# 2.5.1 2.5.x Maintenance release * Bug #3709: Disabled static route entries trigger 'route delete' error at boot * Bug #4521: OpenVPN authentication and certificate validation fail due to size of data passed through ``fcgicli`` * Feature #7077: Display negotiated data encryption algorithm in OpenVPN connection status * Bug #11624: Typo on Router Advertisements page * Bug #11104: OpenVPN does not start with several authentication sources selected * Bug #11105: IPv6 RA RDNSS lifetime is too short, not compliant with RFC 8106 * Bug #11382: OpenVPN client configuration page displays Shared Key option when set for SSL/TLS * Bug #11383: pfSense Proxy Authentication not working * Bug #11403: DNS Resolver does not add a ``local-zone`` type for ``ip6.arpa`` domain override * Bug #11409: IPv4 MSS value is incorrectly applied to IPv6 packets * Bug #11425: XMLRPC error with Captive Portal and CARP failover when GUI is on non-standard port * Bug #11428: CPU details are incorrect in the System Information widget after resetting log files * Regression #11433: Gateways with "Use non-local gateway" set are not added to routing table * Regression #11435: IPsec status incorrect for entries using expanded IKE connection numbers * Regression #11442: Distinguished Name (FQDN) IPsec peer identifier type is not formatted properly in ``swanctl.conf`` secrets * Regression #11443: Disabling 'State Table Size' in the System Information widget prevents other data from being displayed * Bug #11446: Mobile IPsec DNS server input validation does not reject unsupported IPv4-mapped IPv6 addresses * Bug #11448: Incorrect order of ``route-nopull`` option in OpenVPN client-specific override configuration * Bug #11454: Gateway value for DHCP6 interfaces missing after RA events triggered script without gateway information * Bug #11464: Requests to ``ews.netgate.com`` do not honor proxy configuration * Bug #11474: Broken help link on IPsec Advanced Settings tab * Regression #11475: Route tables with many entries can lead to PHP errors and timeouts when looking up routes * Bug #11476: Telegram and Pushover notification API calls do not respect proxy configuration * Bug #11483: Installer does not add required module to loader.conf when using ZFS * Regression #11486: Connect and disconnect buttons on the IPsec status page do not work for all tunnels * Regression #11487: IPsec tunnels using expanded IKE connection numbers do not have proper child SA names in ``swanctl.conf`` * Bug #11488: IPsec tunnel definitions have ``pools =`` entry in ``swanctl.conf`` with no value * Bug #11489: Invalid certificate data can cause a PHP error * Regression #11500: OpenVPN using the wrong OpenSSL command to list digest algorithms * Bug #11514: Renewing a self-signed CA or certificate does not update the serial number * Regression #11519: Incorrect DHCP failover IP address configured on peer after XMLRPC sync * Regression #11526: Mobile IPsec broken when using strict certificate revocation list checking * Regression #11537: IPsec VTI tunnel between IPv6 peers may not configure correctly * Bug #11547: DNS Resolver does not bind to an interface when it recovers from a down state * Bug #11554: Selected Data Encryption Algorithms list items reset when an input validation error occurs * Regression #11555: IPsec peer ID of "Any" does not generate a proper remote definition or related secrets * Bug #11559: OpenVPN does not start with a long list of Data Encryption Algorithms * Regression #11561: ACLs generated from RADIUS reply attributes do not parse ``{clientip}`` macro * Regression #11565: Saved state timeout values not loaded into GUI fields on system_advanced_firewall.php * Regression #11568: Alias name change is not reflected in firewall rules * Bug #11569: ACLs generated from RADIUS reply attributes have incorrect syntax * Bug #11578: Error when removing automatic DNS server route * Regression #11594: IPv6 routes with a prefix length of 128 result in an invalid route table entry * Bug #11602: Delayed packet transmission in cxgbe driver can lead to latency and reduced performance * Bug #11616: Potential stored XSS vulnerability in services_wol.php * Bug #11617: Unexpected Operator error on console at boot with ZFS and RAM Disks * Regression #11633: DHCP6 interfaces are reconfigured multiple times at boot when more than one interface is set to Track * Bug #11638: PHP error in logs from XMLRPC if no sections are selected to sync * Bug #11639: Entries from rotated log files may be displayed out of order when log display includes contents from multiple files * Bug #11643: IPsec tunnel does not function when configured on a 6RD interface * Bug #11644: Unreachable LDAP server for SSH auth causes boot process to stop at 'Synchronizing user settings' and no user can login over SSH * Bug #11652: Unable to renew a certificate without a SAN * Bug #11654: Certificates with escaped x509 characters display the escaped version when renewing * Bug #11674: OpenVPN binds to all interfaces when configured on a 6RD interface * Bug #11705: Creating a certificate while creating a user does not fully configure the certificate properly * Bug #11706: Renewing a certificate without a ``type`` value assumes a server certificate * Regression #11710: PHP error when resetting log files * Bug #11713: Error when deleting IPv6 link-local routes * Regression #11729: Automatic default gateway mode does not select expected entries * Regression #11747: Firewall rule schedule cannot be changed * Todo #11755: Upgrade OpenSSL to 1.1.1k * Regression #11760: PHP error on package install * Regression #11785: OpenSSL "Operation not supported" error with cryptodev in certain cases