# 2.4.0 Release featuring FreeBSD 11, SG-1000 ARM support, a new installer, and more * Feature #809: Config sync username change * Bug #1685: Web configurator silently fails when "Private key does not match the certificate public key" * Feature #2766: status_openvpn.php needs IPv6 support * Bug #3027: input_errors2Ajax function * Bug #7662: Missing close span in login page 2.4.0-BETA * Bug #3710: Adding static DHCP leases doesn't cause BIND zones to update * Todo #3734: Remove PHP static pear modules from repo and use ports * Feature #3971: IPv6 - Preserve the DUID used for WAN DHCP-PD in the configuration file * Feature #4044: Add UEFI support * Feature #4083: Replace GET by POST * Bug #4287: Wrong display for ppp in Interfaces page * Bug #4326: Limiters on firewall rules where NAT applies drop all traffic * Bug #4689: Panic/Crash "sbflush_internal: cc 4294967166 || mb 0 || mbcnt 0" * Todo #4706: MPD needs to be upgraded to version 5 even for the various other tunnels * Bug #4723: Can't forward UDP fragmented packets with scrubbing enabled. * Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense * Todo #5368: Review /etc/ttys for serial console * Todo #5538: remove symlinks from /etc/ to /var/etc/ * Feature #5897: Make Alias url table persistent after reboot without internet * Bug #5976: Load cryptodev as a kernel module * Feature #5985: ntp pool command * Bug #5993: dhcp6c not started until an RA received * Bug #6016: ovpn-linkup not populating IPv6 gateways * Feature #6045: Updates that do not require a reboot should run reroot * Bug #6094: VIP Other subnet does not expand into NAT entries * Bug #6099: igmpproxy does not recognize upstream interface * Bug #6132: race condition in OpenVPN startup * Bug #6138: Long hostnames overlap the "time" title in the Monitoring graphs * Todo #6188: re-enable LUA in nginx * Bug #6257: Kernel panic with ALTQ * Bug #6298: OpenVPN IPv4/6 Local network(s) initial display state * Bug #6340: fsck hangs boot in background, fails to produce any action, resulting in broken firewall * Bug #6363: AutoConfigBackup Restore Actions column missing due to long XMLRPC sync merge strings in the configuration description * Bug #6367: Long delays with LDAP enabled w/local users during boot at "Synchronizing user settings..." * Feature #6373: RFC2136 DDNS could be more configurable to improve security * Feature #6374: Provide sample server-side logic to report peer's IP address for use with DDNS * Bug #6393: SMART service handling is incomplete/missing * Bug #6495: No default route on PPPoE after reconnect or IP change in some cases * Bug #6549: fstab is missing post-install * Todo #6606: Adapt captive portal to work without multi-instance ipfw * Bug #6628: extensions.ini can end up missing required items * Bug #6630: Set Defaults for Graphs - Traffic/WAN + Packets/WAN doesn't work * Feature #6639: Utilize nextboot to control the behavior of the next firewall reboot * Bug #6658: DHCP Relay not working on 2.3.2 * Bug #6663: IPv6 OpenVPN client is down after reboot * Bug #6664: It's impossible to use HE.NET tunnel iface as a parent for OpenVPN instances * Bug #6688: Special characters in a password cause problems * Bug #6717: Status / DHCPv6 Leases Issues * Feature #6743: Packet Capture - Filter MAC * Feature #6746: Option to select dark or misc background for Traffic Graphs when a dark theme is selected. * Todo #6755: Remove GLXSB references from 2.4 * Todo #6767: Change logout from GET to POST request * Bug #6769: Crash PacketFilter in bridge mode * Bug #6770: 802.11 stack on FreeBSD 11 requires changes to support its new device creation method * Bug #6778: CloudFlare Dynamic DNS fails when domain name uses a Second Level TLD * Bug #6781: OpenBSD description links are broken in Traffic Shaper * Bug #6782: pkg update can trigger multiple updates per second * Feature #6793: Add pound package to the pfSense repository * Bug #6820: Configure WAN Interface Boot Delay * Bug #6821: Static ARP attribute not applied when saving a DHCP static mapping * Feature #6822: diag_arp.php: Teach the ARP Table display to also display the status * Bug #6836: Wrong queue length on "/status_queues.php" page under heavy traffic * Bug #6828: Patch for "route change" is not present on 2.4 builds using FreeBSD 11 * Feature #6832: [PATCH] Add the USB ID for the Sierra MC7430 * Bug #6835: firewall_nat_out_edit.php Translation section hidden * Bug #6850: FreeBSD 11.0 Route Syntax Change For Non-Local Gateway * Todo #6853: Convert nanobsd installation to full install during upgrade * Bug #6862: mode 0444 for /var/etc/cert.crt leads to nginx crit error: 13: Permission denied * Bug #6879: GUI doesn't show rebooting notification after upgrading * Bug #6874: Dynamic DNS w/ DNSimple * Bug #6877: nsCertType "Server" property of a certificate is not detected if additional nsCertType flags are also set * Bug #6883: OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases * Todo #6885: Add vectorized logo in web interface * Bug #6919: Filter logs are broken, log has incomplete/invalid data * Bug #6890: PPP service name error * Bug #6892: CARP VIPs Deleted entering CARP Maintenance Mode * Todo #6894: Improvements and fixes on 2.4 installer * Bug #6901: services_unbound_host_edit.php: "Delete" button should be suppressed if < 2 host aliases listed * Bug #6905: XMLRPC Loop detection broken, secondary refuses to accept sync data * Bug #6906: Issues with /tmp and /var in RAM on 2.4 * Bug #6911: no network on hyperv-v 2012 R1 * Bug #6913: install on Hyper-v R2 * Bug #6920: Upgrading to 2.4 with a stale package .inc file can prevent the system from fully booting after upgrade * Bug #6925: System Update Failed * Bug #6929: Choosing ZFS during install results in a system that cannot mount root * Bug #6934: /usr/bin/install missing from new 2.4 installations * Bug #6937: Inbound traffic on enc0 is not creating a state with mobile IPsec * Bug #6943: Textdumps are not working on 2.4 (No DDB) * Bug #6947: Deleting an external CA wipes certificates in use * Bug #6949: username/password not used by proxy support * Bug #6952: Generating user certs from imported CA fails silently when no starting serial# is set * Bug #6953: on mismatching private key for CA, "edit user" silently creates user cert using different CA * Bug #6958: services_dhcp_relay.php: Needs to be converted to more recent rowhelper standard * Bug #6959: Remove or rename "LiveCD" option in the 2.4 installer * Bug #6962: GUI allows selecting missing diffe-helman Paremeters for OpenVPN * Bug #6967: DH Groups 22, 23, 24 missing from Phase 2 selection GUI * Bug #6969: Insufficient error checking on static ARP entries * Bug #7003: autoboot_delay on 2.4.0 * Bug #6985: NPt rules are causing a filter error on 2.4 * Bug #6986: reply-to is not functioning on pfSense 2.4 * Bug #6991: IPv6 traffic hitting a rule with policy routing and NPt fails/disappears * Bug #7001: Certificate manager requiring private key when importing CA certificate authority * Feature #7007: Change default IPsec/strongswan log levels * Bug #7008: OpenVPN sever unable to authenticate users on 2.4 * Todo #7021: system_advanced_network.php Deprecate/remove Device Polling on 2.4 * Bug #7025: wizard.php?xml=setup_wizard.xml - Setup wizard is flagging valid LAN IP addresses as invalid * Bug #7026: filter_logs.inc: parse_firewall_log_line(): Filter logs do not display * Todo #7032: Make a lack of ALTQ-capable interfaces more obvious to the user * Bug #7050: Limiter with PFsense 2.4 transparent proxy * Bug #7038: SG-1000 Quagga zebra service fails to start with signal 6 abort * Bug #7042: DHCP client configures wrong address in some circumstances (setfirst support missing from ifconfig) * Todo #7047: Update status.php with new info helpful to support staff * Todo #7054: Update OpenVPN to 2.4.0 * Bug #7059: firewall_rules_edit.php - strlen error when there are input errors * Feature #7061: OpenVPN 2.4 supports pushing IPv6, allow the GUI to define IPv6 OpenVPN DNS servers to push to clients. * Bug #7062: OpenVPN 2.4 treats "udp" and "tcp" as dual stack now, move old preference to udp4/tcp4 * Feature #7063: Add OpenVPN 2.4 ECDH options * Feature #7064: Add LZO4 options for OpenVPN 2.4 * Bug #7065: OpenVPN Server conf files not created in /var/etc after upgrading to 2017.01.01.1906 release * Bug #7066: vmx(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3 * Bug #7068: Prevent GCM encryption from being selected for Shared Key modes in OpenVPN * Feature #7071: Add TLS Encryption (--tls-crypt) as an optional TLS Key usage type for OpenVPN 2.4 * Feature #7072: vpn_openvpn_server.php / vpn_openvpn_client.php : Add controls to OpenVPN for Negotiable Crypto Parameters * Bug #7073: OpenVPN 2.4: client-cert-not-required is deprecated, replace with "verify-client-cert none" * Bug #7074: Due to OpenVPN protocol selection changes, automatic port number guessing/adjustment is not working * Bug #7075: firewall states show negative value for total bytes processed * Bug #7080: pkg_edit.php - rowhelper fielddescr disappears when last row is deleted * Bug #7081: Search Domains not populating from RA using SLAAC * Todo #7084: Intel IEEE 802.11ac wireless network driver * Bug #7086: stale zfs file systems * Bug #7088: DHCP does not accept input into MAC Control Fields. * Bug #7128: system_advanced_network.php - fugly IPv6 over IPv4 input field alignment * Feature #7097: Authentication cache for LDAP and RADIUS * Feature #7098: RAM Disk Management * Bug #7102: This firewall does not have any interfaces assigned that are capable of using ALTQ traffic shaping for igb interface * Bug #7105: ICMP type selection is assuming IPv6 when it should assume IPv4 * Feature #7111: Add protocol selection to radius server configuration * Bug #7116: a floating 'match' rule on LAN does not put traffic from a broswer on a clientpc into a shaper queue * Bug #7119: Changing LAGG attributes results in a panic/crash * Bug #7121: freshclam.conf advanced editing, configuring value of "Checks" has no effect on crontab entry * Feature #7122: Add filters to various dashboard widgets * Bug #7123: Kernel panic when setting TCP MD5 Password in OpenBGP * Bug #7124: Kernel panic when configuring 6to4 on a interface * Bug #7133: services_router_advertisements.php: Interface drop-down is not showing the user-configured interface name * Bug #7151: Interface Group Name hint is misleading * Bug #7145: rc.newwanipv6 running in all cases, even for a renew * Bug #7147: pfsense-utils.inc - is_ipaddr_configured() does not work properly with some IPv6 formats * Bug #7150: shell option before 1st reboot/wizard - can't login * Bug #7155: services_dhcp_relay.php: Section hide/show gets out of synch with enable checkbox * Todo #7160: Mark Required Fields on GUI Pages * Bug #7166: During bandwidth test 4860 with 2.4 got Fatal trap 12: page fault while in kernel mode * Bug #7167: Error creating higher VLAN ID on SG-1000 * Bug #7171: system_advanced_firewall.php: setHelpText is changing the field label also. * Bug #7176: IPv6 Monitor IP does not seem to propagate * Bug #7185: DHCP6c SIGTERM, SIGKILL * Feature #7193: NTP process PGRMF * Bug #7194: CARP/IP Aliases under same subnet not synced correctly * Feature #7196: setHelp method should use more conventiol argument syntax * Feature #7199: SG-1000 cpsw nics don't support ALTQ * Bug #7202: "Warning: sprintf(): Too few arguments in /usr/local/www/classes/Form/Group.class.php on line 65 Call Stack: * Bug #7206: Authentication Method Used in Bug 6751 Removed by Amazon * Bug #7219: vlan(4) interfaces do not have ALTQ support on pfSense 2.4, they had ALTQ support on 2.3 * Bug #7231: Web UI does not properly remove priq shaping rules when deleting an interface which causes subsequent rule failures without warning in the UI * Bug #7232: haproxy_pool_edit.php -- sprintf() too few arguments * Feature #7251: JavaScript & CSS are cached too aggressively by browsers, add URL fingerprint or other cache control mechanism * Bug #7254: Selection from long tab list that uses dropdown does not POST correctly * Bug #7265: Service dpinger does not start after upgrade from 2.3.3 to 2.4.0-Beta * Bug #7268: System Info Widget "All" button does not work with "Disable the automatic dashboard auto-update check" * Bug #7270: interfaces_vlan.php: Can't delete VLAN * Bug #7291: save and force update on rfc 2136 * Bug #7272: 6rd not functioning on 2.4.0-BETA * Bug #7273: diag_confbak.php: If a user enters 0 for the number of backups to keep, PHP errors occur * Bug #7274: status_ipsec.php: connect/ikedisconnect/childdisconnect actions still use GET, not POST * Bug #7276: 2.3.3 upgrade does not upgrade * Bug #7295: RFC2136 not updating at boot time * Bug #7297: system_certmanager.php: Following a link from a user to add a certificate does not present the "Choose an existing certificate" option * Bug #7309: ZFS - Can't find zroot, error 5 * Bug #7316: Fail Boostrap format port in * Feature #7321: DynDNS - Add DreamHost DNS support * Bug #7323: More user friendly defaults for firewall logs view * Bug #7324: DHCPv6 Dynamic DNS hostname * Todo #7331: Check OpenVPN server/client option visibility changes per mode * Bug #7334: SG-1000 Update failure * Bug #7336: syslogd is not running after installing or uninstalling a package with logging (e.g. tinc, haproxy) * Bug #7394: firewall_aliases_edit.php: Renaming an alias after input errors fails to update references * Bug #7401: custom_php_deinstall_command isn't being run during pkg post-deinstall because info.xml has already been removed by that step. * Bug #7415: favicon is not correctly implemented * Bug #7422: Typo in OpenVPN NCP description * Bug #7446: RFC2136 Dynamic DNS needs local directive so updates are sourced correctly * Bug #7448: XMLRPC Sync failure notice is ugly/long exception from cURL rather than our usual custom message * Bug #7451: vpn_openvpn_client.php - Fields not hidden/processed correctly in chrome * Bug #7452: Adding a gateway from interfaces.php does not work * Bug #7474: Problems adding gateway from interface edit * Bug #7485: scrub does not properly re-fragment unusual but valid IPv6 fragments, results in overlapping fragments * Bug #7499: ipsec.widget.php: Tunnel Status incorrect * Bug #7500: Upgrade From 2.3.3_p1 to 2.4 Fails (libssl.so.8 not found) * Bug #7501: Interfaces statistics widget GUI + JSON (2 issues) * Bug #7504: Info blocks do not work inside a table * Feature #7505: system_certmanager.php: Certificate list should show SANs, KU, and EKU for certificates * Todo #7507: Investigate and potentially add options for fast-io and sndbuf/rcvbuf tweaks to OpenVPN * Bug #7518: Not all language choices show selected text * Todo #7545: OpenVPN 2.4.2 * Feature #7527: Sign CSRs - subjectAlternateNames * Feature #7529: CPU Type * Todo #7546: d3pie version update * Todo #7540: Fix ca/cert input validation to allow currently blocked characters * Feature #7549: Enable Python support in Unbound * Bug #7559: l2tp wins unused code * Todo #7560: vpn_l2tp.php dns checks * Bug #7561: l2tp turn off local user database * Bug #7564: l2tp broken logging shortut * Bug #7565: openvpn and port 0 * Bug #7567: unused openvpn address pool setting? * Bug #7568: unused openvpn client_mgmt_port ? * Bug #7569: openvpn wizard reused settings cause wrong defaults * Bug #7572: openvpn client resolv-retry infinite issues * Todo #7573: openvpn tunnel networks and "second network address will be assigned" * Bug #7575: openvpn client and --route-up * Todo #7577: growl and notification suggestions * Bug #7579: pftop size sort is same as none * Bug #7580: pftop impossible options in web gui * Bug #7581: etc/pfSense.obsoletedfiles wrong path for diag_system_pftop.php * Bug #7584: privileges abuse with page-diagnostics-dns * Bug #7585: system_usermanager.php showcert does nothing * Todo #7586: system_usermanager_addprivs show user name * Todo #7587: sort system_groupmanager_addprivs privileges * Bug #7588: missing label for form in services_dyndns_edit * Bug #7591: services_captiveportal.php suggest default auth_method, and old links * Bug #7592: SG-1000: Unbound not always restarting properly after changes in /etc/hosts * Feature #7593: Enable FreeBSD 11 pvclock module in 2.4 builds * Feature #7598: Static IPv6 using IPv4 PPPoE as parent interface * Bug #7625: When creating IPv6 firewall rule for single host, netmask improperly displays * Bug #7629: FreeBSD PR affecting pfsense * Feature #7633: option to rearrange gateways under routing * Bug #7637: Any operation of the suricata package will cause the system to crash * Bug #7645: SG-1000 VLAN interfaces do not work without promisc mode * Feature #7666: Adding SAN DNS:username to User Certificates that are created via User Manager the same way as it is done via Cert. Manager * Bug #7677: Cert manager not creating server cert * Bug #7685: OpenVPN Auth Digest Algorithm list contains entries that are functionally identical and thus redundant * Todo #7689: bsdinstall does not automatically copy config.xml from USB drive like the previous installer * Todo #7708: bsdinstall does not have a "Recover config.xml" option like the previous installer * Bug #7719: Dynamic DNS updates not working on interface failover * Bug #7728: 1:1 NAT: Destination IP Alias not displayed as web link * Bug #7744: VLAN Priority options cause pf syntax error * Bug #7750: unbound refuses ipv6 queries after reboot * Bug #7751: Duplicated traffic graphs * Bug #7763: IX driver - fails to recognize media type with SFP after link drop * Bug #7770: php suhosin mdule error in crash report every boot on latest 2.4 snapshot * Bug #7777: IPsec P2 - Tunnel IPv4 edition form changes remote network mask to /32 * Bug #7784: IPsec widget breaks dashboard loading * Bug #7785: jQuery syntax error: unterminated regular expression literal * Bug #7790: dpinger / code using it, falsely defines a down gateway as up after dpinger gets restarted. * Bug #7795: NTP status widget: d.getSeconds is not a function * Bug #7804: System info widget CPU usage not updating in IE. Needs Math.trunc() polyfill. * Bug #7805: dashboard System Information - inconsistent date formats * Bug #7809: Wireless interfaces are not upgraded properly for 2.4.0 * Bug #7811: Installed pacakges dashboard widget breaks if no packages are installed * Bug #7813: Missing download statistics on captive portal with MAC filtering enabled * Bug #7819: php-fpm crashing * Bug #7827: Clicking "Cancel" while deleting a firewall state will still delete it * Bug #7830: LDAP authentication fails using SSL with intermediate certificates * Bug #7833: ipfw will not limit download speed - captiveportal * Bug #7834: Disabling captiveportal will not flush the ipfw pipes * Bug #7839: IPv6 ICMPv6 Type 3 Code 0 (hop limit exceeded in transit) reply uses wrong address. * Bug #7853: Signed CSRs always use SHA1, which is weak * Bug #7854: OpenVPN Remote Access Server Setup Wizard - Regex too strict * Bug #7864: OpenVPN (tun/tap) is not showing * Bug #7865: User groups -> Assigned Privileges doesn't work * Bug #7869: Hyper-v vm traffic shaper error: hn0: driver does not support altq * Bug #7877: Crash when enabling traffic shaper on more than 1 port * Bug #7878: GUI lag in Edit Phase 1 ipsec * Bug #7879: traffic shaper crashes with hfsc_dequeue * Bug #7913: Applying wizard for creating Traffic Shapers with PRIQ and Prioritize VoIP traffic doesn't create qVoIP and Floating Rule * Bug #7914: External Config Locator does not trigger a package sync or clear the wizard, so it does not result in a functional and expected restore * Bug #7919: Logging not working * Feature #7383: system_certmanager.php?act=new: Add new select option to sign a CSR * Bug #7118: ICMP rule with ICMP type "any" fails to load * Bug #7149: igb driver queue related crashes * Bug #7130: Lightsquid 3.0.4_2 HTTP 500 * Bug #6419: RRD_Summary reports incorrect bandwidth statistics. * Bug #6527: Squid 3.5 - Deprecated "ssl_bump server-first all" don't allow SNI in transparent mode with HTTPS/SSL Interception * Bug #6592: squid does NOT use EDH and EECDH cipher suites because "tls-dh" is not configured and so these ciphers are silently dropped - see squid documentation * Feature #6593: squid: allow user to configure DH key size, SINGLE_DH_USE, NO-SSLv3, Cipher-Suites - performance improvement hint * Bug #7192: ACME package cannot update more than one nsupdate type domain * Feature #6859: have an includedir by default (sudo package) * Feature #6951: Disable Auto Config Backup without uninstalling * Bug #6878: how to use snort, squid and squid_guard with a ram disk * Bug #6928: freeRADIUS, logging with "Access-Reject" not work in mysql table radpostauth * Bug #6950: Auto Config Backup always reports success * Bug #6983: pfBlockerNG-2.1.1_4 requires xmlrpc.inc which is removed or moved * Bug #6999: ntopng missing preferences menu * Bug #7009: syslog_ng Log Viewer page didn't get converted to the new 2.3 bootstrap * Bug #7017: Squid NT Domain authentication is broken * Bug #7197: Freeradius ldap authentication failed after update 1.7.5 to 1.7.6 * Bug #7498: Deprecated option included in OpenVPN client export * Feature #7548: Add absolute offset stat to NTP monitoring display * Bug #7555: Snort settings show translation metadata when creating a new interface that is not yet defined * Bug #7766: ACME Package on 2.4 requires pecl-ssh2, which is not in base any longer * Bug #7876: Potential XSS in status_monitoring.php