# 2.6.0 Next release * Feature #2668: Support aliases in OpenVPN local/remote/tunnel network fields * Feature #4769: IPv6 support in the Traffic Shaper Wizard * Bug #4893: Error loading rules when URL Table Ports content is empty * Bug #6275: Disconnected IPsec phase 2 entries are not shown in IPsec status * Bug #6507: GRE and GIF tunnels on dynamic IPv6 interface are not brought up during boot * Feature #7416: DHCPv4 client does not support ``supersede`` statement for option 54 * Bug #7547: Static routes using aliases are not automatically updated when alias content changes * Feature #7749: Support ``0`` CIDR mask for IGMP Proxy networks * Bug #7801: UDP fragments received over IPsec tunnel are not properly reassembled and forwarded * Bug #8390: Input validation does not prevent removing a gateway used by a DNS server * Bug #12050: "GoTo line #" function does not work on ``diag_edit.php`` * Bug #9058: Kernel panic during L2TP retransmit * Feature #9092: Option to set interval of forced Dynamic DNS updates * Bug #9277: MBT-4220/2220: pfSense hangs when running sysctl -a * Feature #9297: Graph for hardware temperature readings * Feature #9341: Support DNS Made Easy authentication without a username * Feature #9439: Poll Interval For GPS and PPS * Feature #9877: QEMU Guest Agent * Todo #10298: Use SHA-512 for user password hashes * Bug #10304: ``radvd`` only responds to the first Router Solicitation received after each multicast Router Advertisement * Feature #12194: Support Check IP services which return bare IP address values * Bug #12195: IPsec writes CRL files when tunnel does not use certificates * Feature #10587: UPnP/NAT-PMP STUN configuration options * Bug #10662: Restoring from AutoConfigBackup presents reboot type selection option then reboots automatically * Feature #12226: Copy button for group entries in the User Manager * Bug #10706: Kernel route table entries are removed if they match disabled static route entries * Bug #10955: XMLRPC sync results in an error when a failover peer IP address is specified in DHCP server settings for an unconfigured interface * Feature #11118: Backup and restore SSH host key(s) * Bug #11290: Package ```` and ```` content missing from configuration in some cases * Bug #11337: Interface column empty in list of GIF tunnels when using IP Alias on CARP VIP as Interface * Feature #11439: IPv6 support in ``easyrule`` CLI script * Regression #11447: EAP-RADIUS Mobile IPsec clients with RADIUS-assigned addresses do not get additional configuration attributes * Regression #11470: Panic when using CBQ traffic shaping * Feature #11496: Support for NTP Peer mode * Todo #11507: Update font formats to WOFF2 * Regression #11512: DHCP Leases page and ARP table page fail to load if DNS is not available * Bug #11552: Incorrect phase 2 entry removed when deleting multiple items consecutively * Bug #11581: Cannot configure WAN IP address with ``/32`` CIDR mask via console menu * Bug #11599: Modifying static routes results in a logged error, changes are not reflected in routing table * Bug #11653: Duplicate ``comconsole_port`` lines in ``/boot/loader.conf`` * Feature #11659: Support for UEFI HTTP Boot option in DHCPv4 Server * Bug #11662: QinQ using OpenVPN ``ovpn`` interface as a parent is not configured at boot time * Bug #11675: VLAN and QinQ edit pages allows selecting incompatible OpenVPN ``tun`` interfaces * Bug #11701: Missing global ``$g`` declaration in ``config.lib.inc`` function ``pfSense_clear_globals()`` * Bug #11727: Cannot enter persistent CARP maintenance mode when CARP is disabled * Bug #11734: NAT rule overlap detection is inconsistent * Feature #11750: Support for network interfaces using the ``qlnxe`` driver * Bug #11816: RFC 2136 Dynamic DNS client uses IPv6 alias VIP instead of Track IPv6 address for AAAA records * Bug #11818: Mixed use of aliases in a port range produces unloadable ruleset * Bug #11829: OpenVPN client certificate validation with OCSP always fails * Bug #11831: Certificate Revocation tab does not list active users of CRL entries * Bug #11843: Potential XSS vulnerability in Captive Portal ``redirurl`` handling * Bug #11846: Logging configuration added by a package is not removed on uninstall * Bug #11863: Unable to create nested URL aliases * Feature #11865: Option to validate OpenVPN peer TLS certificate key usage * Bug #11891: strongSwan configuration contains incorrect structure for mobile pool DNS records * Bug #11894: Vouchers may expire too early when using RAM disks * Feature #11895: Require user to manually apply changes after altering static route entries * Bug #11902: Incorrect variable substitution in captive portal error page * Bug #11905: DHCPv4 server configuration does not include ARM TFTP filenames * Bug #11909: Output from reboot process is printed on Backup & Restore page when restoring a configuration file * Regression #11910: IPsec status tunnel descriptions are incorrect * Bug #11959: PPP interfaces lose the description field in ``ifconfig`` output when restarted * Bug #11922: Certificate manager reports CA as in use by an LDAP server when LDAP is not configured for TLS * Bug #11926: Advanced DHCP client configuration "Protocol timing" help text is in the wrong location * Todo #11933: PC/SC Smart Card Daemon ``pcscd`` running on all devices at all times, should be optional * Feature #11935: Log external IP address of OpenVPN clients on connect and disconnect * Regression #11938: DNS Resolver does not add PTR record for OpenVPN clients * Bug #11951: IPsec status fails when many tunnels are connected * Bug #11969: PHP error if no DHCPv6 Relay interfaces are selected * Todo #11976: Compliance with pfSense style guide in Dynamic DNS service code * Feature #11978: New Dynamic DNS Provider: Strato * Todo #11983: Hide "Reboot and run a filesystem check" for ZFS systems * Todo #11985: Ensure ``/usr/local/sbin/`` scripts use full path to executable files * Bug #11999: OpenVPN IPv6 tunnel network is not validated properly * Bug #12000: Remote log server input validation allows invalid values * Bug #12001: System attempts to stop inactive services at shutdown * Bug #12002: Boot messages contain entries about configuring LAGG/VLAN/QinQ interfaces even when no entries of those types are configured * Bug #12007: Dynamic DNS cache expiration time check calculation method may cause update to happen on the wrong day * Bug #12020: OpenVPN RADIUS-based firewall rules use incorrect port ranges * Feature #12011: Disable log compression on new installations when ``/var/log`` is a ZFS dataset with compression enabled * Todo #12012: Improve log settings help text for file size, compression, and retention count * Regression #12021: NoIP.com incorrectly encodes Dynamic DNS update credentials * Bug #12022: Incorrect OpenVPN Client Export help link * Bug #12023: Mobile IPsec NAT/BINAT entries missing from firewall rules * Bug #12026: Applying IPsec settings for many tunnels is slow or times out * Regression #12028: SNMP daemon issues with pf nvlist changes * Regression #12048: Error during XMLRPC synchronization due to changes in ``pear-HTTP_Request2`` * Bug #12448: Set OpenVPN Gateway Creation value to "Both" by default for new instances * Bug #12034: Certificate Manager performs redundant escaping of special characters in certificate DN fields * Feature #12035: Input validation to prevent unsupported UTF-8 characters from being used in certificate subject components * Bug #12038: System attempts to start inactive services at boot * Bug #12049: Input validation incorrectly rejects a second IPv4-only GRE tunnel * Bug #12039: Gateway alarm always triggers IPsec restart * Bug #12041: Certificate Manager shows incorrect DN for imported entries with UTF-8 encoding * Todo #12044: Improve IPsec identifier settings * Todo #12051: XMLRPC client improvements * Regression #12052: IPsec status IKE disconnect button drops all connections for the IKE ID, not a specific IKE SA ID * Regression #12057: 21.09/2.6.0 - High CPU usage and slowness with ``pfctl -ss`` * Bug #12481: Temporary files for firewall rules generated from RADIUS ACL entries are not deleted on unclean shutdown * Todo #12060: Remove deprecated ``libzmq`` code and references * Regression #12069: Panic in ``pfctl`` with large numbers of states * Bug #12072: FQDN L2TP server address is only resolved at boot * Bug #12075: Changes to an existing IPsec configuration are not applied on HA secondary after XMLRPC sync * Bug #12076: OpenVPN RADIUS-based firewall rules do not use expected value for RADIUS-assigned IP addresses * Feature #12086: New Dynamic DNS Provider: deSEC * Feature #12094: Suppress kernel messages for ``lo0`` configuration during boot * Feature #12096: Refactor DNS forwarder (dnsmasq) for MVC * Regression #12100: Recent 2.6.0 development installers don't actually install * Bug #12102: Prevent using OpenVPN "Exit Notify" option with point-to-point modes * Bug #12107: Notifications page cannot be saved without configuring or disabling SMTP * Feature #12109: Option to suppress expiration notifications for revoked certificates * Regression #12110: PHP error in firewall_nat.inc on line 329 * Regression #12111: Crash report message displayed on dashboard. flock() expects parameter 1 to be resource, null given in /etc/inc/util.inc on line 166 * Feature #12116: Support DNS server gateway selection on ``system.php`` for multiple gateways not assigned to interfaces * Feature #12118: Create a log entry when a configuration change occurs * Bug #12124: Creating or editing aliases fails with multiple hosts separated by spaces * Bug #12134: Typo in crash reporter page * Bug #12138: Clicking "logout" on portal page does not function when logout popup is disabled * Todo #12145: Convert RAM disks to ``tmpfs`` * Bug #12151: ``easyrule`` script does not function properly * Bug #12155: Tunnels with conflicting REQID values can lead to multiple identical Child SA entries * Bug #12159: "Default preferred lifetime" router advertisement validation check uses incorrect variable * Bug #12164: IPv6 policy routing does not work if an IPsec tunnel phase 2 remote network is configured for ``::/0`` * Bug #12168: 1:1 NAT rule with internal IP address of "Any" results in an invalid firewall rule * Feature #12169: IPsec keep alive option to initiate phase 2 without using ICMP * Bug #12170: Interface assignment mismatch is not detected if VLAN-only parent interface is removed * Todo #12171: Upgrade to ``pkg`` 1.17.x * Regression #12172: OpenVPN Wizard configuration missing recently added default values * Feature #12184: GUI options to configure IKE retransmission behavior * Bug #12173: IPv6 RA DNSSL lifetime is too short, not compliant with RFC 8106 * Bug #12174: Firewall rule tabs load slowly when many rules on the tab utilize gateways * Bug #12177: When attempting to delete an in-use alias, input validation only prints the first item using the alias in the error message * Feature #12181: Add connect/disconnect buttons to IPsec dashboard widget * Regression #12186:
tags shown in Status>IPsec * Bug #12189: IPsec status shows connect buttons while tunnel is connecting * Bug #12191: File overwrite in ``services_ntpd_gps.php`` via ``gpsport`` parameter * Bug #12192: OpenVPN does not clean up previous CA and CRL files * Feature #12193: AutoConfigBackup performance improvements * Bug #12196: IPsec settings fail to apply when a remote gateway is set to an FQDN and there are no DNS servers available * Bug #12197: Mobile IPsec phase 1 should not display "Gateway duplicates" option * Bug #12198: Disabling an IPsec phase 1 entry does not disable related phase 2 entries * Bug #12202: When a CARP VIP VHID change is synchronized to a secondary node, the CARP VIP is removed from the interface and the old VHIDs remain active * Bug #12212: Disabled IPsec VTI interfaces are always created * Feature #12213: Support SHA-256 hash NTP authentication * Bug #12216: ARM 32/64 network boot options are not parsed on Static DHCP Mapping page * Regression #12217: Kernel panic in IPFW when using Captive Portal * Todo #12218: Move "Description" option on OpenVPN server and client pages to top of the page, show internal instance ID * Bug #12219: Prevent using OpenVPN "Inactive" option with point-to-point modes * Feature #12222: OpenVPN with LDAP active directory auth with Two factor authentication * Bug #12223: Configuration files are not deleted after disabling an OpenVPN instance * Bug #12224: OpenVPN page allows to delete/disable instance with an assigned interface * Bug #12227: Changing VHID on CARP VIP does not update VHID of related IP Alias VIPs * Regression #12228: States table content in GUI is corrupted/invalid on snapshots * Regression #12229: Revision 0d3747aa - missing semicolons * Bug #12232: OpenVPN status incorrect for TAP servers without a defined tunnel network * Regression #12233: VIP network addresses are not expanded on Port Forward rules * Regression #12234: Wireless Channel/Width Issues with GUI * Todo #12235: ``pfSense-upgrade`` should reinstall all packages on new version upgrades * Bug #12236: IPsec bypass rules display help text under each entry * Bug #12238: OpenVPN client connect/disconnect scripts are not used in Remote Access (SSL/TLS) mode * Regression #12239: Interfaces page does not show Wireless EAP client options * Bug #12241: System Information widget unnecessarily polls data for hidden items * Regression #12245: Input validation error in system.php * Bug #12247: Viewing an AutoConfigBackup entry takes approximately 60 seconds to completely load * Bug #12252: IPv6 DNS servers from dynamic sources are not listed on ``status_interfaces.php`` * Bug #12253: IPv6 gateway for an interface is not shown on ``status_interfaces.php`` if the interface does not also have an IPv4 gateway * Bug #12256: Sanitize WireGuard private and pre-shared keys in status output * Bug #12257: Route data collection method on ``diag_routes.php`` has multiple issues * Bug #12262: IPsec phase 1 entry with ``0.0.0.0`` as its remote gateway does not receive correct automatic firewall rules * Todo #12265: Improve uses of ``grep`` which utilize user-supplied patterns * Feature #12269: Include firewall rules from packages which failed to load in status output * Bug #12272: Duplicating a Port Forward does not copy "Filter Rule Association" values of "None" or "Pass" * Bug #12274: Unbound fails to start if its configuration references a python script which does not exist * Bug #12277: DHCPv6 Server should not offer configuration options for unsupported PPPoE Server interfaces * Regression #12279: Uninitialized config array and escaped html in ipsec widget * Bug #12280: Default IPv6 router advertisement intervals and lifetime are too low * Bug #12282: Default IPv4 gateway may be set to IPv6 gateway value in certain cases * Bug #12298: IPsec manual initiation and termination should use a timeout value or forced actions * Regression #12287: State table entry rule ID does not contain the expected value * Regression #12288: GRE and GIF tunnel inside addresses are missing at the OS level after applying changes on assigned interfaces * Todo #12289: Update "IPsec Filter Mode" option values and help text to reflect that VTI mode also helps transport mode (e.g. GRE) * Feature #12290: Add ``librdkafka`` package to the pfSense package repository * Feature #12291: Support for Slack notifications * Todo #12296: Explicitly state where AutoConfigBackup stores encrypted backup data * Todo #12299: Update default ``config.xml`` * Regression #12306: Certificate info block has CA info, not certificate info * Bug #12307: Update cURL to address vulnerabilities in 7.76.1 in CE * Todo #12314: Convert help shortcut links to server-side redirects * Bug #12315: IPsec tunnels using a gateway group do not get reloaded in some cases * Feature #12316: Include firewall rules generated from OpenVPN RADIUS ACL entries in status output * Feature #12318: Display default "Reflection Timeout" value on ``system_advanced_firewall.php`` * Feature #12321: Pop-up window to view firewall rules generated from RADIUS ACL entries on the OpenVPN status page * Bug #12323: IPsec Phase 2 entry incorrectly orders proposals in AH mode * Regression #12324: Hash algorithm GUI options are disabled after switching a phase 2 entry to AH mode * Feature #12325: IPv6 support for base system SNMP service * Bug #12328: IPsec VTI interface remote endpoint is not resolved the correct way * Bug #12331: Yandex Dynamic DNS client does not set the ``PddToken`` value * Regression #12333: DNS resolver using incorrect variable name when making ACL for OpenVPN IPv6 Tunnel Network * Regression #12337: IPsec widget generates errors if no tunnels are defined * Regression #12340: Factory Reset Menu Broken in webConfigurator * Feature #12342: Dynamic DNS client proxy support * Regression #12345: Captive Portal users cannot get past portal even after successfully logging in * Bug #12346: Deny SSH access for ``admin`` and ``root`` users when the ``admin`` GUI account is disabled * Bug #12347: IPsec widget treats phase 1 in "connecting" state as connected * Feature #12349: Disks dashboard widget to replace Disk Usage section of System Information widget * Bug #12350: Incorrect label for IPsec DH group 32 * Bug #12352: Update Dynamic DNS code for one.com to use their new login process * Bug #12355: Captive Portal database and ``ipfw`` rules are out of sync after unclean shutdown * Bug #12356: Validation when deleting a VIP does not check if the VIP is used by IPsec phase 1 entries * Bug #12361: NAT rule overlap detection does not check special networks * Bug #12362: Validation when deleting a VIP does not prevent deleting a CARP VIP used as a parent for an IP Aliases VIP * Bug #12366: Rotation settings for individual log files do not take effect after saving * Bug #12368: Disk widget alignment issue when only two items are in the list * Bug #12371: Remove subnet overlap check on LAN interfaces when using 6rd * Bug #12373: Update mpd5 to address vulnerabilities in < 5.9_2 * Bug #12374: Update python to address vulnerabilities < 3.8.12 * Regression #12377: NAT Rule Reorder * Bug #12383: Typos in interfaces_assign.php configuration change description strings * Bug #12388: Captive Portal input validation for "After authentication Redirection URL" and "Blocked MAC address redirect URL" is swapped * Bug #12389: Help text for RAM disk settings does not mention Captive Portal data * Bug #12391: Uninitialized config variable in ```interface_assign.php``` * Regression #12396: PHP Warning: Use of undefined constant ip - /etc/inc/services.inc on line 2465 * Feature #12397: Distinguish between policy-based and route-based entries on IPsec status SPD tab * Regression #12398: "Expiration and Replacement" section is shown twice when editing a mobile IPsec phase 2 entry * Todo #12406: Remove unused functions * Bug #12408: Input validation prevents creating 1:1 NAT rules on OpenVPN * Bug #12410: 1:1 NAT edit page lists incorrect entries in the Destination field * Feature #12416: Support OpenVPN ``client-kill`` to terminate remote clients instead of clearing their session * Bug #12419: Console boot output includes ``Configuring IPsec VTI interfaces`` when no VTI interfaces are configured * Todo #12430: Add IPsec phase 2 BINAT subnet size input validation * Feature #12433: Icon for traffic direction on floating rules tab * Bug #12434: Multiple cURL Vulnerabilities * Bug #12435: "6RD Prefix" field does not have input validation * Feature #12438: Option to select PPPoE Server authentication protocol * Bug #12439: "Default preferred lifetime" field for IPv6 RA does not have input validation * Feature #12441: Send notification for halt, reboot, and reroot events * Regression #12442: Unexpected error message after trying to delete a CARP VIP * Todo #12449: Update "DNS Server Override" and "DNS Query Forwarding" help text * Bug #12452: Port forward rules are not created for special networks (pppoe, openvpn) * Todo #12454: Suppress kernel messages when loading ``dummynet`` and thermal sensor modules * Bug #12455: Captive Portal online user statistics data is not cleared on unclean shutdown * Bug #12460: Unbound falls back to using all outgoing network interfaces if manually selected outgoing interface(s) are unavailable * Bug #12470: Thermal Sensors Dashboard widget filter for negative values refers to invalid variable * Bug #12472: IPsec Keep Alive does not work correctly with gateway groups in HA * Feature #12480: Wake on LAN button to wake all devices * Bug #12498: Input validation error can unintentionally result in removal of PPP type interface settings * Feature #12499: Allow Chelsio T6 CXGBE (``cc``) drivers to be used for ALTQ traffic shaping * Bug #12500: Automatic outbound NAT for reflection does not support IPv6 * Todo #12501: Traffic shaper wizard default bandwidth type should be Mbit/s * Bug #12503: Unable to delete limiter referenced in filter rules * Todo #12511: Add note in log settings that disabling logging also disables ``sshguard`` login protection * Bug #12514: Trying to delete an assigned PPPoE interface fails without printing an error message * Bug #12515: Missing input validation check for 6RD Tunnel IPv6 Configuration Type setup * Regression #12517: pfSense-rc console errors on old zfs scheme (zroot) * Feature #12518: Restore RRD and extra data from configuration backups when restoring during installation * Bug #12529: Interface group name starting with a digit creates invalid XML for rule separators * Bug #12548: Kernel panic in ``nd6_dad_timer()`` * Regression #12550: PHP ``foreach`` error in IPsec status * Bug #12554: Route overlap input validation does not work properly * Feature #12555: Change Gateway/Group name in firewall rule list to clickable link to edit page for the entry * Regression #12559: Firewall rule direction indicator is displayed on all interfaces * Bug #12566: IPsec initiates on HA backup node when a tunnel interface is set to a gateway group * Bug #12572: Log entries from ``acbupload.php`` are missing the upload URL * Bug #12575: IPsec Mobile Client RADIUS Advanced parameters are not reset to default values when disabled * Bug #12584: ``rc.carpmaster`` only sends notifications via SMTP * Bug #12585: ``rc.notify_message`` only sends notifications via SMTP * Bug #12588: Automatic rule tracker IDs incorrect after multiple filter reloads * Bug #12589: Dynamic DNS updates do not respect certificate authority trust store * Bug #12604: IPv6 interface prefix change not reflected in RADVD configuration * Regression #12605: ``diag_dump_states.php`` no longer filters by rule ID * Bug #12614: Pushover notifications fail * Regression #12615: MAC passthrough does not work on the latest snapshot * Regression #12617: Dynamic DNS client updates using a private IP address when it cannot determine the public IP address * Bug #12621: Fix rare case where /getstats.php might be called without valid post data. * Bug #12654: Nat issue after 20211220 version * Bug #12626: Router Advertisement DNS search domain from one interface may unintentionally be used by other interfaces * Regression #12631: Dynamic DNS may not use the correct interface when updating during failover * Bug #12635: PHP: Error generated when backing up a config file with SSH disabled * Bug #12637: Incorrect SSH key permission after restore * Regression #12660: High CPU usage due to incorrect gateway on some policy routed states * Regression #12666: Default password warning is not displayed for new installs * Bug #12677: OpenVPN form validation issues * Bug #12686: Incorrect copyright year * Bug #12694: PHP error when clicking Delete on Outbound NAT with no rules selected * Regression #12698: ARP table interface column empty for entries on unassigned interfaces * Regression #12699: ldap_get_groups() must return an array value * Regression #12707: Minnowboard Turbo cannot boot a clean install * Bug #12713: PHP error on ``pkg_mgr_install.php`` when multiple instances are running * Bug #12725: Potential XSS in ``pkg.php`` via ``pkg_filter`` * Regression #12745: AutoConfigBackup does not delete temporary encrypted configuration files from ``/tmp`` * Bug #12769: ZFS installations without an RTC battery boot with clock at BIOS/EFI default value because they do not receive initial clock value from filesystem data * Regression #12622: Kernel panic when using ``fq_pie`` limiter scheduler * Feature #11957: XMLRPC synchronization for DHCP relay settings * Bug #11173: Status>Monitoring parameters are hidden by the interactive graph * Bug #12074: Freeradius: Additional Information field descriptions swapped * Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset * Todo #12456: Remove zabbix 5.2 packages