# 2.7.0 pfSense CE software release featuring a FreeBSD 14 base OS, PHP 8.x, plus many other features and fixes * Feature #2456: Option to choose default tab in IPsec status Dashboard widget * Feature #2505: Toggle button to disable/enable multiple firewall rules * Feature #4259: Port forward NAT rules with "any" protocol * Todo #14209: Update Time Zone data to 2023c or later * Bug #4500: UPnP/NAT-PMP status page does not display all port mappings * Feature #4881: Allow NPt to use dynamic IPv6 networks * Bug #6253: Firewall log widget action icon features stop working when new log entries are added dynamically * Bug #6880: Multiple DHCP6 WAN connections leads to multiple dhcp6c clients * Bug #7996: Unnecessary link tag in login page * Feature #8365: Button to copy rules from one interface to another * Feature #12752: Support wildcard Dynamic DNS records on DigitalOcean * Feature #9091: Chelsio TOE support using the ``t4_tom`` module * Bug #9263: Incorrect ICMP reply when using limiters * Feature #9393: Improved support for USB interfaces that may not always be present * Feature #9544: Enable ``ROUTE_MPATH`` multipath routing * Bug #9887: Rule separator positions change when deleting multiple rules * Feature #10345: Improve distinction between online and idle/offline entries in DHCP lease list * Bug #10624: Memory leak in Unbound with Python module and DHCP lease registration active * Bug #11226: IPsec VTI phase 2 traffic selectors default to address when defined as a network * Feature #11266: Option to list AutoConfigBackup entries in "reverse" order (newest at top) * Regression #11316: Unbound crashes with signal 11 when reloading * Bug #11416: OpenVPN IPv4 Tunnel Network incorrectly allows hostnames * Bug #11629: PPPoE WAN IP address different than expected when set static by ISP * Bug #11692: ``fixup_default_gateway()`` should not remove a default gateway managed by a dynamic routing daemon * Bug #12896: ``HTTPClient`` option does not work for static mappings * Bug #11730: "Dark" theme does not sufficiently distinguish between selected and deselected elements in option lists * Bug #11764: IPv6 link local gateway default status not indicated in GUI * Bug #11864: OpenVPN stays bound to previous IP address after interface changes * Bug #11877: Labels and description disappear in firewall_schedule_edit.php * Bug #11941: Many ``exec()`` functions do not use full path to executable files * Bug #11984: Automatic Outbound NAT mode can create incorrect rules in some cases * Feature #12070: Support for VLAN ``0`` * Feature #12092: Utilize new ``pfctl`` abilities to kill states * Todo #12093: Make AutoConfigBackup menu entry point to the settings tab so it loads faster when there is no WAN connectivity * Bug #12105: Packages are not automatically reinstalled when restoring configuration using the installer * Bug #12527: DHCPv6 server does not skip interfaces configured with invalid ranges * Bug #12141: Lack of DNS or Internet connectivity causes GUI to be slow * Feature #12267: OpenVPN option to limit concurrent connections per user * Bug #12319: NAT reflection does not work for IPv6 port forwarding rules when configured for NAT+Proxy mode * Bug #12332: OpenVPN does not clear old Cisco-AVPair anchor rules in some cases * Feature #12392: Allow the selection of "any" interface in floating rules * Feature #12407: Use deferred client connections in OpenVPN * Bug #12440: Zero-value prefix IPv6 addresses are mishandled * Feature #12464: Option to control log level of authentication messages in system logs ("Emergency" vs "Notice" level) * Bug #12536: Setting a default gateway of "None" does not remove the default gateway from the routing table * Todo #12556: Comply with current iteration standards when encrypting and decrypting configuration files * Bug #12579: Utilize ``dnctl(8)`` to apply limiter changes without a filter reload * Regression #12582: RADVD can be started on both HA nodes when configured with an IPv6 link-local address * Bug #12651: ``nginx`` logs an error that the port is already in use when restarting Captive Portal services * Bug #12590: Dynamic DNS custom IPv6 service fails on 6rd tunnels * Bug #12606: ``devd`` is not configured to act on USB interface attach/detach events * Bug #12609: IGMP Proxy server is restarted during every ``rc.newwanip`` event * Bug #12611: SNMP daemon is restarted during every ``rc.newwanip`` event * Bug #12613: DNS Resolver does not restart during link up/down events on a static IP address interface * Feature #12616: Option to filter state table contents by rule ID * Todo #12619: Restart services on interface changes * Todo #12624: Reorganize UPnP options * Bug #12628: OpenVPN re-synchronization also synchronizes override entries unnecessarily in some cases * Bug #12632: Changing an interface IP address and gateway at the console does not save the new gateway if one already exists for the interface * Bug #12633: Gateway monitoring should mark gateway as "offline" on PPPoE parent interface disconnect * Feature #12636: Automatically create DNS Resolver ACLs for OpenVPN CSO entries * Bug #12645: ``filterdns`` does not monitor remote IPsec gateways for IPv6 address changes * Bug #12649: Allowed IP/Hostname "Direction" option is never used * Regression #12688: pppoe won’t connect after upgrade to 2.7.0.a.20220115.0600 * Bug #12672: GleSYS Dynamic DNS responses are not parsed properly * Feature #12675: Move command line history to a GUI option stored in ``config.xml`` rather than a manual flag file * Bug #12678: Applying firewall rule changes does not clear dirty flag for aliases subsystem * Bug #12680: Typo in the warning text * Feature #12685: Support encrypted ``config.xml`` files when restoring via ECL * Feature #12687: Option to disable auto-addition of static routes for ``dpinger`` * Bug #12691: Support encrypted ``config.xml`` files when restoring during install * Todo #12701: Reorganize CARP status page * Feature #12702: Use consistent pf host ID and add GUI option to set a custom host ID in state synchronization settings * Bug #12703: pf ``hostid`` value is handled inconsistently * Bug #12710: Disabling DHCP Server RRD statistics does not work * Feature #12714: Show ``Inactive`` for Hardware Crypto output instead of empty field on System Information dashboard widget when nothing can be accelerated * Bug #12721: IPv6 gateway group using link local addresses incorrectly logs a gateway change because it not including interface scope properly * Bug #12723: Disallow remote gateway of ``0.0.0.0`` for VTI mode * Bug #12727: Renaming an alias does not update the alias names in static routes and OpenVPN instances * Bug #12728: Cannot remove IPv6 static routes * Bug #12749: Uninitialized array in ``array_remove_duplicates()`` * Bug #12750: Input validation prevents configuring wildcard Dynamic DNS records on GoDaddy * Bug #12733: Value of ``net.inet.ip.dummynet.*`` OIDs in ``sysctl`` are ignored * Bug #12735: Interface status "Total Interrupts" display is non-functional * Bug #12737: CA path is not defined when using ``curl`` in the shell * Feature #12741: Eliminate duplicate shell commands from history file * Feature #12744: IPv6 support for DNSimple Dynamic DNS * Bug #12754: Google Domains Dynamic DNS responses are not parsed properly * Bug #12757: Clean up use of ``pfctl -F`` in ``/etc/inc/filter.inc`` * Bug #12761: Input validation prevents configuring wildcard Dynamic DNS records on Google Domains * Bug #12763: VTI gateway status stuck as "pending" after reboot * Bug #12766: Packages with custom ``internal_name`` values do not reinstall properly when restoring a backup * Bug #12771: Automatic filter reload with OpenVPN client gateway uplink happens too soon or not at all * Feature #12773: Ability to sort AutoConfigBackup entries * Bug #12775: NTP service is not listed on ``status_services.php`` unless ``config.xml`` contains NTP configuration data * Bug #12780: L2TP/PPTP interface assignment page loses some values after input validation error * Bug #12781: DNS Resolver help text for **System Domain Local Zone Type** option refers users to ``unbound.conf(5)`` man page instead of pfSense docs * Todo #12782: Disable ``pkg`` compatibility flag which creates ``txz`` file extension symbolic links * Bug #12790: Link-Local IPv6 address on WAN with MAC spoofing changes if there is an IP Alias on WAN * Bug #12792: Automatic Outbound NAT rules do not include OpenVPN CSO entries * Bug #12794: Link-local address does not reset after removing MAC address spoofing * Bug #12801: User password hashes pseudo-random number generator may return insecure salt value * Bug #12803: Error loading ruleset due to illegal TOS value * Feature #12809: Recover existing SSH keys during installation * Bug #12810: Sanitize SHA-512 user password hashes in ``status.php`` output * Bug #12811: Services are not restarted when PPP interfaces connect * Regression #12816: Namecheap Dynamic DNS responses are not parsed properly * Regression #12817: PHP error when terminating OpenVPN sessions via the dashboard widget * Feature #12819: GUI option to configure layers for LACP hash * Bug #12824: Firewall Alias not working as intended - Stack Trace (2.6.0) * Regression #12827: High latency and packet loss during a filter reload * Bug #12831: Typo in in /etc/inc/interfaces.inc line 1107 * Feature #12842: Retain descriptions when exporting and importing aliases * Bug #12847: On startup "No routing address with matching address" might appear * Feature #12855: GUI option to select the user password hashing algorithm * Regression #12862: Some ``sysctl`` OIDs in ``loader.conf.local`` are silently removed * Regression #12866: Disabled Captive Portal configuration prevents adding an interface to a bridge * Bug #12868: Output from ``pfctl -vvsr`` does not include ``ridentifier`` value in the expected location * Bug #12870: Clicking Save & Force Update on a Dynamic DNS entry results in a GUI timeout * Bug #12871: Some action buttons are always active for firewall rules, even if no rules are selected * Regression #12873: Hyper-V RSC support in ``hn(4)`` driver is enabled by default and results in very low throughput * Bug #12876: Changing RAM disk size does not prompt to reboot * Feature #12879: Toggle button to disable/enable multiple entries on NAT pages * Todo #12881: Update ``dpinger`` to 3.2 * Regression #12884: OpenVPN status display for TAP mode services shows peer-to-peer instead of client list in certain cases * Bug #12887: GUI does not reject an invalid OpenVPN tap mode configuration with an empty tunnel network "Bridge DHCP" disabled * Regression #12897: Attempting to decrypt an encrypted backup with the wrong password makes the GUI timeout * Bug #12900: Clicking Save & Force Update on a Dynamic DNS entry results in a GUI timeout * Bug #12901: DNS Forwarder refuses valid retries from clients in certain cases * Bug #12902: DNS Forwarder creates a loop when "Use local DNS, ignore remote DNS servers" is selected * Regression #12915: ``diag_pftop.php`` does not fully encode output * Bug #12923: DHCP "Ignore denied clients" option with MAC Deny list set causes DHCP server to not start * Bug #12925: FQDN in network alias is omitted from OpenVPN networks list * Feature #12931: Retain knowledge of previous dynamic gateway IP address when interface is down * Regression #12937: Traffic Shaper wizard can produce an invalid ruleset when configured with an IPv4 upstream SIP server * Bug #12940: Deleting a user on the primary node does not delete its home directory on secondary node during XMLRPC sync * Feature #12945: Implement missing ipfw equivalents in libpfctl necessary for captiveportal * Regression #12949: The ruleset is not regenerated after assigning an interface * Bug #12953: ESP description in IPsec phase 2 proposal help text is ambiguous * Regression #12954: Traffic routed through DUMMYNET by PF fails when IPFW is enabled * Bug #12957: Delete button is always active for NAT rules, even if no rules are selected * Bug #12960: VGA install defaults to serial as primary console when loading/saving admin GUI settings without making changes * Feature #12968: Button to clear previous packet capture data * Regression #12971: Firewall rule usage counters showing 0/0 after latest pf merge * Feature #12973: Playback script to perform a configuration upgrade on an arbitrary ``config.xml`` file * Bug #12975: IKEv2 Mobile IPsec clients do not receive ``INTERNAL_DNS_DOMAIN`` (value ``25``) attribute * Regression #12977: Rule descriptions in firewall logs show wrong rule label * Todo #12981: Warn about OpenVPN shared key deprecation * Regression #12984: OpenVPN causes Crash Reports in the GUI * Bug #12985: DNS Resolver updates trust anchor at boot even with DNSSEC disabled which can lead to a startup delay of ~2 minutes if the firewall does not have Internet access * Bug #12986: DHCP network boot filename can be incorrectly placed in DHCP Pool Options * Bug #12991: DNS Resolver ACLs are not updated when OpenVPN networks change * Bug #12998: Wireless interface WPA configuration fields are always visible * Regression #12999: Duplicate wireless interfaces are created at boot * Bug #13004: ``write_rcfile()`` does not create ``rc_restart()`` entry * Feature #13057: GUI option for IPsec ``dns-interval`` setting * Feature #13010: Option to retain the existing serial number when renewing a CA or certificate * Regression #13011: Ruleset can fail to load on snapshot from March 31st * Bug #13012: NAT Reflection generates duplicate rules when internal interface contains multiple VIPs in the same subnet * Bug #13013: bsdinstall error while creating filesystem on the latest snapshots * Bug #13471: APU1 hardware is not properly identified with current BIOS versions * Bug #13015: NAT generates duplicate ``no nat on`` rules for port forwards with a destination of ``Any`` * Feature #13023: DNS Resolver option to keep probing when servers are down * Bug #13060: Potential XSS from URL and URL Table alias URLs * Regression #13025: Some services won't start - wrong syntax in autogenerated rc.d scripts * Regression #13026: Limiters do not work * Bug #13027: Input validation requires a gateway for floating ``match out`` rules * Bug #13061: Gateway events for IPv6 affect IPv4 OpenVPN instances and vice versa * Todo #13042: Remove code references to unused ``reset`` parameter from traffic shaper pages * Regression #13059: Error when saving changes to a disabled OpenVPN client * Bug #13049: Empty ``negate_networks`` table breaks policy routing rules * Bug #13055: The ``negate_networks`` table is not updated when an OpenVPN server is deleted * Regression #13056: OpenVPN ``remote_cert_tls`` option does not behave correctly when enabled and later disabled * Regression #13064: Crash Report after saving any Interface configuration change * Bug #13066: L2TP MPD configuration is not updated when a dynamic WAN IP address changes * Bug #13067: Resolve interval for ``filterdns`` may not match the configured value * Bug #13069: Input validation for IPv6 addresses allows invalid address compression in some cases * Feature #13070: Allow auto prefix with manual prefix-length in NPt * Bug #13071: Delete function for IPsec SAD entries on ``status_ipsec_sad.php`` does not work * Bug #13076: Marking a gateway as down does not affect IPsec entries using gateway groups * Bug #13082: L2TP stays bound to previous IP address after static IP address change * Bug #13083: Slack notification options only allow ``-`` as a special character in channel names * Bug #13097: PHP error when upgrading from before configuration revision 21.6, ``ipsec_create_vtimap()`` is undefined * Bug #13086: Traffic shaper wizard rewrites Mbits to Kbits * Bug #13092: PPPoE WANs fail to reconnect after parameter negotiation failure * Feature #13094: Allow packet capture filtering in tagged packets * Bug #13099: Static routes to destinations at L2TP clients are not re-added after a client reconnects * Todo #13100: Transition Captive Portal from IPFW to PF * Feature #13103: Warn the user if they attempt to disable SSH from the menu while connected through SSH * Bug #13105: DNS Forwarder custom options may fail after save/restore when options are only separated by newline * Bug #13538: Deleting an alias marks the subsystem as unclean but also unconditionally reloads the filter configuration * Regression #13106: ``pfanchordrill`` treating errors as anchor names * Feature #13109: Trim whitespace from MAC addresses in user input * Regression #13112: PHP warning from ``unlink()`` function calls when files do not exist * Regression #13126: NAT rules are not saving properly, they are losing the `local-port` value * Bug #13116: OpenVPN client ``tls-client``/``client`` configuration directive not handled properly * Regression #13117: pfBlockerNG DNSBL unbound python mode prevents deletion of OpenVPN server and client configurations * Feature #13118: Relax DHCP maximum lease time input validation * Regression #13122: PHP error from Captive Portal status on current development snapshots * Regression #13123: PHP error from Captive Portal at boot on current development snapshots * Feature #13125: Option to restore dashboard widget layout * Bug #13127: DHCP lease list displays wrong interface name in the "Leases in Use" summary if DHCP settings for a disabled interface remain in the configuration * Todo #13129: OpenVPN status page improvements * Bug #13131: Mobile IPsec clients cannot be manually disconnected from IPsec status screen * Bug #13132: Multiple ```` or ```` sections in ``config.xml`` lead to an XML parsing error during restore * Regression #13147: Captive Portal: Idle timeout does not see activity * Bug #13133: OpenVPN ``client-connect`` file contains ``topology`` * Regression #13134: PHP error when releasing DHCP lease * Bug #13139: Stale ``sshdkeys.dirty`` lock file prevents generating SSH server keys * Regression #13142: PHP shell ``pfanchordrill`` script produces errors on captive portal tables * Bug #13145: Per-user ``route`` files are not removed from ``/tmp`` when they are no longer needed * Regression #13146: Captive Potal: Hosts remain connected after removing them from the table * Bug #13148: Traffic passed by Captive Portal cannot use limiter queues on other rules * Todo #13149: Remove unnecessary trailing colon after Outbound NAT "Automatic Rules" section header * Regression #13150: Captive Portal not applying per user bandwidths * Regression #13155: Rule labels in pftop output are not correct * Bug #13157: PHP error restoring DHCP lease data on fresh installation: * Regression #13162: Upgrade does not work when using only IPv6 DNS servers * Regression #13163: Incorrect variable in package error message results in "Array" being printed instead of package name * Bug #13164: Info icon on ``firewall_nat_out.php`` is incorrectly placed in manual outbound NAT mode * Regression #13167: DigitalOcean Dynamic DNS update fails with a "bad request" error * Bug #13169: captiveportal_ether_delete_entry() does not delete anchors/pipes * Bug #13171: Changing the redirect target for a Port Forward with an associated filter creates an incorrect firewall rule * Bug #13174: Icon missing for user manager entries with a scope other than "user" * Bug #13175: PHP error on MAC entry add/edit * Regression #13176: UPnP port mappings cause kernel panic * Regression #13178: Incorrect usage of DSCP hex value * Regression #13182: Enabling /var as a RAM disks conflicts with ZFS * Bug #13185: LDAP setup does not display 'Global Root CA List' option unless another CA also exists * Regression #13191: Deleting a passthru mac entry fails to remove pf rules and dummynet pipes associated with the passthru mac * Regression #13192: Default pipe rate limits are applied to allowed mac/ip/host entries * Regression #13193: Deleting a host entry fails to remove dummynet pipes * Regression #13203: Floating rules without an interface are not loaded * Bug #13204: Captive Portal reserves four (instead of two) pipes for client * Bug #13210: PPPoE server panics with multiple client connections * Regression #13212: Captive Portal redirect not working if HTTPS login is enabled * Bug #13216: Switching nomacfilter option does not change autorized users rule format * Bug #13225: Bridges with QinQ interfaces not properly set up at boot * Bug #13853: Captive Portal does not apply RADIUS bandwidth limits to user pipes * Bug #13228: Recovering interface gateway may not be added back into gateway groups and rules when expected * Regression #13238: WAN_DHCP6 gateway stuck pending with "Do not wait for RA" set * Bug #13240: User is forced to pick an NPt destination IPv6 prefix length even when choosing a drop-down entry which contains a defined prefix length * Bug #13243: OpenVPN status for multi-user VPN shows info icon to display RADIUS rules when there are none to display * Todo #13250: Clean up DHCP Server option language * Bug #13254: DNS resolver does not update its configuration or reload during link down events * Bug #13257: Exporting a PKCS#12 file from the certificate manager does not use the intended encryption algorithm * Bug #13258: Hidden menu option ``100`` incorrectly handles HTTPS detection * Bug #13262: File browser on ``diag_edit.php`` does not encode filenames before display * Regression #13265: Authentication using Voucher cause SQLite3 syntax error * Bug #13272: Voucher CSV output has leading space before voucher code * Regression #13274: OpenVPN override IPv4 tunnel network field changing value improperly * Bug #13282: Alias content is sometimes incomplete if the firewall cannot resolve an FQDN in the alias * Bug #13289: Attempting to restore a 0 byte ``config.xml`` prints an error that the file cannot be read * Regression #13290: Error ``dummynet: bad switch 21!`` when using Captive Portal with Limiters * Bug #13295: Incorrect function parameters for ``get_dpinger_status()`` call in ``gwlb.inc`` * Bug #13298: Dynv6 Dynamic DNS client does not check the response code when updating * Regression #13303: DNSExit Dynamic DNS updates no longer work * Regression #13350: SSL/TLS OpenVPN Client fails with ``ifconfig`` error when the IPv4 Tunnel Network is defined * Bug #13307: PPP interface custom reset date/time Hour and Minute fields do not properly handle ``0`` value * Bug #13310: Each line in the NPt destination IPv6 prefix list also contains the network of the previous line when multiple choices are present * Regression #13316: ``vmstat -m`` value for ``temp`` is accounted for incorrectly, resulting in underflows * Bug #13317: ``array_filter`` PHP Errors in ``interfaces.inc`` * Bug #13318: Neighbor hostnames in the NDP Table on ``diag_ndp.php`` are always empty * Regression #13323: Captive Portal breaks policy based routing for MAC address bypass clients * Regression #13356: RADIUS authentication attempts no longer send RADIUS NAS IP attribute * Todo #13357: Spelling and typo corrections * Bug #13364: Using the copy (not clone) function on firewall rules unintentionally converts interface ``address`` to interface ``net`` * Feature #13367: Specify CA trust store location when downloading and validating URL alias content * Regression #13373: IPsec rejects certificates if any SAN is wildcard rather than rejecting when **all** SANs are wildcard * Regression #13420: TCP traffic sourced from the firewall can only use the default gateway * Regression #13381: Software VLAN tagging does not work on ``ixgbe(4)`` interfaces * Regression #13391: Multiple Captive Portal interfaces do not properly form the list of portal IP addresses * Bug #13387: Input validation is not rejecting invalid description characters when editing a CA or Certificate * Feature #13388: Support for international characters in the AutoConfigBackup Hint/Identifier field * Bug #13390: "Dark" theme uses the same colors for disabled and enabled input fields * Bug #13393: DNS Resolver responds with unexpected source address when the DNS over TLS server function is enabled * Regression #13394: ``ASN1_NULL.php`` missing from package build of ``security/php-openssl_x509_crl`` on snapshots * Bug #13396: Custom logo or background image is created with two dots (``..``) before the file extension * Todo #13398: Information box on ``status_ipsec.php`` says "IPsec not enabled" even when a tunnel is established * Feature #13411: Packet capture does not support 6rd tunnels * Regression #13418: Captive Portal does not keep track of client data usage * Bug #13424: CRL expiration date with default lifetime is too long, goes past UTCTime limit * Bug #13425: Invalid alias name can still be used by code attempting to validate URL table content * Bug #13426: ``status.php`` uses ```` component of ``/tmp/rules.packages.`` filenames in shell command without encoding * Bug #13436: Input validation on ``system_advanced_firewall.inc`` uses incorrect variable references for some fields * Bug #13437: ECDSA certificate renewal causes digest algorithm to be reset to SHA1 * Todo #13440: Update external HTTPS/HTTP links * Bug #13445: ``easyrule`` CLI script has multiple bugs and undesirable behaviors * Feature #13446: Upgrade PHP from 7.4 to 8.1 * Bug #13448: Table row selection has poor contrast in Dark theme * Regression #13459: Automatic ``reply-to`` bypass for traffic in the same subnet is no longer functioning in main builds * Bug #13453: Incorrect word in "Network Interfaces" help text on ``services_unbound.php`` * Regression #13460: Panic with netgraph interfaces * Bug #13462: Advanced DHCP6 client settings only work for a single interface * Bug #13477: Captive Portal disconnecting a single user stops all traffic. * Bug #13479: Input validation is checking RAM disk sizes when they are inactive * Regression #13488: All Captive Portal users are given the same limiter pipe pair * Bug #13493: Several advanced DHCP6 client options do not inform the user when rejecting invalid input * Todo #13501: Clean up obsolete code in ``pfSense-dhclient-script`` * Todo #13505: Correct DHCP client rule descriptions in the generated firewall ruleset * Regression #13506: Services Status Widget always shows hiddebn * Regression #13512: PHP 8.1 Syntax Error in DNS Resolver Configuration Screen * Regression #13514: PHP 8.1 - Syntax error when disabling a gateway under SYSTEM > GATEWAYS > EDIT * Regression #13517: Erroneous dhcp6 Messages in Boot log on 22.11 * Todo #13524: Update reserved alias names * Bug #13525: Memory leak in PF when retrieving Ethernet rules * Bug #13533: pfsense 2.7 (FreeBSD 14) system_authservers.php - syntax error * Bug #13539: Missing descriptions for referrers to firewall aliases cause empty strings for references to be returned when deleting an in-use alias * Bug #13545: Toggling NAT rules using the button method does not enable/disable corresponding firewall rules * Regression #13550: Pfsense 2.7 October 7 Snapshot manualmount, failed boot * Regression #13553: PHP error when creating a new limiter * Regression #13563: PHP Error when attempting to save configuration after disabling a gateway * Regression #13559: GUI not starting after update to 2.7 * Bug #13561: Unable to set web interface session timeout to ``0`` (i.e. never expire) * Bug #13573: DHCP Server generates an invalid configuration for static mappings when defining network booting and UEFI HTTPBoot URL * Bug #13574: Extra remote address information can confuse ``sshguard`` * Bug #13579: Incorrect quoting of Split DNS attribute value in ``strongswan.conf`` * Regression #13581: Empty Dynamic DNS entry causes PHP errors in various contexts * Regression #13583: PHP error when defining an IP address and gateway manually from the Console menu using option 2) Set Interface(s) IP address * Feature #13584: Input validation for numbered DHCP options in static mappings * Bug #13591: Changing the GUI port does not redirect the browser to the new port on save * Regression #13593: pfSense-repo.abi left at FreeBSD:14:amd64 after changing update branch to DEVEL and back * Bug #13594: "Provide DNS servers to DHCPv6 clients" setting does not reflect a changed value until the page is reloaded * Regression #13598: fcgicli can output garbage for stdout/stderr read back from php-fpm * Regression #13599: Error when disabling sshd * Regression #13604: OpenVPN service status is incorrect * Regression #13605: Creating firewall rules with a schedule set triggers a config restore. * Bug #13607: Malformed format strings in French translation causing PHP errors. * Regression #13614: Cannot Edit Firewall Rules - 2.7.0-DEVELOPMENT (amd64) built on Mon Oct 31 06:05:27 UTC 2022 * Regression #13627: PHP: Easyrule from the firewall log * Bug #13633: DHCPv6 rules are not created for interfaces with static IPv6 * Regression #13635: Interface speed and duplex selection defaults to non-default option * Bug #13638: ``fcgicli`` fails to write packets with ``nvpair`` values that exceed ``128`` bytes * Bug #13645: PHP errors regarding ssh * Feature #13647: Support for ChaCha20-Poly1305 encryption with IPsec * Todo #13648: Remove deprecated IPsec algorithms (3DES, Blowfish, and CAST 128 encryption; MD5 HMAC/Hashing) * Bug #13655: DNS Forwarder (``dnsmasq``) is using an invalid combination of options when "Query DNS servers sequentially" is enabled * Bug #13659: replace direct config accesses for system/webgui paths in system_advanced_admin.inc * Regression #13660: PHP8.1 error after applying floating rules changes * Regression #13661: Input validation issues on firewall_shaper.php * Regression #13663: WIFI interface configuration creates invalid xml * Regression #13705: PHP8.1 Captive Portal TypeError * Regression #13669: Status / Services doesn't show correct OpenVPN status * Regression #13670: AES-NI support is built into the kernel on snapshots instead of being a module * Bug #13671: DHCP client can fail permanently if an interface is down at boot * Bug #13675: Code that sets IPv6 MTU can unintentionally act on IPv4 addresses * Bug #13676: PHP errors on services_dhcpv6_relay.php * Regression #13685: URL alias parsing is broken, gets stuck in infinite loop reading downloaded file * Bug #13716: CVE-2022-23093 / FreeBSD-SA-22:15.ping * Todo #13718: Improve LDAP debugging * Regression #13719: PHP8.1 error when saving DHCP Server settings. * Todo #13731: Add multicast group membership (``ifmcstat``) to ``status.php`` * Regression #13735: UPnP service status is incorrect when disabled * Bug #13736: Captive Portal service restart needed after MAC bypass * Regression #13739: Interfaces without a configured name appear as lowercase * Regression #13749: RADIUS auth using CHAP does not work * Bug #13742: Captive Portal MAC bypass - pf rules are not enforced * Regression #13744: Debug output shown on dashboard * Regression #13747: Captive Portal blocked MAC addresses are not blocked * Regression #13754: DHCPv4 rules are not automatically created * Bug #13755: Multiple incorrect configuration paths in recent UPnP code changes * Regression #13757: Circular dependency issue in ``auth.inc``/``authgui.inc`` * Regression #13761: Gateway list is empty when editing static route entries * Regression #13767: Refuse Nonlocal action in DNS Resolver access list breaks configuration file * Regression #13781: DNS Forwarder: PHP error in ``services_dnsmasq_edit`` * Regression #13782: DHCP leases are not registered in Unbound * Regression #13831: Syntax error in /etc/inc/util.inc on line 3655 * Regression #13833: Cron jobs are not removed by ``install_cron_job`` when set inactive as they should be * Bug #13838: Captive Portal RADIUS start/stop accounting does not reset counters at each accounting start * Bug #13851: DNS Resolver does not generate automatic ACLs for IPv6 when Network Interfaces is set to "All" * Bug #13860: Typo in Remote IPv4/IPv6 Address help text on ``interfaces_gre_edit.php`` * Regression #13861: Configuration history restores revision no matter which option is clicked in confirmation dialog * Regression #13862: Dynamic DNS check IP address service fails when using the default service * Todo #13865: Update Python 3.9.15 to 3.9.16 in base system * Todo #13866: Add Python 3.11.1 to base system * Todo #13867: Update Unbound to use Python 3.11 instead of Python 3.9 * Feature #13868: Allow packet capture on unassigned interfaces * Regression #13876: PHP error on diag_backup.php with no packages installed * Bug #13883: UDP checksum errors with ``ixgbe`` interfaces * Regression #13890: Captive Portal Voucher Rolls Status "Fatal error" * Todo #13893: Update Unbound to 1.17.1 * Bug #13908: Firewall rules are not reloaded when removing a VIP, outdated rules/entries remain active * Bug #13935: RRD restore process does not sanitize filenames from backup XML * Bug #13938: Kernel panic accessing the GUI over IPsec in certain environments when using nginx ``sendfile`` with unmapped mbufs * Bug #13940: Firewall log parser does not handle SCTP log entries * Regression #13942: PHP error on ``status_logs_settings.php`` if the configuration contains an empty ``syslog`` section * Regression #13944: PHP error in ``flock()`` during certain XMLRPC operations * Bug #13953: PHP Error loading Floating rule tab with OpenVPN group rules when there are no OpenVPN instances in the configuration * Todo #13959: Trim blank characters from static IP address fields on the Interface configuration page * Regression #13962: PPP interfaces do not request DNS servers when "DNS Server Override" is enabled * Regression #13965: Automatic DHCP failover firewall rules are not present in the ruleset when failover is active * Todo #14027: Update PHP to 8.2.6 * Regression #13983: Multiple PHP errors in the DHCP Server when the configuration contains an empty section for an interface * Bug #13992: Custom default state timeouts are not respected in the ruleset * Feature #14002: Option to enable/disable console bell, enabled by default * Bug #14004: PHP errors when configuration lacks any certificates * Bug #14007: Using PF reserved keywords for interface descriptions results in an invalid ruleset * Bug #14009: PHP error from upgraded IPsec tunnel containing only deprecated ciphers * Regression #14015: Alias list is not sorted * Regression #14016: FreeBSD default ``cron`` jobs are enabled when they should be disabled * Bug #14034: PHP errors in ``xmlrpc.php`` during configuration synchronization if the target host has an empty XML tag for a given section * Bug #14036: PHP error when the ``timeserver`` section of the configuration is empty * Bug #14037: PHP Error enabling ICMP6 using EasyRule * Regression #14053: Changing the default IPsec widget tab removes all widgets * Feature #14050: Support for ``iwlwifi`` wireless interfaces * Bug #14052: Bridge interface is not properly validated when submitted on ``interfaces_bridge_edit.php`` * Bug #14055: Traffic shaped by limiters is dropped when routed to a GIF gateway * Regression #14057: Dynamic gateway names use mixed case instead of upper case, leading to configuration mismatches * Bug #14060: Auto Config Backup prints a confusing decryption error when using the wrong key * Regression #14076: PHP error if the configuration has an empty Auto Configuration Backup section * Bug #14077: Kernel panic from incoming IPv6 connections * Bug #14092: Kernel panic when PF passes a large/fragmented ICMP6 packet * Todo #14098: Match upstream changes in PF syntax to disable fragment disassembly * Todo #14103: Add more disk information to status output * Bug #14115: DHCP Server page does not properly select a default interface tab if neither WAN nor LAN are capable of being DHCP servers * Regression #14120: ``syslogd`` tries to bind interfaces with no IP address * Bug #14124: Some blank SAN fields are not ignored when creating a certificate * Bug #14136: Services Status page and Dashboard widget do not list the ``radvd`` service with certain static IPv6 configurations * Regression #14139: CARP announcement src MAC should be virtual MAC * Regression #14163: Running ``ifconfig`` logs a high volume of netlink debug messages (``genl_handle_message``) on dev snapshots * Bug #14176: Uptime displays plural seconds for multiple minutes in the System Information Dashboard widget * Todo #14188: Add note to inform the user that the "Next Certificate Serial" value is ignored when the "Randomize Serial" option is enabled * Regression #14172: PHP error in Captive Portal if ``usedmacs`` list is empty * Todo #14183: Update OpenVPN Wizard to match current certificate and OpenVPN options * Feature #14185: Ability to edit Certificate Revocation List properties * Todo #14186: Improve DynDNS help text readability * Todo #14201: Remove deprecated NCP enable/disable toggle from OpenVPN * Regression #14217: IPsec Phase 2 rekey failures with some PFS key groups * Bug #14236: PHP Error when viewing Traffic Graphs in ``iftop`` mode * Todo #14250: Update firewall host and domain fields in the Setup Wizard to match the description and warning text from ``system.php`` * Bug #14256: PHP Error performing IPv6 ``ip_in_subnet()`` when passing a host addresses within prefix * Regression #14267: PHP error when saving an ICMP firewall rule with no subtypes selected * Bug #14288: Setting system DNS servers can incorrectly modify routes for interface addresses * Regression #14305: Boot loader is not updated during upgrade from pfSense CE 2.6 to 2.7 * Regression #14316: Filter/NAT rules configured with "No XMLRPC Sync" enabled are still synchronized * Bug #13014: Deadlock in Charon VICI interface * Feature #13382: Packet Capture GUI with granular control * Bug #14035: PHP error when attempting to create a GIF interface when ``if_gif`` kernel module is not loaded * Regression #14322: CARP password is not being respected on 23.05 snapshots * Regression #14327: Gateway popup in firewall rule list does not indicate current gateway status * Bug #13939: IPv6 does not work on secondary PPPoE WAN * Bug #14358: Discrepancy in "TTL for Host Cache Entries" Description * Bug #13915: PHP errors when re-running Traffic Shaper Wizards with different settings * Regression #14336: Firewall logs do not show the rule description * Bug #14045: ``pfSense-boot`` can fail to copy the EFI bootloader * Bug #14376: Packet captures can fail to start on loopback and encapsulated IP interfaces * Bug #14335: Associated firewall rule for NAT port forward does not inherit ``nosync`` property, gets synchronized * Feature #13054: Package plugin hook for web server configuration stanzas * Regression #14338: PHP error from empty separator * Regression #14086: Current snapshot builds missing most kernel modules that were on previous builds/releases * Bug #14031: Identical SMTP notifications repeat in an infinite loop under certain conditions * Regression #14091: The "Kill States" button does not work consistently * Regression #14351: Ram Disks are not created at boot. * Regression #14072: No working IPv6 gateway if upstream RA does not contain M or O flags because rtsold does not execute script * Feature #14255: Support for Intel PCH temperature values in thermal sensors * Todo #13492: Start ``rtsold`` immediately after ``dhcp6c`` sends a request * Todo #14307: Update miniupnpd to 2.3.3 * Bug #14482: Notices incorrectly set system LEDs on hardware with less than three LEDs * Bug #14345: Default tab on ``firewall_rules.php`` is not selected if the configuration has no WAN interface * Bug #13088: Rapidly clicking certain options on OpenVPN Client Overrides can cause hide/show field behavior to invert * Bug #2218: CARP VIPs can become master too early at boot time * Regression #14370: Console and system log may contain unnecessary Netlink debug messages from IPsec * Regression #13943: OpenVPN crashes with Signal 8 with very low fragment size * Bug #14373: System crashes or may become unresponsive with Captive Portal * Todo #12431: GUI pages should use ``POST`` for AJAX calls, not ``GET`` * Feature #8861: Show SFP module details on ``status_interfaces.php`` * Bug #14056: DNS Resolver experiences intermittent resolution failures with SSL over TLS due to ASLR * Regression #12821: Intel e1000 driver (``em``, ``igb``) cannot pass packets tagged with VLAN ``0`` * Regression #13522: Minnowboard Turbot additions are no longer present * Bug #13080: Cannot set EFI console as primary console when using both EFI and Serial * Feature #7727: uPnP fails to properly give out subsequent reservations when multiple gaming systems are playing the same game/using the same port * Bug #14354: Outbound NAT rule input validation error when attempting to manually specify "Other Subnet" with a valid address * Regression #12961: CARP event storm when leaving persistent CARP maintenance mode * Bug #14013: PHP error when attempting to bulk import Alias content * Bug #13756: Rules for authenticated Captive Portal users are not removed when a zone is disabled * Regression #12834: Only TCP traffic is passed outbound through IPFW * Bug #14022: PHP error when exporting a CRL for an old CA * Feature #14408: Include ``ixv`` in ALTQ capable NIC list * Regression #13748: DHCP server "Disable Ping Check" option does not store value on save * Regression #14010: Typo in ``filter.inc`` variable for DHCPv6 VLAN priority tag value * Todo #12934: Update strongSwan * Regression #14415: Enable IPv6 over IPv4 tunneling option results in invalid PF rule * Bug #14425: "Max Processes" value is not stored properly when saving on ``system_advanced_admin.php`` * Regression #14164: IPv6 interface configuration race condition can lead to kernel panic * Bug #14433: Panic when changing the parent of a VLAN interface used by limiters * Regression #14039: Limiters have no effect on upload traffic passed by policy routing rules * Bug #13003: Malicious Driver Detection event on ``ixl(4)`` driver * Feature #14457: Support receiving ``EAPOL`` frames on VLAN ``0`` in ``wpa_supplicant`` * Regression #14412: PHP error when attempting to bulk import Alias content * Bug #14458: PHP error in IPsec tunnels list * Bug #14396: Reassembled packets received on a VTI are not forwarded * Bug #12892: ``HTTPClient`` option not sent when using UEFI HTTP Boot * Bug #12612: DNS Resolver is restarted during every ``rc.newwanip`` event even for interfaces not used in the resolver * Bug #13048: Explicit PPPoE disconnect of a WAN Gateway Group member may not restore a default route * Bug #13253: ``dhcp6c`` is not restarted when applying settings when multiple WANs are configured for DHCP6 * Regression #14365: PHP error in RSS widget after saving settings * Todo #13701: Replace direct config accesses for the rest of the paths in ``system_advanced_admin.inc`` * Bug #14474: PHP error from empty ```` tag in ``config.xml`` * Bug #13529: Intel i226 network interfaces do not honor a manually selected link speed * Bug #13929: IGMP Proxy multicast group membership query packets have an invalid checksum * Regression #13666: Assigned bridge interfaces are not configured at boot * Bug #13973: PHP error in ``gwlb.inc`` when OpenVPN or IPsec instances referred to by assigned interface entries are missing * Regression #14283: Nothing is logged through ``syslog`` if the configuration contains an empty ```` section or if that section is not present * Regression #13999: PHP error in NTP widget and status with GPS data * Todo #13702: Replace direct config accesses in ``system_advanced_sysctl`` * Bug #14033: PHP error in NTP Server if the configuration contains a partial section of old ``openntpd`` settings * Bug #13280: Entries for ``net.link.ifqmaxlen`` duplicated in ``/boot/loader.conf`` * Regression #13963: OpenVPN and GIF interface create/destroy operations fail due to outdated ``linker.hints`` * Bug #14061: PHP error if a non-privileged shell user attempts an operation which needs to write ``config.cache`` * Bug #14117: PHP Error on ``status_interfaces.php`` from PPP interface uptime * Regression #13966: RRD update script does not parse state data properly * Bug #13308: The ``negate_networks`` table is duplicated in ``rules.debug`` * Bug #13408: PF can fail to load a new ruleset * Bug #13507: Copying multiple rules at the same time results in new rules with duplicate tracker IDs * Regression #13601: Error creating port forward rule with port alias * Feature #4154: Support for RADIUS authentication over IPv6 * Bug #14363: "All" user group overwritten after assigning an existing user to a group * Bug #14182: PHP error when XMLRPC client attempts to synchronize without any synchronization settings in the configuration * Bug #14400: PHP Error in ``upgrade216_ipsec_create_vtimap()`` * Bug #14446: PHP error in Captive Portal ``usedmacs`` handling * Bug #13946: Polish translation contains an invalid ``sprintf()`` format in the text for ``firewall_nat_out_edit.php`` * Regression #11545: Primary interface address is not always used when VIPs are present * Bug #12708: Alias with non-resolving FQDN entry breaks underlying PF table * Feature #12724: Notify user if AutoConfigBackup is unable to successfully upload a backup * Todo #14011: Update memory graphs to account for changes in memory reporting * Bug #14356: URL scheme is not properly validated in some cases * Bug #12003: Pie and ``fq_pie`` are missing options and do not handle floating point number input correctly * Feature #13304: ALTQ GUI support for Broadcom Netextreme II (``bxe``) interfaces * Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entries * Todo #13190: Update System_Patches package for pfSense+ 22.05 * Bug #13564: PHP error after creating a Route Map * Regression #13570: openvpn-client-export php error in 2.7 * Regression #13628: FreeRADIUS Users cleared out each time a user is add, removed, or modified * Regression #13892: PHP error from ``status_monitoring.php`` with empty OpenVPN servers * Regression #13960: PHP Fatal error - pfblockerng.widget.php * Bug #14075: Using the ``Transparent ClientIP`` option in HAproxy results in kernel panics * Bug #14096: Status_Traffic_Totals does not work on snapshots due to sqlite change * Bug #13799: Unbound python module persistently shows enabled in resolver settings