# Future Items for an indeterminate later release * Todo #32: PPPoE Server users integration with user manager * Todo #33: L2TP users integration with user manager * Feature #84: Nightly Filter Summary E-Mail * Feature #96: Add "All local networks" to source and destination drop down boxen in firewall rules * Feature #286: Backup/restore users individually * Feature #521: Group manager Assigned Permissions * Feature #701: Interface groups with NAT * Feature #1257: Handle encypted CA/Certificate private keys * Feature #1268: Allow mass renewing of certs * Feature #1337: VLANs with different MAC address than parent interface * Bug #1675: Captive portal logout problems with pop-up blockers. * Feature #1831: Captive portal IPv6 support * Feature #2024: RRD Graphs for packages * Feature #2593: sync NTPD, SNMP config between HA members * Feature #2965: Mac Firewalling * Feature #3115: Traffic shaping for multi WAN * Feature #3185: Accommodate a DHCPv6 failover-like mechanism * Feature #3377: OAuth2 authentication in captive portal * Feature #3652: OpenVPN - Dynamic IPv6 Tunnel Network * Feature #3696: Multiple items backup/restore * Feature #3697: New backup/restore area: Certificates * Feature #3882: Add OUI database to the base system, remove dependency on nmap * Feature #4098: Add option to force a password change on login * Feature #4195: Aliases: sections * Feature #4234: allow for strict user <> cn validation of mobile ipsec users when using rsa+xauth * Bug #4406: ALTQ problems with wireless cloned interfaces * Bug #4479: Firewall rules won't match GRE interface after applying IPSEC transport encryption on GRE tunnel * Feature #4724: Captive Portal Status Add Client Hostname * Feature #4776: Add 802.1x dynamic vlan support * Feature #5307: Add logarithmic scale option to RRD graphs * Bug #5367: Safari repeatedly tries to reload dashboard * Feature #5510: Need a simple way to enable/disable package-installed services * Feature #5619: Curl with ARES support * Feature #5735: Automaticaly add DHCP leases to alias list or make it readable in selected fields * Bug #5786: Check WebConfigurator port for conflicts * Feature #5835: Improve OpenVPN client gateway detection in edge cases where the remote does not send gateway information * Todo #5902: Use a common place for default values * Feature #5950: DHCPv6 Server support for PD of PD-obtained networks * Bug #6186: race conditions in service startup * Feature #6457: Allow ability to configure AWS EC2 AMI via userdata * Todo #6647: Enable Additional Security Headers * Bug #6696: Add configure link to Status > Queues error message if traffic shaping not configured * Todo #6697: White squares around the numeric values in the Status / Queues page * Feature #6728: Route53 API mod and Geolocation * Feature #7078: Allow reordering of client specific overrides in OpenVPN * Bug #7082: pkg_edit.php - impossible to use default_value with rowhelperfield * Bug #7138: Pfsense wide dhcpv6 client doesn't recognise ifid statement * Feature #7181: Add Top and Add Bottom on Seperator * Feature #7182: Break up System Widget on the Dashboard * Bug #7195: pkg_edit.php - tag has no effect on fields other than checkbox/input * Bug #7222: Encryption No Longer Enforced for Email Notifications * Feature #7244: Publish pfsense as a Vagrant Basebox * Bug #7288: The field 'Distinguished name Organization' contains invalid characters * Feature #7783: Support for hosting VMs on pfSense using bhyve * Feature #7847: USB NIC not loading (TP-Link UE300 RTL8153) * Feature #7852: Add views support to Unbound GUI * Feature #8316: expiration date when creating new rules * Feature #8474: Easier Conversion to HA Pair from Existing Non-HA Firewall * Bug #8502: main (top) menu items do not drop down in some cases * Bug #8614: Cannot remove Additional BOOTP/DHCP Options * Feature #8694: Client CA Auth for PFSense WebGui * Feature #8712: QOS on ipsec links * Feature #8775: Use SRV record for LDAP Authentication * Bug #8820: System/Advanced/Misc - "Do not kill connections when schedule expires" UN-checked still leaves existing connections open. * Feature #8879: DHCP options ADD force options * Bug #9344: OpenVPN click NCP Algorithms will always go to DH Parameters website(in Chinese-Taiwan) * Bug #9353: PHPSession errors from limited access to dashboard and widgets * Feature #9536: Support dynamic prefix in DHCPv6 Server * Feature #9574: Show changelog at package upgrade * Feature #9680: Seperate DHCP Server and relay per interface * Feature #9717: Search box for pfsense ? * Feature #9718: Make diag_states_summary table sortable * Bug #9755: package description wrong link https://www.freshports.org/security/openvpn-client-export * Feature #9942: Give pfSense the possibility to change the keyboard Layout for console users * Feature #10204: Possible clarification of Track IPv6 Interface Subnet ID * Feature #10223: Add the ability to create additional loopback interfaces * Bug #10310: Systems with low RAM and several packages may temporarily fail to load large tables after an upgrade * Bug #10352: RADIUS authentication fails with MSCHAPv1 or MSCHAPv2 when passwords contain international characters * Feature #10467: Email alert functionality for system health * Feature #10987: Add support for secure boot * Feature #11056: Add option to disable flow-control on interfaces in GUI * Bug #11093: ral(4) driver non-functional in arm64 * Feature #12863: dynamically tune sha512crypt rounds * Feature #11270: Consider integrating Nebula mesh VPN * Todo #11280: Add WireGuard to ALTQ list * Feature #11302: WireGuard XMLRPC sync * Feature #11324: Separate syslog "Remote log servers" Parameters * Bug #11352: CTF types > 2^15 in the pfSense kernel config results in DTrace failing * Bug #11473: System Activity shows invalid data on SG-3100 * Feature #11498: WireGuard does not pass multicast traffic to peer * Feature #11604: WireGuard Dynamic Listen Port Randomization * Feature #11588: Automatically suggest next IP address in Wireguard interface subnet when creating a peer * Feature #11921: Feature Request: Compile unbound with EDNS Client Subnet (ECS) module (--enable-subnet) * Bug #12013: Reading log data is inefficient in certain cases * Todo #12025: Add 1:1 Validation to Notify Someone They are 1:1 NAT'ing an Interface Address * Feature #12521: Add the BBR2, QUIC, RACK Congestion Control (CC) protocols * Feature #15078: Display all available updates on the dashboard * Bug #15228: User manger fails to display certificate option for a new user in case of input error * Feature #2676: Reply-to option in firewall rule * Feature #2479: Allow reordering of the traffic graphs on the dashboard * Feature #290: Add Multi-WAN awareness to UPnP * Feature #7260: Source OS / p0f Database Missing Modern Operating Systems * Bug #6167: IPsec IPComp not working * Feature #946: Allow aliases to be used to define IPsec phase 2 networks * Feature #13805: A way to reliably determine if system is the primary or secondary in CARP * Feature #14666: Option to add automatic pass rules for IGMP Proxy which allow IP options * Feature #12564: add column to show that an Alias is in use by or not * Regression #12183: Changing MAC address for PPP parent interface stopped working * Feature #10250: DHCP lease view by interface * Feature #4632: Support for Multipath TCP (MPTCP) * Feature #6742: OAuth2 authentication for OpenVPN (and for FreeRadius) * Bug #15708: The filterdns service won't start * Feature #10404: Consider using chrony for NTP services