# 2.4.5 2.4.x maintenance release * Feature #3244: Check that OpenVPN tunnel network does not overlap any other subnet * Feature #3473: Allow configuration of OpenVPN keepalive * Feature #3792: Group name size limit too restrictive on Active Directory Users * Bug #4674: invalid state table entries after WAN IP change * Feature #5851: Add copy action to OpenVPN client / server * Bug #6195: Cannot set Manual Outbound NAT when Language is pt_BR * Bug #6263: Encryption options for every P2 on a given P1 are written to each P2 individually inside ipsec.conf with multiple P2 entries + split conn entries * Bug #6846: System misreporting Super Micro C2558 platform as Super Micro C2758 * Bug #7186: Unable to use national symbols in password fo ACB package * Bug #7359: Status/OpenVPN Page Sorts Incorrectly * Feature #7537: Include mellanox mlx4 and mlx5 ethernet driver * Bug #7601: Dynamic DNS - Hostname should not be required for DNS-O-Matic * Feature #7791: include /usr/bin/strings in core pfSense * Bug #7840: OpenVPN 2.4 Server: Hide Interface when Protocol is Multihome * Bug #8014: DynDNS wildcard option doesn't work for provider Loopia * Bug #8051: XG-2758 - Wrong Interface Assignment * Bug #8443: DHCP relay not starting after ovpnc interface is unchecked - vm 2.4.3 * Bug #8531: URL Table aliases don't support FQDNs or names that return >1 IP * Bug #9867: Packet Capture IPv6 rejects all packets if CARP type is set in Protocol field * Feature #8703: Allow user to search firewall alerts by tracking ID * Bug #8847: IPsec status "Show Child SA entries" button only expands and never collapses * Bug #8907: wizard.php - $field['type'] - "Select" doesn't have the attribute "Size" defined * Feature #9030: Allow TLS Key Direction with OpenVPN * Bug #9053: Dynamic DNS will not allow Route 53 wildcard record * Feature #9078: Investigate adding knobs for explicit-exit-notify in OpenVPN * Feature #9111: Add IPsec VTI interface MTU support * Bug #9133: "Show all configured leases" does not stay set after deleting a lease * Bug #9150: Web authentication RADIUS package shows PHP error if unable to resolve FQDN of RADIUS server * Bug #9218: SNMP sysDescr does not display hostname and patch version * Bug #9234: Wording consistency in Certificate Management notifications * Feature #9251: DNS Resolver (Unbound) Python Integration * Bug #9243: IPsec ID type keyid not explicitly set * Todo #9245: Update copyright notices to 2020 * Bug #9248: Dynamic dns updates on azure ipv6 service is not working properly * Feature #9256: adjust frequency of geom rebuild notifications. * Bug #9258: Error deleting tunnel type P2 when mixed with VTI * Bug #9267: dhclient does not handle protocol timeouts or script failures correctly * Feature #9268: Add Linode Dynamic DNS support * Bug #9271: Azure DDNS whitespace cleanup * Feature #9280: Add AAAA record type support for DynDNS with Digital Ocean * Feature #9285: Add an option to disable the ping-check in dhcpd * Bug #9292: Default route as indicated by "(Default)" does not match the actual default route on the OS. * Feature #9323: Option to hide 'Kernel PTI' from sysinfo widget * Bug #9327: Using the character "ยค" in OpenVPN password field creates invalid config.xml * Bug #9361: Cloudflare Not Allowing "*" Hostname Entry in Dynamic DNS * Bug #9362: rc.dyndns.update: Cloudflare DDNS with proxy enabled doesn't work at all * Bug #9407: Update jQuery to current version (3.3.1 or later) * Feature #9412: Add sorting and search/filtering to CA/Certificates * Feature #9532: GUI indication and options for MDS mitigation * Bug #9447: Configuring LAGG at XG-7100 Switch Ports Broken * Bug #9448: Dynamic DNS options showing in GUI for IPv6 when not in use * Bug #9543: diag_dns.php: Reverse lookup of IPv6 fails with "Host must be a valid hostname or IP address." * Feature #9452: Add Gandi LiveDNS DynDNS client. * Bug #9466: DHCP (IPv4) relay mistakenly listening on upstream interface * Bug #9468: Removing the last limiter does not sync to secondary via XMLRPC * Bug #9469: Removing the last ATLQ traffic shaper queue does not sync to secondary via XMLRPC * Bug #9483: UFS filesystem is not being mounted noatime. * Bug #9488: No console when booting CE Memstick UEFI. * Bug #9522: Diagnostics > System Activity shows only the header * Bug #9533: XG-7100 FAT config restore not working post-install * Bug #9540: PHP Uncaught Error in Status/System Logs/Firewall/Dynamic View * Bug #9541: Non-admin user with admin rights is given the wrong URL for the user manager * Bug #9550: New privilege matching method does not allow menu or tab links to anchors (#foo) * Bug #9558: GPS NTP source PHP errors * Bug #9569: Fix serial console terminal size issues * Bug #9580: Dynamic DNS DNSimple client errors * Bug #9582: PHP error setting up VLANs from the console * Bug #9584: Potential XSS in services_acb.php via hostname parameter with legacy settings * Bug #9586: Unbound Access List /31 UI Issue * Feature #9590: RFE: Add additional prefix delegation size entries to dropdown-list * Bug #9595: OpenVPN does not resync when running on a gateway group * Bug #9602: Dynamic DNS with DigitalOcean not working * Bug #9609: Reflective xss in services_captiveportal_mac.php * Bug #9610: picture.widget.php: Arbitrary file read/write * Bug #9612: Run fsck with -z for ufs on upgrade to address FreeBSD-SA-19:10.ufs * Bug #9736: status.php: Sanitize oinkcode and etprocode of snort/surricata * Bug #9668: Running /etc/rc.newipsecdns breaks FRR BGP on VTI interfaces * Bug #9674: hidden OpenVPN settings are validated and written to file * Bug #9684: System Notifications: Asterisks over writing current password causing notifications to stop working. * Bug #9692: system_authservers.php: Descriptive name can be changed by removing read-only property via inspect element * Feature #9693: Bypass automatic backups * Feature #9694: Redact ACB encryption password from status.php * Feature #9695: Add Ability to Force NAT-T Encapsulation on IKEv2 Peers * Feature #9705: Add kernel memory usage to status.php * Bug #9708: /etc/inc/unbound.inc: Pfsense Default Unbound Configuration does not Prevent DNS Rebinding Attacks Against Localhost * Bug #9851: PHP error in logs * Bug #9719: system_certmanager.php - Descriptive name field disappeared when adding certificate for user * Bug #9720: vpn_ipsec_phase2.php - no remote network field in VTI mode * Bug #9722: services_captiveportal_vouchers.php wrong status icon link * Bug #9727: status.php: Sanitize influx_pass * Bug #9728: status.php: Sanitize tinc private key * Bug #9729: status.php: Sanitize zabbix-agent tlspsk key * Bug #9731: Path Traversal vulnerability in picture widget * Bug #9741: interfaces_ppps_edit.php: WebGUI don't show local ip / gateway ip values * Bug #9747: IPsec widget - Missing escape of domain backslash * Bug #9748: openvpn_wizard.xml: DH 15360 and 16384 fall back to 1024 * Bug #9756: vpn_openvpn_(client|server).php: js issue when selecting multiple NCP * Feature #9757: DH groups 25,26,27 not listed for phase1 & phase2 * Bug #9763: Trying to set VLAN Priority causes error * Bug #9764: status.php: Sanitize barnyard_dbpwd * Feature #9766: diag_packet_capture.php: allow to input multiple tcp/udp ports * Bug #9767: Interesting Traffic Will not Initiate an IPsec VTI tunnel. * Bug #9770: XML-based Packages do not activate shortcuts * Bug #9778: Inconsistent update check results * Bug #9779: Dynamic DNS class constructor uses deprecated function name * Bug #9780: PHP warning in diag_dump_states.php * Bug #9781: Fix IPsec VTI interface creation logic * Bug #9782: XMLRPC auth error message format is inconsistent with GUI auth error message * Bug #9784: status.php: Sanitize bandwidthd db password * Feature #9791: Ability to filter Diagnostics ARP Table by IP range (DHCP) * Bug #10230: Typo in the setup wizard final page * Todo #9799: Create custom CSRF callback page with proper theme & more warnings * Bug #9801: VTI IPv6 addresses don't get assigned * Bug #9804: services_captiveportal.php: Image upload does not validate file type * Feature #9816: firewall_aliases.php: add ability to export list of aliases * Bug #9819: Captive portal: Change order redirect page is selected * Bug #9829: NTP Status vs. parsing NTP Access Restrictions * Feature #9831: diag_packet_capture.php: print packet capture start time * Bug #9840: PHP7: Uninitialised array in upgrade_config.inc * Todo #9864: Set autocomplete=new-password for user/password fields in forms * Todo #9868: Add clientAuth EKU to Server type certificates * Bug #9873: Switching the System Update to Development renders the system unbootable * Bug #9898: DNS over TLS hostname verification does not save * Feature #9905: ospf / ospv3 packet capture * Feature #9911: Show confirmation box before disconnecting PPPoE * Bug #9921: Limiters allow invalid delay values * Bug #9931: 0.pfsense.pool.ntp.org doesn't work on IPv6 only installations * Bug #9938: Queue stats parser broken if bytes > 9999999999 * Bug #9945: wizard error on clean install * Bug #9946: package install failed: unset the 'vital' flag with: pkg set -v 0 pfSense * Bug #9953: no meta.txz, Unable to retrieve package information * Bug #9954: status_ipsec.php: Unable to manually connect P2 when P1 is up but not P2 * Bug #9961: status_upnp: UPnP status not showing rules when using override WAN address option * Bug #9963: DNS servers assigned dynamically are omitted if also assigned manually when override is disallowed * Feature #9966: allow to disable APIPA blocking * Bug #9969: static route remain in the OS routing table after deletion * Bug #9971: sshguard error: Logging subprocess (exec /usr/local/sbin/sshguard) exited with status 1. * Bug #9975: PHP error on upgrade from 2.4.4-p3 to 2.4.5 * Todo #9976: strongswan: Update to 5.8.2 * Bug #9977: Enabling Captive Portal on 2.4.5 breaks network connectivity * Bug #9984: PHP error in 2.4.5 services_dyndns_edit.php * Bug #10275: L2TP and PPPoE user password issues * Bug #10139: IGMPPROXY spamming the main systemlog * Todo #10157: Setup new redirect subdomain and processes * Bug #10159: nginx error " 48: Address already in use" sometimes displayed in the logs when reconfiguring captive portal * Feature #10166: Add DNS-over-TLS as option to source/destination port range when creating a firewall rule * Bug #10168: firewall_rules_edit.php: Firewall GUI allows selecting 'not' and 'any' for source/destination which is invalid * Bug #10172: A few places in the UI still refer to "SSL" instead of "SSL/TLS" * Bug #10183: diag_packet_capture.php: Capture for 'pfsync' fails * Bug #10184: Shaper Add Child Scheduler options Codel wrong description link * Bug #10195: radvd spamming routing log with "IPv6 forwarding on interface seems to be disabled, but continuing anyway" * Bug #10189: pfsense calculates wrong ip header checksum when reassambling packages with different mtu * Bug #10196: Cloudflare dyndns not working (Invalid TTL) * Bug #10217: PHP Warning: Invalid argument supplied for foreach() in /etc/inc/ipsec.inc on line 952 * Bug #10233: jquery-ui theme files missing * Bug #10235: OpenVPN server tries to push compress parameter when it's empty * Bug #10246: NAT: Syntax error when "Automatic create outbound NAT rules that direct traffic back out to the same subnet it originated from" is enabled * Bug #10248: PHP Warning: A non-numeric value encountered in /etc/inc/rrd.inc on line 418 * Bug #10254: pf error "too many elements" when attempting to load large tables * Bug #10255: status_logs_filter.php: PHP error when log entry contains invalid port * Bug #10287: OpenVPN TLS key direction value added to existing tunnels is 0. * Bug #10303: pfSense-upgrade is not upgrading itself * Bug #10308: PHP error in /etc/inc/service-utils.inc on line 378 * Bug #10324: system_usermanager_addprivs.php: User account full name is not encoded before output * Bug #10355: diag_ping.php: Potential XSS via Hostname parameter * Feature #9620: User privilege to manage integrated switch * Bug #8139: LADVD not working on LAGG interfaces * Todo #9392: Status_Traffic_Totals needs updated for vnstat 2.0 * Bug #9583: Freeradius 3 auth error on OTP (only on PFSense 2.5-dev) * Bug #9601: Status_Monitoring rrd_fetch_json.php does not encode errors returned by the RRD module. * Bug #9807: Packets Monitoring graphs are being incorrectly scaled