# 2.5.2 Maintenance/bug fix release of pfSense software (CE) * Feature #2400: GUI options for WPA Enterprise with identity/password * Bug #5135: DHCP interfaces are always treated as having a gateway, even if one is not assigned by the upstream DHCP server * Feature #7092: Kernel modules for alternate congestion control algorithms * Feature #7842: New Dynamic DNS Provider: Mythic-Beasts * Bug #10956: Panic configuring LAGG+VLAN interfaces when using a kernel with ``INVARIANTS``. * Feature #10811: Randomize time of scheduled AutoConfigBackup runs * Bug #11387: Interfaces page displays MAC Address field for interfaces which do not support L2 * Bug #11082: XMLRPC synchronization restarts all OpenVPN instances on the secondary node when making any change on the primary node * Feature #11103: Use virtual link local IP address as RA source address for HA environments * Feature #11125: Kernel module for RTL8153 driver * Feature #11140: Allow the firewall to use DNS servers provided to an OpenVPN client instance * Bug #11141: OpenVPN Wizard does not support gateway groups * Feature #11164: Input validation to prevent setting a load balancing gateway group as default * Feature #11211: GUI option to set RADIUS Timeout for EAP-RADIUS * Feature #11228: Replace HTTP links with HTTPS in the GUI * Bug #11229: Harmless error when enabling traffic shaper * Feature #11264: Redirect Captive Portal users to login page after they logout * Bug #11299: Unused L2TP VPN files are not removed when the service is disabled * Feature #11293: New Dynamic DNS Provider: one.com * Feature #11294: New Dynamic DNS Provider: Yandex PDD * Feature #11358: New Dynamic DNS Provider: NIC.RU * Feature #11380: PHP shell playback script to modify Alias contents * Feature #11390: Copy button for Authentication Server entries * Feature #11402: Xen console support * Feature #11395: Option to switch IPsec filtering modes to choose between ``enc`` and ``if_ipsec`` filtering * Feature #11406: GUI option to set MTU for L2TP VPN server * Feature #11420: New Dynamic DNS Provider: Gandi LiveDNS IPv6 * Todo #11426: Deprecate old cryptographic accelerator hardware which is not viable on modern systems * Bug #11453: ``wpa_supplicant`` uses 100% of a CPU core at boot * Bug #11456: Unbound Python Integration repeatedly mounts ``dev`` without unmounting * Regression #11495: NTP widget displays incorrect status * Regression #11510: ARP Table populates hostname values using expired DHCP lease data * Todo #11518: Move custom IPsec NAT-T port settings to Advanced Options * Feature #11521: Set Explicit Exit Notify to ``1`` by default for new OpenVPN client instances * Regression #11524: Using SHA1 or SHA256 with AES-NI may fail if AES-NI attempts to accelerate hashing * Regression #11550: Segmentation fault when loading ALTQ traffic shaping rules using FAIRQ * Regression #11564: strongSwan configuration always contains user EAP/PSK values * Feature #11576: IPsec GUI option to control Child SA ``start_action`` * Feature #11596: Support for Cisco AVPair ``{clientipv6}`` template in firewall rules returns by RADIUS * Bug #11609: CLI interface configuration without IPv6 leaves RA enabled * Bug #11636: Unused Limiter entries with schedules create unnecessary cron jobs * Bug #11651: Error when adding both IPv4 and IPv6 P2 under an IPv4 or IPv6 only IKEv1 P1 * Bug #11658: Ambiguous text in help and input validation error for system domain name * Bug #11667: Automatic 25-day forced Dynamic DNS update removes wildcard domain * Bug #11678: Certificate Manager does not report Unbound as using a certificate * Todo #11684: Set ``explicit-exit-notify`` option by default for new OpenVPN server instances * Bug #11685: PHP error if ``PHP_error.log`` file is too large * Bug #11688: Disabling all interfaces associated with a floating rule causes the firewall to generate an incorrect pf rule * Bug #11698: Incomplete PPPoE custom reset values lead to invalid cron entry * Bug #11699: OpenVPN does not clean up parsed ``Cisco-AVPair`` rules on non-graceful disconnect * Bug #11700: OpenVPN does not kill IPv6 client states on disconnect * Regression #11702: RAM Disk Settings shows Kernel Memory at ``0`` Kb and does not allow the user to create RAM disks * Bug #11704: Stale hostname registration data for OpenVPN clients is not deleted from the DNS Resolver configuration at boot * Bug #11718: XMLRPC Client does not honor its default timeout value * Regression #11723: Virtual IP addresses are only added to interfaces after reboot * Bug #11725: Error when setting queue limit on CODELQ limiter * Bug #11748: Automated corruption recovery from cached ``config.xml`` backup files should check multiple backups * Regression #11751: Input validation prevents creating 1:1 NAT rules on IPsec * Bug #11754: Digital Ocean Dynamic DNS help text is incorrect * Bug #11762: Invalid combinations of TCP flag matching options cause ``pfctl`` parser error * Bug #11765: Invalid HTML encoding in modal Notices window * Bug #11767: Sanitize OpenVPN Client Export certificate password in status output * Regression #11819: MAC address OEM information missing from ARP table * Bug #11769: Sanitize Captive Portal RADIUS MAC secret in status output * Regression #11775: State counters not updating and always show 0/0 since last few updates * Bug #11781: Disable DNSSEC option for dnsmasq * Regression #11787: Thermal sensors widget no longer shows values from certain hardware * Bug #11792: Cannot disable IPsec P1 when related P2s are in VTI mode and enabled * Bug #11793: OpenVPN client starts when CARP VIP is in BACKUP status when bound to Virtual IP aliased to CARP VIP * Regression #11794: IPsec VTI interface names are not properly formed for more than 32 interfaces * Regression #11795: Applying IPsec settings for more than ~30 tunnels times out PHP * Bug #11801: PHP error in ``upgrade_212_to_213()`` when upgrading certain IPsec tunnels * Regression #11805: Port forward rules only function through the default gateway interface, ``reply-to`` does not work for Multi-WAN (CE Only) * Regression #11806: IPv4 link-local (``169.254.x.x``) gateway does not function * Bug #11808: Ignore WireGuard configurations under ```` * Bug #11815: NoIP.com Dynamic DNS update failure is not detected properly * Bug #11821: Upgrade libcurl to version 7.76.0 * Bug #11830: Certificate validation with OCSP always fails in ``openvpn.tls-verify.php`` * Bug #11832: ``ipsec_vti()`` does not skip disabled VTI entries * Regression #11839: Panic on 21.05/2.6.0 snapshots when memory usage is high * Bug #11842: Captive Portal post-auth redirect is not properly respected * Todo #11844: Update OpenVPN to 2.5.2 * Bug #11850: NTP authentication input validation rejects valid keys * Bug #11852: State table content on ``diag_dump_states.php`` does not sort properly * Bug #11855: Error when changing MTU if the interface is used for both IPv4 and IPv6 default routes * Regression #11857: Match rules cause pf error parsing rules * Bug #11859: PHP error on certificate list due to unreadable private key * Bug #11861: Error loading rules in certain cases where an interface is temporarily without an address * Bug #11866: Update dnsmasq to 2.85 to fix CVE-2021-3448 * Bug #11867: Unquoted variable in ``dot.tcshrc`` can cause proxy password to be printed * Regression #11868: PHP error from missing ';' in util.inc line 2036 * Bug #11869: OpenVPN client startup error if IPv6 Tunnel Network is defined in TAP mode * Bug #11873: HTTP Referer error message text is incorrect * Bug #11880: Missing ``/0`` subnet when cloning repeatable CIDR mask controls * Bug #11883: ``dhcp6withoutra_script.sh`` does not get executed when advanced options are set * Regression #11884: Export P12 icon is missing if certificate is not locally renewable * Bug #11893: IPsec Dashboard widget only displays first P2 subnet when using a single traffic selector * Bug #11897: Language presented to user during upgrade is misleading * Regression #11986: Static routes may not be in routing table when expected * Bug #11904: IGMP Proxy restarts unnecessarily after IPv6 gateway events * Feature #11911: Shortcut buttons for service control and logs on RADVD configuration * Bug #11912: IPsec GUI allows creating multiple identical Phase 1 entries when using FQDN for remote gateway * Bug #11913: RADVD breaks on SIGHUP * Todo #11914: Allow reroot on ZFS from console and GUI reboot menu entries * Todo #11915: Temporarily move back to Unbound 1.12.x due to instability on Unbound 1.13.x * Bug #11923: Input validation not working for 1:1 NAT entries using an alias as a destination * Bug #11939: Editing widgets on Dashboard causes a PHP Warning * Todo #11943: Add FRR package documentation links * Regression #11945: Incorrect VTI interface creation * Bug #11946: Custom value for AutoConfigBackup schedule Hours is not shown when loading the settings page * Regression #11952: Traffic matching rules with limiters is not handled by DUMMYNET * Bug #11966: Incorrect RADVD log message on HA event * Bug #11967: Mobile IPsec advanced RADIUS parameters do not allow numeric values with a decimal point * Feature #11968: VLAN list sorting * Regression #11981: Duplicating Outbound NAT rule does not carry over contents of the source rule * Regression #11982: Outbound NAT does not create automatic equivalent rules when switching from Automatic to Manual mode * Regression #11994: Firewall rule usage counters showing 0/0 after latest pf merge * Regression #12005: ``Recover config.xml`` installer option does not work after default ZFS pool name change * Regression #12017: FreeBSD-SA-21:12.libradius breaks mpd5 when using MS-CHAPv2 * Regression #12024: State table data in GUI does not show the expected interface after latest pf merge * Regression #12037: Built-in SNMP daemon does not return values for BEGEMOT-PF-MIB::pfLabels on latest build * Regression #12040: Scheduled firewall rules failing to load * Regression #12045: High CPU usage and slowness with ``pfctl -ss`` * Bug #12061: Update NGINX to address CVE-2021-23017 * Feature #6626: Support for IPv6 firewall entries with dynamic delegated prefix and static host address * Bug #12031: Wireguard Package Produces Crash in 2.5.2 * Bug #12085: OpenVM Tools vmware-kmod service won't start in 2.5.2 RC on ESXi 6.0