# 2.4.3 2.4.x maintenance release * Bug #4031: Notifications mail bomb in some gateway failure circumstances * Bug #4310: Limiters + HA results in hangs on secondary * Bug #6318: IPsec dashboard widget causes GUI failure * Bug #6319: DHCP6 DDNS tsig key missing from dhcpv6.conf for reverse zone * Bug #6400: assign_interfaces.php issues with large numbers of interfaces * Bug #7015: IPsec not working behind NAT * Feature #6621: Permit DHCP Server Dynamic DNS server key algorithm type selection and use * Bug #6677: CARP VIPs are configured on disabled interfaces at boot time * Feature #6847: Register CN of OpenVPN clients in DNS Resolver * Bug #6848: Do not create an IPv4/6 gateway for an interface without according IPv4/6 address * Feature #6886: Allow Dual-Stack IPSec VPN * Bug #6974: radvd enabled on a disconnected interface kills RA completely on all interfaces * Bug #7131: DHCP v4&v6 DDNS missing options * Bug #7153: pkg-utils.inc - register_all_installed_packages() does not handle packages that are missing XML * Bug #7213: Hyper-V install, no disk found * Bug #7308: ZFS installer - check storage capabilities * Bug #7412: rtsold will not run on VLAN interfaces * Bug #7413: status_dhcpv6_leases.php: Some DHCPv6 leases are not displayed in the GUI * Bug #7469: local_sync_accounts() slowness can trigger GUI/XMLRPC failures with many accounts * Bug #7502: Cannot set router lifetime to 0 in radvd * Bug #7607: Chelsio T4/T5 CXGBE drivers not loaded as ALTq capable in the PfSense UI * Feature #7643: Send notification when boot completed * Todo #7762: Add uid check to pfSense-upgrade and exit unless it is run as uid=0 * Feature #7843: DynamicDNS Widget - Show Description * Bug #7972: Captive portals do not synchronize voucher data in both directions * Feature #8186: ipsec, allow configuration of multiple ike phase1 encryption ciphers #3711 * Bug #8056: Bridge + CARP crashes/freezes pfSense * Bug #8091: Limiters with fractional bandwidth values are not loaded correctly * Bug #8106: dhcp6c lock files not removed after unclean shutdown when using "Do not wait for an RA" on IPv6 WAN interface * Bug #8129: NTP Status -> Server time value incorrect for timezone Asia/Kolkata * Feature #8123: Add GoDaddy as a Dynamic DNS provider * Bug #8125: gateway 502 errors proposed fix for high ram systems * Bug #8185: status_queues, provide 'realtime' statistics #3792 * Bug #8182: Support shutdown scripts in /usr/local/etc/rc.d * Bug #8183: pkg, fix, reinstall missing package #3866 * Feature #8184: pppoe, allow configuring pppoe on a carp interface so its only active on the master #3830 * Feature #8191: IPv6 - Support for configuring multiple DUID types * Bug #8208: Restoring a config in 2.4.2 with 2.3.X Security/Errata Only repo selected breaks PHP * Bug #8200: Set VLAN priority on on dhcp6c packets * Feature #8205: Allow display of temperature in Fahrenheit * Bug #8219: No gateway groups on french language * Bug #8220: UI does not allow multiple MAC for same DHCP address * Bug #8226: Pass-through MAC automatic additions adds duplicate * Bug #8231: Undefined function while restoring config from older version * Todo #8237: Import netstat kresolve_list() fix from stable/11 to improve performance on some platforms * Bug #8238: A global definition for $cpconfig is missing ... * Bug #8239: If IPsec bypasslan is enabled while the LAN interface is disabled, all traffic bypasses IPsec * Feature #8244: Add Dynamic DNS RFC 2136 Client server key algorithm choice * Todo #8245: use delayed compression for sshd * Bug #8249: pid 77785 (php-fpm), uid 0, was killed: out of swap space * Bug #8252: Automatic SAN code for certificates does not work properly with additional SANs when the CN contains a space * Feature #8257: pfSense Diagnostics -> Packet Capture support for loopback interface * Bug #8259: Range description is not encoded in firewall_schedule.php * Bug #8261: OpenVPN tunnel network handled incorrectly with a /31 tunnel network * Bug #8266: Bogus error message occurs on killing OPenVPN connection * Feature #8267: OpenVPN tap bridge configurations without a tunnel network need a route-gateway for routes/redirects * Bug #8268: RAMdisk warning pop-up appears when no changes have been made * Bug #8275: Input validation for Certificate SAN (Subject Alternative Name) allows IP addresses to be entered when FQDN/Hostname is selected * Feature #8278: Add control for source address of RFC2136 updates * Bug #8290: filter.inc, make filter_expand_alias_array() return consistent results between first and second call. * Bug #8296: status_services.php: AJAX requests via GET can control services without CSRF validation * Bug #8297: User with no privileges cannot logout. * Bug #8298: OpenVPN Wizard protocol defaults to "UDP IPv4 and IPv6 on all interfaces" causing problems * Bug #8300: diag_system_activity.php: Potential XSS due to encoding of process output * Bug #8301: Dashboard Widgets may no longer need CSRF disabled * Bug #8302: traffic_graphs.widget.php potential XSS via settings * Bug #8303: Undefined Function * Bug #8317: Captive Portal Sync Errors * Bug #8321: IPv6 LAN Network missing from IPsec LAN bypass list * Bug #8322: PPP UI error * Bug #8323: Remote Logging Options and IPv6 * Todo #8331: Update Copyright Year on GUI Login page * Bug #8333: Dynamic DNS updates may fail when using a gateway group as the interface when the default route is down * Bug #8337: System Authservers page Authentication Containers field should be marked required * Bug #8338: Wrong LDAP host is reported when testing system auth server settings * Feature #8348: Add firewall rule tracker ID display to rule list and rule edit page * Bug #8353: Some automated rules are missing tracking IDs * Feature #8356: igmp, Add option to disable the igmp service * Bug #8360: pf rules occasionally contain "!/" where the WAN network/netmask should be * Feature #8371: Reduce config.xml size by removing picture widget images to file system * Bug #8269: Passing an invalid RRD file to rrd_fetch_json.php via the left= parameter in POST prints the supplied name to the user without encoding