# 2.2.1 2.2.x maintenance release * Feature #3199: Option to accumulate or not IP addresses in Alias table of FQDNs * Bug #3395: DHCPv6 client pass rules need to come before bogons * Bug #3669: WAN IPs not being cached causing unnecessary "rc.start_packages: Restarting/Starting all packages" * Bug #3979: 2.2 IPsec NAT-T / MOBIKE IKEv2 control * Bug #4117: Using run(4) USB WLAN in hostap mode crashes in FreeBSD 10.x * Feature #4176: Add support for SMTP authentication mechanisms * Bug #4339: RAM Disk Setting minimum ram error * Feature #4205: unbound config option missing * Feature #4230: Prefer SSL Perfect Forward Secrecy ciphers in UI * Bug #4238: Firewall rule: source port display issue * Bug #4239: athstats, cryptostats, cryptotest missing from 2.2 builds * Bug #4245: after disabling ipsec, "# VPN Rules" are still loaded * Bug #4246: Fix "netstat -gW" behavior broken in r259638. * Bug #4273: OpenVPN options route-nopull and route-noexec swapped * Bug #4274: Marking a packet with only a number results in a broken rule * Bug #4275: ASN.1 DN needs double quotes in config file * Bug #4289: Invalid alias using a numerical name causes a filter reload error * Bug #4379: Remove CGN (RFC6598) address space from "private networks" * Bug #4300: Can not enter outbound NAT destination port range * Bug #4302: Several DSCP choices are non-functional and result in a broken ruleset * Bug #4308: LAGG LACP defaults to strict mode in FreeBSD >= 10 * Bug #4340: OpenVPN connect fails if login contains special characters (e.g. &) * Bug #4314: Traffic Shaper Wizard not accepting an alias in the "Upstream SIP Server" text box * Bug #4317: firewall_edit_nat.php - memory exhaustion on 32 bit with VIP range * Bug #4318: gen_subnet_max returns incorrect result for 32 bit * Bug #4328: Some symlinks not updated by full update * Bug #4332: Unable to run DNS Forwarder (dnsmasq) and DNS Resolver (unbound) simultaneously on different ports * Bug #4333: Shaper wizard retains and uses incorrect info when supplying a different count of interfaces on future runs * Todo #4338: Upgrade PHP to 5.5.22 * Bug #4341: strongSwan fails to re-attach dynamic IPs where interfaces_use specified * Bug #4343: Firewall Log does not display logs for IGMP * Bug #4349: Generating IPsec entries with the option similar to this one causes bad ipsec configuration * Feature #4360: IPsec allow making a connection repsonder only * Feature #4361: add input validation to prevent use of AES > 128 w/glxsb * Bug #4362: RSS widget - broken character encoding due to forcing latin-1 * Bug #4363: gpioapu causes kernel panic at boot on some hardware * Bug #4367: Incorrect rrset-cache-size in unbound.conf * Bug #4371: Re-enable suhosin * Bug #4381: Bring back the automatic captive portal pass rule to allow users to reach lighttpd on the proper captive portal port * Bug #4384: missing input validation in captive portal * Bug #4389: gif0 tunnel for ipv6 using a carp-ip to the outside world stops working upon reboots and some config changes * Bug #4390: Cannot create an IP alias on a CARP interface where the actual Interface address is in a different network * Bug #4393: syslogd stops and fails to restart during boot in some cases * Bug #4395: /etc/hosts doesn't contain any local IPv6 addresses * Bug #4402: Unbound: enable harden-glue by default and/or apply patch * Bug #4427: Traffic Shaper Wizard still having issues * Bug #4432: Net_IPv6::compress() does not properly handle all-zeroes address * Bug #4433: DHCP6 only pushes name server info to tracked interfaces if delegation prefix length is less than /64 * Bug #4434: Enabling NTP graphs does not take effect right away * Bug #4435: Invalid increment in DHCP6 server address range check * Bug #4436: dhcp6c requests prefix delegation when no tracking interfaces are configured * Bug #4443: diag_arp does not display reverse resolved hostnames containing underscore * Bug #4444: Reverse lookup domain overrides and "Do not forward private reverse lookups" * Bug #4445: Applying NAT changes in Hyper-V can break running NAT config * Bug #4446: IP Alias with CARP VIP parent is not removed from OS on secondary node when deleted * Bug #4447: Unbound adds PTR records for host override aliases * Bug #4455: Router Advertisment Daemon does not add UnicastOnly for OpenVPN interfaces * Bug #4464: Config restore forces serial console to be enabled * Bug #4485: last commit broke globals.inc * Bug #4471: stf tunnel interface is not destroyed when 6rd or 6to4 tunnel is disabled * Bug #4475: 6rd prefix validation message is not displaying correct range * Bug #4481: DHCP server - Dynamic DNS options layout messed up * Bug #4482: IPsec on gateway group with VIPs not working * Bug #4490: slight error in builder_scripts/scripts/buildports.sh * Bug #4492: pfSsh.php help appears to reference an older config structure. * Bug #4502: Default gateway not switching when interface stuck in pending state * Feature #4509: Add granular state timeouts control * Todo #4514: upgrade to Unbound 1.5.3 * Todo #4516: Improve wireless input validation