# 2.8.0 pfSense CE software release * Regression #15895: Configuration upgrade from before revision 19.1 removes OpenVPN settings * Feature #15437: Use natural sorting when sorting interfaces * Bug #15399: Local host gateways are shown in the default gateways list * Bug #15750: Hostnames for ISC DHCP leases are not removed from Unbound when switching to Kea * Bug #15751: Declining to reset the admin account via the console menu still prompts to change the password * Todo #15975: Additional error handling for invalid certificate configuration * Bug #14893: Large number of IPsec tunnels causes long filter reload times * Feature #9293: Custom message text for the login screen * Bug #15704: Automatic EDNS value may be lower than expected * Regression #15832: DDNS always resolves the public address using the default gateway * Bug #15907: PHP error in Captive Portal with undefined zone interface list * Bug #16093: Firewall logs mark entries for ``match`` rules the same as ``pass`` rules * Bug #13226: Disconnecting a user from Captive Portal may allow previously established connections to continue * Bug #15990: Input validation prevents updating a limiter without changing the name * Regression #15634: SSH Fails to Start on snapshots * Bug #16095: Firewall generates invalid rules for IPsec tunnels with descriptions containing special symbols * Bug #15834: Package menus with the same name but different sections do not get removed * Bug #15067: Secondary node attempts to delete the ``admins`` group when synchronizing accounts via XMLRPC * Bug #15071: Applying interface changes may not update default ACLs for the DNS Resolver * Bug #13089: Some OpenVPN NetBIOS settings are kept even when NetBIOS is disabled * Bug #13087: OpenVPN WINS options may be visible even when NetBIOS is disabled * Bug #15635: Gateway monitoring includes disabled gateways * Bug #13090: OpenVPN NetBIOS Node Type and Scope ID options are not pushed to clients * Bug #15914: PHP error when a queue is added with the same name as a limiter * Feature #13256: Better handling of duplicate IP addresses in static DHCP assignments * Bug #13413: Some messages presented to users contain relative links to pages which may be invalid when triggered from certain packages * Bug #15145: Unable to perform Packet Captures on a tailscale interface in GUI with default settings * Todo #13537: Update vendor files * Bug #15565: System proxy credentials with certain characters may fail to authenticate * Bug #15791: No default route after boot * Regression #15076: DHCP leases may not be restored from older configuration backups * Bug #16102: syslogd fails to release file handlers * Bug #16103: PPPoE WAN loses IPv4 addresses on ``IPV6CP`` ``LayerDown`` events * Bug #16104: Config access error with null static routes * Bug #15601: Routes with IPv6 Address as Next Hop for IPv4 Destination Causes Kernel Panic * Feature #15828: Kea DHCP lease database RAM disk support (IPv4 and IPv6) * Todo #14888: Exclude non-release branches from general update checks * Bug #15911: PHP error on save with very long configuration change descriptions * Feature #13894: Explicitly enable/disable DHCP Dynamic DNS updates in each scope * Bug #15912: Errors on the console when starting/stopping services * Feature #16092: Separate IDS/IPS and link-local firewall log entries from default block logging * Bug #15310: Errors in ``status.php`` IPsec sections when IPsec is not configured * Feature #15089: Support LuaDNS provider * Bug #15363: Reply traffic on a secondary WAN may be dropped when passed through dummynet * Bug #15830: ``process_alias_urltable()`` can fail to create an archive of a URL table alias when RAM disks are enabled * Feature #14067: Per-instance options to control Dynamic DNS client Check IP Service behavior * Bug #15223: Killing states on downed gateways breaks when ``Skip rules when gateway is down`` is enabled * Feature #14165: Option to allow the DNS Forwarder to ignore system DNS servers * Bug #15711: Special characters in the ACB configuration change description can cause PHP errors * Regression #15430: Interface-bound state policy does not handle IPsec VTI traffic as expected when filtering on ``enc0`` interface * Bug #15224: ``services_acb_settings.php`` does not fully validate value of ``frequency``, uses value without encoding * Bug #15225: Killing states on downed gateways breaks for static interface configurations * Bug #15096: Interface subnet aliases do not contain IPv6 VIPs * Todo #15969: Improve the system load impact from Dashboard widgets * Feature #14289: Enable ``@`` support for name.com in Dynamic DNS * Bug #14312: MSS clamping on VPN traffic does not work on IPsec IPv6 mobile VPNs * Regression #15112: ``status_interfaces.php`` is missing several values for SFP modules * Todo #15106: Remove ``Time`` column from OS Boot logs * Todo #15429: Clarify descriptions for gateway recovery options * Bug #16347: Memory leak in ``pftop`` * Bug #15108: ``pfctl`` is unable to retrieve state creator list in certain circumstances * Feature #855: Ability to selectively kill states on gateway recovery * Todo #15053: Update PHP to 8.3.x * Feature #8794: NTP authentication support * Bug #14605: Dynamic DNS uses the default gateway interface instead of the specified interface * Bug #15057: Router Advertisement daemon does not prioritize IPv6 GUA over ULA * Bug #15844: Dashboard ``widgetkey`` values are not validated on save or load, can lead to configuration corruption or other problems * Bug #15935: Incorrect rule may be opened for editing after rule order has changed * Bug #14083: Adding MSS and MTU values on a LAGG VLAN interface breaks connectivity * Regression #15936: Tracking information for firewall rules is not shown when editing the rule * Bug #15122: PHP errors in LDAP server prevent it from falling back to Local Database * Regression #14488: Extensions directory is not set in ``rc.php_ini_setup`` * Bug #14386: ``openvpn.auth-user.php`` gets stuck at 100% CPU usage when RADIUS authentication times out * Feature #15233: Recognize QAT 4xxx devices in System Information Widget * Bug #15373: Firewall Logs Dashboard widget update interval does not behave as expected * Bug #15069: Extra space in ``pkg`` configuration file ``FreeBSD.conf`` * Bug #13498: Newer variant models within the PC Engines APU2 platform are not recognized, causing garbled early serial console output * Bug #15117: Shortcut bar on DHCPv6 leases (``status_dhcpv6_leases.php``) navigates to DHCPv4 destinations, not DHCPv6 * Bug #15118: DHCPv6 settings page "DDNS Reverse" check box not showing current state * Bug #15434: DNS Forwarder ignores "Use remote DNS Servers, ignore local DNS" setting * Bug #15723: ``unbound-checkconf`` fails with python mode enabled * Bug #14967: Cannot disable Router Advertisements when the interface IPv6 configuration is set to ``None`` * Bug #15214: Advanced rule options tooltip does not show negated Tag option * Bug #15924: SCTP states not purged causing subsequent SCTP INIT to be blocked * Feature #15234: Show details of system aliases in tooltip on firewall and NAT rule lists * Bug #14977: Kea fails to restart due to race between process termination and startup * Todo #15864: Update UPnP IGD & PCP GUI text * Bug #15248: Removing a gateway group used as the default gateway results in no default route * Todo #15865: Make the UPnP IGD & PCP STUN port optional * Todo #16013: AutoConfigBackup code cleanup and GUI refresh * Bug #15124: IPsec VTI is not created correctly when using a Phase 2 remote type of ``Network`` * Regression #16196: System update page shows version string with extra parts * Bug #12673: Firewall Logs Dashboard Widget is slow and may fail to update * Bug #15252: Egress states remain when killing states for scheduled rules * Bug #15502: Proxy variables in ``crontab`` contents are improperly formatted * Bug #13158: Input validation error when applying limiter changes * Feature #15321: Kea DHCP Custom Configuration Support (IPv4 and IPv6) * Bug #15127: ``check_dnsavailable()`` failing even when DNS is available * Feature #15245: Show interface subnet details in a tooltip on the IPsec Phase 2 list * Bug #15133: PHP error with OpenVPN server certificate verification if the certificate has multiple ``CN`` attributes * Todo #15465: Update dnsmasq to version 2.90 * Bug #16012: "Reset" button on AutoConfigBackup Restore tab does not submit the form * Bug #15552: NTP option "DNS Resolution" has no effect when using NTP pool hostnames * Bug #14983: Upgrade can fail when unexpected EFI partitions are present. * Bug #15139: Local DNS resolution behavior does not add an IPv6 nameserver * Feature #15257: Support using a mask to block MAC addresses in Captive Portal * Feature #16014: Download function for AutoConfigBackup entries * Todo #15258: Update Gandi LiveDNS service with API changes * Bug #15156: Fragmented packets delayed by limiters are lost * Bug #15157: PHP error when generating a notification after detecting a malformed configuration * Bug #15718: AutoConfigBackup tries to upload backups before the system has finished booting * Bug #15264: ``crash_reporter.php`` displays PHP Error log without encoding * Feature #15575: Kea High Availability Support (IPv4 and IPv6) * Bug #15147: Cannot configure dual stack IPsec tunnel to accept connections from any remote address on both address families * Bug #15148: OpenVPN Wizard fails when a VIP is used * Bug #15162: Adding Wake-On-LAN entry from ARP table view can incorrectly include OEM text in MAC address field * Regression #15692: OpenVPN QinQ interface creation fails * Regression #15762: Captive Portal concurrent login setting does not work * Bug #14290: ICMPv6 Path MTU Discovery breaks with NPT * Bug #16069: The monitoring IP address for dynamic gateways may be unexpectedly routed via a different gateway * Regression #15206: Deleting OpenVPN server or client on 24.03 release gives an error * Todo #15265: Remove ``jquery-treegrid`` unit testing files * Bug #15404: Captive Portal logo fails to load after authenticated redirect * Bug #14991: Kea does not allow FQDNs for NTP servers but input validation does not prevent them from being added * Bug #15719: GUI logout messages do not use the ``auth`` log facility * Bug #16205: pfSense 2.8 Release has no package repositories * Regression #15152: Systems with low RAM fail to upgrade to 24.03 * Bug #14996: Kea DHCP PHP error from WINS server value * Regression #15170: webConfigurator IPv6 resolver syntax change * Bug #15490: Sanitize RFC 2136 Dynamic DNS update keys in ``status.php`` output * Bug #15171: Removing an IPsec Phase 1 entry can either remove the wrong Phase 2 entries or leave orphaned Phase 2 entries in the configuration * Bug #15135: Potential local file include vulnerability via DNS Resolver Python Module Script include mechanism * Feature #10000: Enable ``@`` support for Azure in Dynamic DNS * Todo #15173: Add global option to set default PF State Policy (if-bound vs floating) * Bug #12942: Code to kill states for old gateway when reconnecting an interface is incorrect * Bug #15176: Change Mobile IPsec RADIUS accounting to use ``accounting_requires_vip`` so accounting will not activate for non-mobile VPNs * Bug #14742: Several PHP errors in upgrade_config.inc * Feature #14953: Add Kea information to ``status.php`` * Bug #13687: Cannot add limiters named ``new`` * Todo #13268: Dynamically adjust the interface name maximum width in the login banner * Todo #15220: Handle ``route-to`` and ``reply-to`` states when using the ``if-bound`` state policy * Bug #15032: Kea DHCP sends wrong bootloader file for UEFI * Regression #15339: Firewall logs widget cannot have multiple instances * Regression #16105: Config access error after changing an interface from DHCP to Static * Feature #15183: Add per-rule option to set PF State Policy (if-bound vs floating) * Regression #14431: Sending IPv6 traffic on a disabled interface can trigger a kernel panic * Bug #15288: ``loader.conf`` may be missing ``loader_conf_files`` so ``loader.conf.lua`` may not be parsed * Bug #11418: 'NAT-T: Force' is broken for IPv6 IPsec * Bug #16019: Kea can unintentionally attempt to spawn multiple processes and fail * Bug #15282: Users with Deny Config Write privilege can trigger some VLAN interface operations * Feature #2358: NAT64 support * Todo #15188: Remove deprecated OpenVPN hardware crypto engine option * Regression #16127: ``syslog`` configuration for ``if_pppoe`` breaks logging for itself and later configuration entries in certain cases * Bug #10980: ``/etc/rc.local`` script content is executed at login instead of during boot sequence * Bug #14942: DNS Resolver host overrides ignore all aliases if first entry has a domain set but no hostname * Feature #7943: Overflow scrolling for top navigation drop-down menus in Fixed mode * Bug #14854: Packets are passed through dummynet twice when using ``route-to`` leading to half the expected bandwidth * Feature #5080: Settings tab for global Kea DHCP server options * Regression #15439: Incorrect icon on collapsed dashboard widgets * Feature #11556: Kill states using the pre-NAT address * Feature #15322: 50x and 404 error handling to GUI web server configuration * Regression #14970: Static ARP assignments lose ``permanent`` flag in ARP table * Bug #15083: Installing to ZFS mirror does not format or populate EFI partition on additional disks * Regression #16129: Bogons file is not updated * Bug #15084: Upgrading an EFI system installed to ZFS mirror does not upgrade EFI loader on additional disks * Bug #16130: Input validation prevents creating port forwards for the same port using a different address family * Bug #14919: OpenVPN forms invalid ``route`` statements for empty local networks * Bug #14929: ``choparp`` service is not stopped after deleting Proxy ARP type Virtual IP addresses * Bug #15440: CA certificates are not added to the Trust Store * Bug #14936: ``radvd`` service shows as stopped in services list when it should be disabled and hidden from that list * Bug #15384: Reordering IPsec Phase 2 entries may result in a malformed configuration * Bug #11268: Cookie named ``id`` prevents some forms from being loaded or saved properly * Bug #15442: CLI password check exits with a write access error when checking is a read-only operation * Regression #15197: Outbound NAT rules using an alias without a matching address family create unexpected PF rules * Feature #15297: Add EFI boot information to ``status.php`` * Todo #13263: Reduce log spam when deleting a static DHCP entry * Feature #15298: Add ``loader.conf.lua`` contents to ``status.php`` * Bug #12920: Gateway behavior differs when the gateway does not exist in the configuration * Feature #1979: Allow user-defined rules to utilize built-in system aliases * Bug #15301: Setup Wizard WAN configuration form field problem * Regression #16023: RAM disk configuration check fails at boot * Todo #15302: Error handling in the Setup Wizard is very user-unfriendly * Bug #15361: Network and broadcast address input validation is incorrectly applied to IPv6 VIPs * Bug #9453: Reconfiguring a parent LAGG interface breaks its VLANs * Regression #14930: Clean installation using Auto (ZFS) + MBR (BIOS) does not boot * Bug #15722: Unbound configuration file contains Localhost address in forwarding mode with TLS enabled * Bug #16028: RFC 2136 Dynamic DNS cannot update AAAA records over IPv6 * Feature #15422: Show current boot method in System Information Dashboard widget * Bug #15181: PHP error in ``interfaces_qinq_edit.php`` when creating a QinQ interface * Feature #16015: Method to change the AutoConfigBackup device key * Bug #15043: IGMP proxy works intermittently * Bug #16030: Captive Portal service management via ``pfSsh.php svc`` fails when the zone name contains uppercase letters * Bug #15054: Permissions on tmpfs RAM disk for ``/var`` are too lenient * Bug #15263: PHP error display formatting issues * Feature #13085: OpenVPN NBDD server options * Feature #14728: Support for CD/DVD drives in the External Configuration Locator (ECL) * Bug #15299: Old auto-added MAC addresses are not pruned for non-concurrent Captive Portal sessions * Regression #16031: Some older ISA-based uart consoles do not function on development snapshots around 25.03 or later * Bug #16032: Creating a Captive Portal zone with uppercase letters overwrites existing zones of the same name * Bug #15471: Memory leak in pfSense module function ``pfSense_get_ifaddrs()`` * Bug #16115: Potential XSS in IPsec Phase 1 * Bug #15525: File browser on ``diag_edit.php`` does not encode directory names before display * Bug #16114: Potential XSS in Firewall Schedules * Bug #15454: Certificate Manager GUI inconsistency in Revocation tab titles * Bug #15481: File descriptor leak in ``bsnmpd`` * Bug #15729: Session cookie warnings * Regression #16036: Cannot set a new name when duplicating an existing gateway group * Bug #16116: Potential XSS in Wake on LAN page and widget * Bug #15777: ``resizewin`` occasionally gets fed a spurious line feed over certain serial console+client combinations * Bug #15516: Per-rule byte counter values lost across a filter reload * Bug #15643: Deleting one pre-installed package may delete other pre-installed packages * Regression #16126: Captive Portal status page lists empty selections when multiple portals exist * Feature #16134: Support ``if_pppoe`` backend for PPPoE WAN interfaces * Todo #15728: Improve Thermal Sensors Dashboard widget refresh code * Bug #15778: Interface group members are not validated on load/save on ``interfaces_groups_edit.php``, and are printed without encoding on ``interfaces_groups.php`` * Bug #15624: Skip Packages option for Configuration Backups fails with large configurations * Todo #15781: Remove deprecated HTTP/1.0 Pragma header * Bug #15413: Kernel panic in HA nodes when under high load * Todo #15483: Update Unbound to 1.22.0 * Bug #16155: mpd5 specific options remain availble after enabling if_pppoe * Bug #16169: NAT64 states have ``src`` and ``dst`` swapped in data returned by pfSense PHP Module * Bug #14859: Config upgrade error: upgrade_config.inc:6135 * Bug #12938: Incorrect warning from ``radvd`` about ``AdvRDNSSLifetime`` value * Bug #16011: AutoConfigBackup remote revision timestamps may not be unique due to batch uploads * Bug #15449: IPsec VTI static routes may not be added after the system boots * Bug #15362: Config upgrade error with empty gateway interval tags. * Bug #15423: PHP error when applying interface settings if the ``/tmp/.interfaces.apply`` file is present but empty * Bug #16145: Not possible to delete Custom message text for the login screen * Regression #15578: Saving an existing certificate authority creates a duplicate * Bug #16043: The filtered states shown may include states for interfaces other than the selected interface * Bug #15589: Saving an IPv6 gateway overrides the IPv4 gateway * Bug #15572: Disabling DNSSEC should also disable Harden DNSSEC Data * Feature #15609: Allow filtering packet captures by system-defined protocols * Bug #15537: Separator positions are incorrect when copying interface group rules * Todo #15586: Query for SMART data only on root disk devices * Feature #15651: Kea DNS Resolver (Unbound) Integration (IPv4 and IPv6) * Feature #15652: Kea DHCPv6 Prefix Delegation Support (IPv6 Only) * Bug #16046: Dynamic DNS IP address may not be updated after changing the interface of a Dynamic DNS entry * Bug #16047: Cannot kill states using the post-NAT address * Bug #15657: State table entries printed on ``diag_dump_states.php`` may contain an unexpected interface * Regression #15669: Static routes using null gateways are not installed * Feature #15661: GUI options to change default SCTP state timeouts * Todo #16049: Update nginx to 1.26.3 * Regression #12581: Non Link-Local IPv6 CARP address does not get advertised to endpoints with RADVD * Todo #16050: Update cpu-microcode-intel to version 20250211 for multiple CVE mitigations * Bug #15671: Setting the Port Forward interface to an interface group selects an invalid destination * Bug #12747: Restarting the logging daemon during rotation also restarts ``sshguard``, leading to frequent log messages * Bug #15130: Kea will not start with identical MAC address filters on multiple interfaces * Bug #15694: State Killing on Gateway Recovery fails for the default gateway group with the "Kill all" option selected * Bug #15700: Package navigation menus can be duplicated when reinstalling the package * Regression #15470: Port forward rules created by ``miniupnpd`` do not expire * Regression #15833: Default Check IP Service enable/disable status not reflected on Check IP Service List * Bug #15702: IPv4 DHCP client responses may be routed unexpectedly out unrelated WANs * Regression #15768: OpenVPN Windows Client fails to connect * Bug #15755: Mobile IPsec sends incorrect DNS attribute IDs * Bug #15831: Kernel Panic when IGMPProxy gets CIDR Removed * Bug #15802: Dynamic DNS attempts to resolve entries with disabled interfaces * Feature #15022: Allow overriding text scrolling during package install/uninstall * Bug #16059: RAM Disk cron jobs are not saved correctly * Todo #16060: ``pkg`` no longer supports setting ``ALTABI`` manually at run-time * Bug #12947: Old IPv6 addresses may continue to be used after DHCP or RA changes * Regression #14026: HA node with CARP VIP in backup state is unable to ping the active node using that CARP VIP address * Feature #13520: Improve Thermal Sensors Dashboard widget readability * Bug #15328: Changes in Kea DHCP interface pools may invalidate lease database content * Bug #15547: Filter rule association incorrectly displayed when editing a port forward * Bug #15606: Data transfer problems when using interface-bound states with automatic floating states for IPsec rules * Todo #15782: Use minified nvd3 vendor files * Regression #15888: ALTQ shaper queues are not present after importing a config * Feature #11177: Improve Dynamic DNS client IPv6 support * Bug #14933: Traffic Graph widget displays bandwidth usage values which are half the actual usage amount * Bug #15725: Dashboard widgets refresh at unintended intervals * Bug #15772: Captive Portal zones can fail to start due to ID conflict * Bug #15685: Mobile IPsec does not automatically switch to failover gateway * Bug #16156: DDNS may send requests over IPv4 for IPv6 services * Bug #14708: PHP error when the system fails to create an interface * Feature #12522: More GUI options for OpenVPN Client-Specific Overrides * Regression #15815: PHP error when no WOL entries are defined * Bug #16158: IPsec allows deleting P1/P2 entries with an assigned VTI * Regression #15810: ntpd can fail to start when unbindable addresses exist * Todo #15779: Update Dynamic DNS API URL for porkbun.com * Bug #15819: PHP error when creating intermediate certificates * Bug #15684: Panic in ``tcp_m_copym`` with selective ACK enabled * Bug #15856: OpenVPN Status Page and Dashboard Widget use input values without validation * Todo #15848: Exclude the WireGuard and Tailscale interface group system aliases from rules * Bug #15842: Kea HA does not list TLS certificates * Regression #15094: Updates fail against an authenticated upstream proxy * Bug #16162: IPsec unnecessarily prompts to apply changes after input errors * Bug #15874: Users with Deny Config Write privilege can trigger logging operations * Regression #15882: L2TP server settings are not saved correctly * Regression #15885: Error when viewing ALTQ Traffic Shaper queue status * Todo #15893: Limit PHP request order processing to only GET and POST * Todo #15863: Update nginx HTTP2 syntax * Regression #15890: Unable to change DNS Forwarder domain overrides * Bug #15332: Kea fails to start if DHCP pool configuration contains default lease time or max lease time * Feature #15818: Certificate Authorities created in the GUI do not have the Basic Constraints extension marked critical * Bug #16167: if_pppoe sends invalid service name * Bug #15598: Input validation for duplicate remote gateways does not work when using the duplicate P1 button * Feature #15654: Kea Static ARP Support (IPv4 only) * Bug #15927: Potential XSS in AutoConfigBackup backup list on ``services_acb.php`` * Bug #15908: Users with Deny Config Write privilege can change their own password * Feature #15776: System Aliases for various reserved networks * Bug #15767: Clicking the picture widget image downloads the image with an invalid filename instead of showing it inline * Bug #15873: PHP error when a user is denied access to the dashboard * Bug #15926: Captive Portal does not function with MAC filtering disabled * Todo #15953: Link to release information on the system update page * Bug #16076: Deleting or adding a firewall rule may result in an unexpected rule order * Regression #15961: Warning message in logs when changing firewall rules after setting Require Firewall Interface * Bug #15925: DNS Resolver option for Query Name Minimization cannot be disabled * Bug #15977: Incorrect color in button text within disabled rows * Bug #15988: PHP error when saving System Log settings * Bug #16005: PHP error from invalid IPv6 address on ``diagnostics_ping.php`` * Todo #16016: Change AutoConfigBackup default key generation format * Regression #16045: Dynamic DNS IPv6 tries to use IPv4 address * Bug #16057: The package ``post-install`` script does not run with a system upgrade on ZFS * Bug #16063: PHP error after saving NTP settings with an interface selected * Bug #16170: Incorrect logic for detection of DNS server change in cases where the ISP does not provide search domains in DHCPv6 renewal * Bug #16180: Improve gateway status detection with routed monitoring addresses * Bug #16182: Firewall rules using interface subnet aliases may prevent filter rules from loading after upgrades * Bug #13662: Setting a limiter queue length greater than 100 prevents the limiter from loading * Bug #15318: Users with Deny Config Write privilege can trigger some QinQ interface operations * Feature #15415: Enhanced firewall log action information display * Bug #15679: Multicast with intel NIC * Feature #15808: PREF64 support in Router Advertisements * Bug #15876: Routing Advertisements daemon fails to start when configured with more than 3 RDNSS entries in a prefix * Bug #12249: Long configuration revision reasons can cause AutoConfigBackup upload to fail * Bug #16081: Panic accessing ``sysctl`` OID ``net.inet.ip.nhdispatch`` with an INVARIANTS kernel * Bug #15860: Contents of the configuration may still be stored even when the XML is not valid * Regression #15898: Changes to the ``admins`` user group are not synced to the secondary node * Todo #15058: Remove Zabbix 4 Agent and Proxy * Todo #16091: tailscale package requires updates * Bug #16096: Day of week description does not reflect input validation * Feature #13063: Improve modem support * Feature #13135: Add dibdot DoH-IP-blocklists feeds * Bug #14299: pfBlockerNG does not honor the cURL source interface setting for DNSBL lists * Bug #13214: AttributeError: 'NoneType' object has no attribute 'text' * Bug #14572: Unused DNSBL files may not be removed * Regression #16090: Commit 96e2c21 breaks the cURL source interface setting for pfBlockerNG * Bug #14861: PHP error when pings are enabled but no ping hosts are defined * Bug #15644: Snort Status icon disappears * Bug #15190: PHP error from RRD Graphs when resolution is null * Bug #15771: RPKI cannot be configured * Regression #15540: Cannot create new System Patches package custom entry on Plus 24.08/CE 2.8.0 Snapshots * Feature #15674: Support custom IP and Port variables for interfaces * Bug #15872: PHP error when accessing mail reports * Bug #15976: Fix ntopng listen options * Bug #15744: Suricata LOGS MGMT feature shows ``enabled`` by default on a green-field install when it should instead default to ``disabled`` * Bug #14523: PHP error when using an unsupported alias type in Advanced Rule Settings * Regression #14850: Unreadable alerts file results in PHP error * Bug #15760: Typo in Snort Important Preproc Information * Bug #15733: Changing the account key name does not update respective certificates * Bug #15726: Apcupsd dashboard widget warning/critical values are not digits or units as expected * Bug #15824: Build options on haproxy29 package do not match previous versions * Bug #15845: UPS Settings doesn't display the full list of availabale drivers * Regression #16160: PHP error after saving WireGuard tunnel with multiple addresses * Feature #15891: NUT driver list update * Bug #15939: An empty IPv4/v6 and DNSBL entry is added if it’s not saved * Bug #15996: pfBlockerNG can clobber unbound file permissions * Bug #15639: Automatic boot verification shows negative timer