Howdy,

Two major improvements being shipped today are standalone core DNS support for Bind and Dnscrypt-Proxy plugins as well as OpenVPN group firewall alias type. The latter makes it easier to manage distinct policies for connected VPN users. For more details please refer to the documentation listed below.

The other honorable mention is the netmap work we have been doing with Zenarmor and Klara on the FreeBSD kernel side which brings bridge device support as well as a considerable improvement to the emulated mode where several packet stalls and mbuf leaks have been identified and subsequently fixed. This should have an operational impact on Suricata (IPS mode) and Zenarmor. The state is much better now but please do not hesitate to contact us about issues that you might still be having with netmap-based packet flows as the topic is a rather complex one.

Orange FR users be aware that your ISP now requires strict VLAN PCP on all DHCPv4 requests so please now set 'Use VLAN priority' interface setting for both DHCPv4 and DHCPv6. The 'Option Modifiers' override for "vlan-pcp" in DHCPv4 can be removed.

Here are the full patch notes:


Stay safe,
Your OPNsense team