# 2.7.1 pfSense CE software 2.7.x maintenance release * Feature #13377: Option to configure a custom value for the PHP memory limit * Bug #13068: Firewall rules fail to load when a URL table alias file does not exist * Bug #13903: PPPoE Server address input validation is incorrectly allowing IPv6 * Bug #14325: Captive Portal incorrectly allows leading zeroes on voucher roll numbers * Bug #13423: IPv6 neighbor discovery protocol (NDP) fails in some cases * Regression #14885: PPPoE clients macro does not work * Regression #14735: ``arp`` command is not filtering output as expected, behavior changed in FreeBSD * Feature #6960: Introduce Kea DHCP as an alternative DHCP server for IPv4 and IPv6 * Bug #14738: IPsec restart in CARP event scripts does not check VIP properly and never runs * Feature #14337: Allow SMTP notifications from non-root processes * Feature #14650: Change default match modifier from "all of" to "any of" * Regression #14740: Outbound NAT pool options are hidden when a subnet VIP is selected * Feature #14746: Method for users to customize shell initialization behavior * Regression #14768: "syslog: unknown facility name "radvd"" error when "Routing Daemon Events (RADVD, UPnP, RIP, OSPF, BGP)" option is enabled * Bug #14831: IPsec rejects certificate without any SANs * Todo #14769: Increase timeout for password entry when restoring an encrypted configuration via ECL * Feature #9504: Include hostname being updated in Dynamic DNS notifications * Regression #14918: Filter rules error with 1:1 NAT rules that use the interface subnet macro * Regression #14374: Static ARP entries are not configured at boot * Feature #13804: Prevent CARP status/maintenance mode from being erroneously toggled * Feature #13245: Type column on Alias lists * Regression #14377: Cannot add a QinQ interface to a bridge * Bug #14392: ``find_interface_ipv6_ll()`` can return a VIP instead of the interface address * Regression #14615: PHP crash during bootup with gateway monitoring enabled with custom monitor IP * Feature #14402: Dynamic DNS support for Porkbun * Bug #14394: PHP error in CSRF Magic from invalid time value * Bug #7589: ``diag_edit.php`` warning is not cleared after picking non-directory to load * Regression #14500: PHP Error when viewing Traffic Graphs in ``iftop`` mode * Todo #12762: Clarify that the IPsec keep alive check option ignores Child SA Start Action * Bug #14621: Rule separators are hidden when their index is greater than the number of rules * Regression #14719: IPv4+IPv6 outbound NAT rule expands to invalid rule set * Feature #14448: Support interface groups in firewall rule source/destination fields * Feature #14265: Option to invalidate GUI login session if the client address changes * Bug #14462: Breadcrumb path missing on ``system_register.php`` * Bug #13218: GIF-based interface MTU is assigned to parent interface on boot when parent interface is a LAGG * Bug #14524: Cannot select IP Alias VIP with CARP VIP parent in Virtual IP drop-down on Gateway Groups * Regression #14525: PHP error in ``status_ipsec.php`` after removing active IPsec tunnel configuration * Regression #14534: Cavium ``qlnxe`` / ``if_qlnxe`` driver is not present * Bug #14497: Kernel panic when using traffic shaping on a PPPoE interface * Bug #14542: Gateway widget tooltip incorrectly indicates some gateways as being default * Bug #14545: Per-log settings for file size and retention count are not honored * Regression #14517: Log rotation is not active if the configuration contains an empty ```` section or if that section is not present * Todo #10464: Don't change the current update repo when new releases are available * Bug #14544: PPP interface default username/password are not being populated from provider data on ``interfaces.php`` and ``interfaces_ppps_edit.php`` * Bug #14574: Firewall rules are not displayed properly when they reference a URL table alias and its file does not exist * Bug #14576: "Convert interface definitions" option is not respected when bulk copying rules * Bug #14548: ``status_logs_filter_dynamic.php`` does not encode value of ``interfacefilter`` in raw mode * Bug #14598: Link to view Captive Portal custom HTML page content does not work * Todo #14399: Combining Interface and Rule ID state table filter fields returns no results * Bug #14637: PHP shell script ``pfanchordrill`` shows duplicate anchor content * Feature #3288: Support interface macros in Outbound NAT rules * Feature #14640: Extend support for SCTP in firewall and NAT rules * Bug #14626: Multi-WAN IPsec does not fail over when preferred WAN loses link * Regression #14635: "Legacy" strength PKCS#12 Export needs ``-legacy`` provider parameter on OpenSSL command * Bug #14725: Primary IPv6 interface address may be incorrect when a ULA is set * Todo #14790: Eliminate direct config access in ``interfaces.php`` * Bug #14646: OpenVPN can select the wrong interface IP address when multiple addresses are present * Bug #6799: Negating `` net`` when a VIP exists on the interface results in unintended behavior * Bug #14673: Remove broken ``stun.sipgate.net`` from UPnP STUN server list * Bug #14665: IGMP Proxy cannot start on VirtIO (``vtnet``) interfaces * Regression #14727: PCH Temperature missing from Thermal Sensors * Todo #14672: Prevent weak SHA1 certificates from being used with GUI and Captive Portal * Regression #14698: TLS Cert Warning Message Present on First Start * Regression #14678: CA and Certificate renewal page does not properly list some SHA1 certificates as being weak * Regression #14794: PHP error when adding firewall rule when the configuration contains no separators * Feature #14844: QAT 200xx devices are not recognized as supported * Bug #9889: Cannot validate Certificates against Certificate Revocation Lists for Intermediate Certificate Authorities * Todo #14677: Prevent weak SHA1 certificates from being used with OpenVPN clients and servers * Regression #14690: Creating or duplicating an IPsec P1 entry does not increment the IKE ID * Bug #14695: Copy function for User Manager Groups does not work for first group in list * Bug #8846: Misleading error message when adding/editing static routes which use a gateway on a disabled interface * Feature #13124: Option to wait for interface selection before displaying firewall rules * Bug #14691: Separators get shifted when copying firewall rules between interfaces * Bug #14417: System Information widget does not properly form list of active hardware crypto algorithms * Regression #14709: Patch to disable procctl in pkg is missing * Bug #14783: List of Dynamic DNS types with split host+domain name is missing several providers * Regression #14845: PHP error in 1:1 NAT rule list when a 1:1 NAT rule uses an interface macro for the external address * Bug #14717: A default route can remain after setting the default gateway to None * Bug #14784: Correct name of Gandi LiveDNS * Bug #14807: Logo text is partially rendered when using Compact-RED theme on CE * Feature #14726: Show IPsec phase 1 authentication type in Mode column of tunnel list * Todo #14732: Update Unbound to 1.18.0 * Regression #14736: Unable to select PFS Group for individual Phase 2 configurations if Mobile Client global override is not selected * Todo #14750: Automatically configure PF states hash table size * Bug #14892: Traffic graph filters apply incorrectly * Feature #14731: Unbound Advanced Settings entry for ``sock-queue-timeout`` * Regression #14755: Intermittent core dump in ``ndp`` when visiting ``diag_ndp.php`` * Bug #14756: Link loss causes interfaces configured as Track Interface for IPv6 to lose their IPv4 addresses * Regression #14569: ``bnxt(4)`` driver errors * Bug #14785: Primary IPv6 interface address may be incorrect when a VIP is set * Bug #13776: Some functions fail if the Language does not exactly match an available Locale * Regression #14623: Primary interface address is incorrectly set to the last address on the interface * Regression #14781: OpenVPN resync for a specific interface may unintentionally restart OpenVPN instances on unrelated interfaces * Regression #14791: ``/etc/version.buildtime`` is not being updated on current snapshots * Feature #14777: Status output plugin hook for packages to include their own data * Bug #14820: GUI TCP port is not updated in the configuration when saving with the field empty to remove an existing value * Bug #14549: Interface value is not properly validated when submitted on ``interfaces_gif_edit.php`` and ``interfaces_gre_edit.php`` * Feature #14347: Improve System menu behavior for Certificate Manager privileges * Bug #14432: PHP error when failing to write ``config.cache`` * Regression #14935: Filter rules specifying a VIP address are not generated * Bug #13911: Unnecessary delay when querying ``ixgbe(4)`` interfaces with SFP ports * Regression #14867: Address family validation prevents creating 1:1 NAT rule * Bug #14809: ``packet_capture.php`` uses ``count`` and ``length`` values in command execution without validation or encoding * Regression #14502: DHCPv6 Prefix Delegation (PD) not installing routes * Regression #14897: DHCPv4 service stopped after applying interface settings when no interfaces have DHCPv6 enabled * Bug #14829: Multi-WAN Dynamic DNS does not fail over when preferred WAN loses link * Regression #14876: ``ca_setup_trust_store()`` behavior conflicts with ``certctl`` * Regression #14856: Duplicating a floating rule places it at the bottom * Regression #14649: PHP error with One.com Dynamic DNS provider * Regression #14819: File to trigger the wizard post-install is missing * Regression #14873: Kea DHCP Static Mappings 404 Not Found * Regression #14866: System aliases created for local subnets can be an invalid length * Bug #14884: Kea service for IPv6 can show active even when no interfaces have DHCPv6 enabled * Regression #14877: Import PKCS #12 (PFX) certificate error when using legacy/low ciphers * Regression #14889: Lock leak kernel panic after upgrading to 23.09 * Regression #14896: Suricata is removed when upgrading the base system * Regression #14880: Diagnostics>States doesn't allow rule ID and interface filtering simultaneously but clearing the interface field is not possible * Bug #14758: ``status_carp.php`` and ``diag_dump_states.php`` unresponsive with large state tables * Bug #14804: Panic when pfsync attempts to synchronize states between hosts with different rulesets * Regression #14870: Aliases are incorrectly added to rules * Bug #13704: Refactor IPsec code using config access functions * Feature #14047: Options to control Intel Speed Shift * Bug #14301: Input validation error when saving IGMP Proxy settings * Bug #14513: Improve error handling in ``status.php`` * Bug #14579: PHP error in ``handle_wireless_post()`` when toggling some wireless interface options * Bug #14609: Update check in GUI does not always honor the configured proxy settings * Bug #14619: Rule separators are ordered incorrectly after removing rules in certain positions * Feature #14667: Improve SCTP support in ``filterlog`` * Todo #14686: Check for deprecated OpenVPN encryption and digest options on upgrade * Bug #14702: ``ctype_digit()`` returns unexpected result for values <= ``255`` which can break some validation functions/usages * Regression #14713: Mobile IPsec not allocating address to connecting clients on dev snapshots * Bug #14767: Kernel textdumps are not recovered properly on systems with multiple swap partitions * Bug #14547: ``getserviceproviders.php`` does not always validate value of ``$connection``, displays without encoding * Regression #14947: Rules using aliases of type ``URL (IPs)`` are not generated * Todo #14985: Update OpenVPN to 2.6.7 * Regression #14966: DHCP WAN with multiple (2+) IP Alias VIPs may show ``0.0.0.0`` as an interface address at boot * Todo #14980: Update Unbound to 1.18.0_1 to address looping UDP retries when ENOBUFS is returned * Feature #13575: Update to frr 9.0.1 * Regression #14636: "Legacy" strength PKCS#12 Export needs ``-legacy`` provider parameter on OpenSSL command