_blank\" rel=\"noopener noreferrer\">#8226<\/a><\/li>\n<li>Fixed a missing global definition in Captive Portal pass-through MAC removal\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8238\" target=\"_blank\" rel=\"noopener noreferrer\">#8238<\/a><\/li>\n<li>Fixed Captive Portal voucher sync errors when vouchers are expired or disconnected while the secondary node is master\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8317\" target=\"_blank\" rel=\"noopener noreferrer\">#8317<\/a><\/li>\n<li>Fixed Captive Portal voucher synchronization between HA nodes\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/7972\" target=\"_blank\" rel=\"noopener noreferrer\">#7972<\/a><\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">Certificates<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Fixed automatic SAN handling when the CN of a certificate contains a space\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8252\" target=\"_blank\" rel=\"noopener noreferrer\">#8252<\/a><\/li>\n<li>Fixed input validation for Certificate SAN values to disallow IP addresses for FQDN\/Hostname entries\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8275\" target=\"_blank\" rel=\"noopener noreferrer\">#8275<\/a><\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">Gateways\/Routing<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Fixed handling of the Router Lifetime value on services_router_advertisements.php so it allows a value of\u00a0<em>0<\/em>\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/7502\" target=\"_blank\" rel=\"noopener noreferrer\">#7502<\/a><\/li>\n<li>Added ospf6d to the routing log<\/li>\n<li>Allow recursive aliases to be used with static routes<\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">Rules\/NAT<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Fixed various pf \u201cbusy\u201d errors when the ruleset is reloaded<\/li>\n<li>Fixed issues with editing firewall rules in non-English languages that contain single quotes in translated strings\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8219\" target=\"_blank\" rel=\"noopener noreferrer\">#8219<\/a><\/li>\n<li>Added an option to disable drag-and-drop of firewall and NAT rules<\/li>\n<li>Added a check to prevent 1:1 NAT rules with missing information from being added to the ruleset<\/li>\n<li>Added firewall rule tracking ID to rule list (in counter tooltip) and firewall rule edit page\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8348\" target=\"_blank\" rel=\"noopener noreferrer\">#8348<\/a><\/li>\n<li>Fixed cases where automatic or scripted rules were not getting tracking IDs\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8353\" target=\"_blank\" rel=\"noopener noreferrer\">#8353<\/a><\/li>\n<li>Added a check to prevent automatic outbound firewall rules with missing information from being added to the ruleset\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8360\" target=\"_blank\" rel=\"noopener noreferrer\">#8360<\/a><\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">Users\/Authentication<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Fixed issues with XMLRPC user account synchronization causing GUI inaccessibility on secondary HA nodes\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/7469\" target=\"_blank\" rel=\"noopener noreferrer\">#7469<\/a><\/li>\n<li>Fixed an issue where a user with no privileges could not logout\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8297\" target=\"_blank\" rel=\"noopener noreferrer\">#8297<\/a><\/li>\n<li>Increased maximum username length from 16 to 32 characters to catch up to the current allowed length in FreeBSD<\/li>\n<li>Fixed required field markings on LDAP authentication server configuration fields\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8337\" target=\"_blank\" rel=\"noopener noreferrer\">#8337<\/a><\/li>\n<li>Fixed display of the LDAP host when testing the GUI authentication source\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8338\" target=\"_blank\" rel=\"noopener noreferrer\">#8338<\/a><\/li>\n<\/ul>\n<h3 style=\"text-align: left; color: #00a0df; font-size: 20px;\">Misc<\/h3>\n<p>[vc_separator align=&#8221;align_left&#8221; border_width=&#8221;2&#8243; css=&#8221;.vc_custom_1522327747370{margin-top: -20px !important;}&#8221;]<\/p>\n<ul>\n<li>Fixed NTP Status server time for zones with minute offsets (fractions of an hour)\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8129\" target=\"_blank\" rel=\"noopener noreferrer\">#8129<\/a><\/li>\n<li>Added support for custom shutdown scripts in \/usr\/local\/etc\/rc.d\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8182\" target=\"_blank\" rel=\"noopener noreferrer\">#8182<\/a><\/li>\n<li>Fixed a references to an undefined function while restoring a config.xml file from an older version\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8231\" target=\"_blank\" rel=\"noopener noreferrer\">#8231<\/a><\/li>\n<li>Added support to diag_packet_capture.php to capture traffic on the loopback interface\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8257\" target=\"_blank\" rel=\"noopener noreferrer\">#8257<\/a><\/li>\n<li>Fixed an issue with the RAM disk warning pop-up appearing when no changes were made\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8268\" target=\"_blank\" rel=\"noopener noreferrer\">#8268<\/a><\/li>\n<li>Fixed an issue with the address familiy selection for remote syslog servers using IPv6\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8323\" target=\"_blank\" rel=\"noopener noreferrer\">#8323<\/a><\/li>\n<li>Silenced warnings from sysctl that otherwise went to stderr<\/li>\n<li>Added a disk size check to ZFS to prevent it from being used on disk which are too small to contain the OS and swap space\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/7308\" target=\"_blank\" rel=\"noopener noreferrer\">#7308<\/a><\/li>\n<li>Added a check to prevent pfSense-upgrade from running as a non-root user\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/7762\" target=\"_blank\" rel=\"noopener noreferrer\">#7762<\/a><\/li>\n<li>Added an option to disable the IGMP Proxy service\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8356\" target=\"_blank\" rel=\"noopener noreferrer\">#8356<\/a><\/li>\n<li>Fixed an issue with package handling when restoring a configuration that contains a branch configuration that is not valid for the target system version\u00a0<a class=\"reference external\" href=\"https:\/\/redmine.pfsense.org\/issues\/8208\" target=\"_blank\" rel=\"noopener noreferrer\">#8208<\/a><\/li>\n<\/ul>\n<p>[\/vc_column][vc_column width=&#8221;1\/3&#8243;][vc_tta_accordion c_icon=&#8221;&#8221; active_section=&#8221;1&#8243;][vc_tta_section i_icon_fontawesome=&#8221;fa fa-check&#8221; add_icon=&#8221;true&#8221; title=&#8221;All versions&#8221; tab_id=&#8221;1e176-0b7ea534-a5bf969a-50a5eeb3-efc9feab-68870c33-53871b11-7d9282fb-01217f37-1de25693-9e60b4fe-5de8&#8243;]<\/p>\n<ul>\n<li><a href=\"https:\/\/blog.miniserver.it\/en\/pfsense-ce-2-5-0-beta\/\">pfSense\u00ae CE 2.5.0 Beta<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/en\/pfsense-2-4-3-last-version\/\">pfSense\u00ae CE 2.4.3: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/en\/pfsense-2-4-2-release-notes\/\">pfSense\u00ae CE 2.4.2: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/en\/pfsense-2-4-1-release-notes\/\">pfSense\u00ae CE 2.4.1: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/en\/pfsense-2-4-release-notes\/\">pfSense\u00ae CE 2.4: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-3-3-beta\/\">pfSense\u00ae CE 2.3.3: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-3-2-note-di-rilascio\/\">pfSense\u00ae CE 2.3.2: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-3-1-note-di-rilascio\/\">pfSense\u00ae CE 2.3.1: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-3-note-di-rilascio\/\">pfSense\u00ae CE 2.3: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-2-5-note-di-rilascio\/\">pfSense\u00ae CE 2.2.5: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-2-note-di-rilascio\/\">pfSense\u00ae CE 2.2: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-1-5-note-di-rilascio\/\">pfSense\u00ae CE 2.1.5: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-1-4-note-di-rilascio\/\">pfSense\u00ae CE 2.1.4: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-1-3-note-di-rilascio\/\">pfSense\u00ae CE 2.1.3: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-1-2-note-di-rilascio\/\">pfSense\u00ae CE 2.1.2: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-1-1-note-di-rilascio\/\">pfSense\u00ae CE 2.1.1: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-1-note-di-rilascio\/\">pfSense\u00ae CE 2.1: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-0-3-note-di-rilascio\/\">pfSense\u00ae CE 2.0.3: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/pfsense-2-0-2-note-di-rilascio\/\">pfSense\u00ae CE 2.0.2: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/rilasciata-la-versione-pfsense-2-0-1\/\">pfSense\u00ae CE 2.0.1: release notes<\/a><\/li>\n<li><a href=\"https:\/\/blog.miniserver.it\/en\/pfsense\/\">Main features<\/a><\/li>\n<\/ul>\n<p>[\/vc_tta_section][vc_tta_section i_icon_fontawesome=&#8221;fa fa-external-link&#8221; add_icon=&#8221;true&#8221; title=&#8221;Link utili&#8221; tab_id=&#8221;2e176-0b7ea534-a5bf969a-50a5eeb3-efc9feab-68870c33-53871b11-7d9282fb-01217f37-1de25693-9e60b4fe-5de8&#8243;]<\/p>\n<ul>\n<li><a href=\"https:\/\/blog.miniserver.it\/en\/firewallharware-guide\/\" target=\"_self\" rel=\"noopener noreferrer\">Guide firewallhardware<\/a><\/li>\n<li><a href=\"https:\/\/www.pfsense.org\/\" target=\"_blank\" rel=\"noopener noreferrer\">Sito ufficiale pfSense<sup>\u00ae<\/sup><\/a><\/li>\n<li><a href=\"https:\/\/forum.pfsense.org\/\" target=\"_blank\" rel=\"noopener noreferrer\">Forum pfSense<sup>\u00ae<\/sup><\/a><\/li>\n<li><a href=\"https:\/\/forum.pfsense.org\/index.php?board=8.0\" target=\"_blank\" rel=\"noopener noreferrer\">Forum pfSense<sup>\u00ae<\/sup> in italiano<\/a><\/li>\n<li><a href=\"https:\/\/doc.pfsense.org\/index.php\/Main_Page\" target=\"_blank\" rel=\"noopener noreferrer\">Documentazione pfSense<sup>\u00ae<\/sup><\/a><\/li>\n<li><a href=\"https:\/\/www.pfsense.org\/download\/index\" target=\"_blank\" rel=\"noopener noreferrer\">Download pfSense<sup>\u00ae<\/sup><\/a><\/li>\n<\/ul>\n<p>[\/vc_tta_section][\/vc_tta_accordion][vc_widget_sidebar sidebar_id=&#8221;sidebar-18&#8243;]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>  [&#8230;]<\/p>\n","protected":false},"author":11,"featured_media":0,"parent":0,"menu_order":21,"comment_status":"closed","ping_status":"closed","template":"","meta":{"content-type":"","footnotes":""},"class_list":["post-16080","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/pages\/16080","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/comments?post=16080"}],"version-history":[{"count":13,"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/pages\/16080\/revisions"}],"predecessor-version":[{"id":18921,"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/pages\/16080\/revisions\/18921"}],"wp:attachment":[{"href":"https:\/\/blog.miniserver.it\/en\/wp-json\/wp\/v2\/media?parent=16080"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}