# CE-Next The next release of pfSense software (CE) * Feature #2386: Bridge member that is not an assigned interface * Feature #4405: Traffic shaping doesn't work when applied to a bridge interface * Todo #16876: Remove option "IPv6 over IPv4 Tunneling" * Bug #6333: Bootup starts/restarts dpinger multiple times * Bug #8100: pfsync deletes states on primary for connections established through secondary * Bug #7389: Limiter does not work with transparent proxy * Bug #8013: IPsec MSS clamping value shared for IPv4 and IPv6 * Bug #16891: ALTQ queues are shown for disabled interfaces * Bug #8192: dpinger - Change in ISP link-local IPv6 address drops connectivity * Bug #8263: Cannot create a nonlinear `Link Share` service curve because of: "the sum of the child bandwidth higher than parent" * Bug #8273: IPv6 GRE tunnel over PPPoE fails on startup * Bug #8611: unable to receive IPv6 RA's on SG-1000, default route lost * Bug #8815: IP addresses are removed from interfaces when link is lost and either IPv4 or IPv6 is dynamic * Bug #8964: IPsec async cryptography advanced setting - TCP traffic not passing through * Bug #9136: IPv6 Tracking Interfaces Lose IPv6 Address in Certain Cases * Bug #9384: devd putting "$" before variable contents when using single quotes * Bug #10530: Convert config version to be based on product version * Bug #10690: Not possible to make UFS install on ZFS formatted drive * Bug #10708: ZFS bootpool boot symlink issue * Regression #17057: Rules for offline gateways may still be generated with ``Skip rules when gateway is down`` checked * Bug #10875: PPP periodic reset does not fully restore gateway group round-robin functionality * Bug #10892: Large number of VLAN/LANs make floating rules are to read * Bug #16890: UPnP input validation allows using WAN for the inside interface * Bug #11110: Backup file should be checked before restoring a specific area * Bug #11296: Static route targets may still reachable via default route when the gateway they should route through is down * Bug #11335: Spoofing the MAC on a LAGG interface does not work for some NIC types. * Bug #11429: System Log / Settings form activates "Reset Log Files" button on enter * Bug #11430: PHP console spam after Assigning Interfaces * Feature #11440: Expand collapsed sections by clicking anywhere on header * Bug #11503: Using multiple authentication backends on an OpenVPN server fails * Bug #11541: OpenVPN status does not work properly when set to TCP and Concurrent Connections = 1 * Feature #11589: Fix iftop experimental traffic fetcher, unify and improve output style * Bug #12095: Memory leak in pcscd * Bug #12357: Captive Portal popup Logout button loads full login page in popup when clicked * Todo #12367: ZFS: Do not show memstick disk on target list * Feature #12553: Auto Config Backup: Allow selecting multiple backups for deletion * Bug #12715: Long system startup time when LDAP is configured and unavailable during startup. * Bug #13487: GUI IPV6-WAN-status stays "Offline, Packetloss" after a short communication hick up * Todo #16547: Make Priority field when editing a VLAN consistent with the VLAN Priority fields in firewall rules * Bug #13217: dhclient using default pid file location which does not exist * Feature #13244: Add help text under Timezone settings in the GUI * Bug #13273: dhclient can use conflicting recorded leases * Bug #13329: Traffic shaping Wizard sets invalid values for qVoip queue * Feature #13351: Improve Indicated Memory Usage in the Dashboard * Bug #9349: IPSec service start/stop/restart fails after settings change * Bug #13450: L2TP Clients system alias is not populated * Bug #13483: dhcp6c shouldn't be killed and restarted on interface reconfigurations * Feature #13499: Namecheap service type is missing help text for the password field * Bug #13621: GUI allows selection of ICMP types that pf rejects * Todo #13644: Enable ALTQ support in cxgbe(4) * Bug #13937: New OpenVPN entries are not immediately reflected in RRD graphs * Feature #15090: Improve feedback from config recovery during install * Regression #17068: Reroot fails to complete * Bug #14244: ``get_interface_list()`` in ``util.inc`` does not always match the expected device in ``dmesg``. * Bug #14577: OpenVPN not removing old Cisco-AVPair anchor rules and files in ``/tmp`` * Bug #14262: IPv6 firewall log entries do not wrap and force the table width past the width of the page * Todo #14264: Consider lowering default session timeout from current default of four hours (240m) * Todo #16875: Remove obsolete interface configuration scripts * Bug #14350: Captive portal text messages are not translated * Todo #14359: Reorganize Advanced Options * Feature #16189: Better Logging for LDAP Connection Errors * Bug #14921: External Config Locator does not trigger a pkg sync except on first boot * Bug #16931: DHCP Server and Relay pages list unsupported interfaces * Bug #16191: Early DNS registration can add invalid addreses * Bug #13961: Virtual IP address input validation does not check for overlap with DHCP address ranges * Bug #13480: GIFs are not automatically started when parent interface doesn't have an address at boot * Bug #16197: underscore (_) is not permitted in Identifier (Pre-Shared key) * Bug #16798: UDP Broadcast Traffic Sent out WAN when Policy-based Route is Defined * Bug #16937: Unbound cannot reload due to SSL/TLS certificate file permissions * Bug #16881: Auto-added routes for IPsec remote gateways are not removed after P1 deletion for any interface assigned to "wan" * Feature #12077: Allow stick-connections per gateway group * Regression #15074: ISO fails to boot UEFI * Feature #14762: Support X25519 and X448 public key algorithms in certificates * Bug #13734: PPP interfaces with a QinQ parent can't initialize the PPPoE node for link * Feature #14620: Support running DHCPv4 Server and DHCPv4 Relay at the same time on different interfaces * Bug #15809: UFS upgrades do not create new log files * Feature #13844: Make RADIUS Start/Stop accounting immediately log off a user that exceeds quota when reauthentication is disabled * Bug #15448: ``miniupnpd`` lacks IGDv2 support * Bug #16194: IPv6 ICMP firewall log entries marked with protocol "Options" instead of ICMPv6 * Bug #15116: Kea not working with UEFI HTTPBoot URL configured * Feature #15323: Display server description when WOL is sent using mac url or power-on button * Feature #14122: Allow selecting the repo branch on config restore * Todo #14352: Virtual IP address configuration input fields are handled inconsistently between VIP types * Regression #12549: Per-user Mobile IPsec settings are not applied to connecting mobile clients * Regression #14410: Behavior of ``earlyshellcmd`` changed, ``ngeth`` interfaces cannot be initiated early enough to pass assignment check * Feature #13362: Update dynamic gateway consumers when their interface is renamed * Todo #13508: Uncouple RAM Disk size from available kernel memory * Feature #15647: Include ability to generate Configuration file and QR Code for wireguard configuration * Bug #15518: Kea does not send configured TFTP server name * Feature #15648: Include ability to gen private/public key in UI for easier WireGuard client provisioning * Feature #14483: Conditionally reconfigure IPsec VTI interfaces only when necessary while applying IPsec changes * Bug #15757: Incorrect dashboard column spacing when using five columns * Feature #15745: Add User Manager Setting to control Remote Authentication fallback behavior * Feature #15766: Enable autocomplete for log filters * Bug #14648: Values obtained from ``sysctl`` are sometimes unexpectedly empty, leading to PHP and other math errors * Bug #5413: Reduce disruptions when changing DNS records from DHCP leases in Unbound * Feature #16159: Provide periodic connection reset for if_pppoe * Bug #15081: Upgrade fails due to undersized EFI filesystem * Feature #13843: Add ability to properly configure RADIUS captive portal user quotas of 4096MB or more * Feature #14166: Use netstat output for interface packet counters * Bug #10513: State issues with policy routing and HA failover * Feature #13293: Option to set auth-gen-token in OpenVPN GUI * Feature #12121: Wider "local network(s)" fields in OpenVPN server configuration * Bug #15902: After an IPv6 prefix and IP change on the WAN interface the KEA DHCP service crashes and cannot be restarted * Feature #14437: Add DynDNS Provider - Hetzner * Bug #12335: IPsec DNS inefficiency * Bug #13102: Deleting an IPsec tunnel doesn't destroy the SA (SADs/SPDs), causes crash in status_ipsec.php * Feature #13710: Support UTF-8 CA/Certificate subject components * Feature #15636: High Availability Status Changes * Bug #3132: Gateway events for IPv6 affect IPv4 services and vice versa * Feature #15659: Kea option for ``reservations-out-of-pool`` and associated input validation (IPv4 and IPv6) * Bug #15637: Kea DHCP service control inconsistencies * Bug #17088: Ensure IKEv1 is enabled when updating to strongSwan 6.1.0 or later * Todo #16950: Add upgrade code to normalize widget sequence data * Bug #17089: Warn the user that IKEv1 is deprecated and will be removed * Todo #16668: Upgrade PHP to 8.5.x * Regression #16510: Firewall Log Widget shows incorrect rule * Bug #17004: Config warning when saving duplicated alias * Todo #15408: Reduce inconsistencies between Configuration History with/without ZFS Boot Environments * Bug #15847: Kea DHCP lease utilization stats incorrect for delegated prefix pools * Bug #13793: filterdns does not reconcile modelled tables with the current state of filter tables * Feature #15922: Allow using dhcp mappings in host aliases for any service * Bug #13680: Package install scripts run after PHP upgrade produce errors * Feature #15544: Add hostname to Slack notifications * Bug #17021: Port Forward associated rule option "pass" is unnecessarily creating firewall rule entries with incorrect attributes * Bug #17023: Non-CARP VIPs used as the RA interface are used for radavd HA * Bug #17026: Gateways Widget No Longer Shows ms and % Strings * Bug #13792: Filterdns assumes sets of resolved addresses for each hostname are nonintersecting * Feature #15934: Kea Lease Reclamation and Affinity Options (IPv4 and IPv6) * Bug #17043: PHP error when removing all Data Encryption Algorithms from an OpenVPN instance * Todo #16874: Improve handling of custom interface assignments * Feature #16877: Extend the anti-lockout feature to all LAN interfaces * Todo #16879: Remove redundant hosts file reconfiguration when configuring an interface assigned to "lan" * Todo #16885: Improve dhcp6c wait timer during boot * Feature #16880: Extend the LAN bypass option for IPsec to all LAN subnets * Bug #16886: PPPoE Server includes LAN address as DNS even when bound to a different interface * Feature #16887: Extend ``enableallowallwan`` script to apply to all WAN interfaces * Bug #16888: Console Menu option 2 clears unrelated configuration * Todo #16889: Allow reconfiguring all WAN interfaces with ``rc.interfaces_wan_configure` * Todo #16878: Remove unused PF option "loginterface" from generated ruleset