21.02/21.02-p1/2.5.0 New Features and Changes (original) (raw)

pfSense® Plus software version 21.02 and pfSense Community Edition (CE) software version 2.5.0 include a major OS version upgrade, a kernel WireGuard implementation, OpenSSL upgrades, VPN and related security improvements, plus numerous other bug fixes and new features.

Warning

The original plan was to include a RESTCONF API in pfSense® Plus software version 21.02 and pfSense software version 2.5.0, which for security reasons would have required hardware AES-NI or equivalent cryptographic accelerator support. Plans have since changed, and these versions do not contain the planned RESTCONF API, thus pfSense® Plus software version 21.02 and pfSense Community Edition (CE) software version 2.5.0 DO NOT require AES-NI.

pfSense Plus

Version 21.02 is the first release of pfSense Plus software, formerly known as Factory Edition. For more details about the distinctions between pfSense Plus and pfSense CE, read the pfSense Plus Announcement. Customers running the Factory Edition of pfSense software version 2.4.5-p1 and older can upgrade in-place automatically to pfSense Plus software version 21.02 as with any other previous upgrade.

In this version, the changes in pfSense Plus software and pfSense CE software are roughly the same, with a few notable exceptions which are only available in pfSense Plus software:

Version 21.02-p1

pfSense Plus software version 21.02-p1 is a special patch release to address a kernel problem affecting the SG-3100 which caused system instability (#11444). No additional fixes are present in the 21.02-p1 release.

See the detailed bug analysis blog post for more details.

Operating System / Architecture changes

Known Issues / Errata

Warning

See the FreeBSD 12.0 Release Notesfor information on deprecated hardware drivers that may impact firewalls upgrading to pfSense software version 2.5.0. Some of these were renamed or folded into other drivers, others have been removed, and more are slated for removal in FreeBSD 13 in the future.

Aliases/Tables

Authentication

Backup/Restore

Captive Portal

Certificates

Configuration Backend

Configuration Upgrade

Dashboard

DHCP (IPv4)

DHCP (IPv6)

DHCP Relay

Diagnostics

DNS Forwarder

DNS Resolver

Dynamic DNS

Gateways

Hardware / Drivers

IGMP Proxy

Installer

Interfaces

IPsec

IPv6 Router Advertisements (RADVD)

L2TP

LAGG Interfaces

Logging

Multi-WAN

NAT Reflection

Notifications

NTPD

OpenVPN

Operating System

Package System

PPP Interfaces

PPPoE Server

Routing

RRD Graphs

Rules / NAT

S.M.A.R.T.

SNMP

Traffic Graphs

Traffic Shaper (ALTQ)

Traffic Shaper (Limiters)

Translations

Upgrade

UPnP

User Manager / Privileges

Virtual IP Addresses

Web Interface

WireGuard

Wireless

Development

XMLRPC