Netgate has recently released the latest version 2.9.0 of pfSense Community Edition, a distribution kit for building firewalls and network gateways. Based on FreeBSD and incorporating developments from the m0n0wall project and the pf packet filter, pfSense CE 2.9.0 can be downloaded using the installer available on the Netgate website.
The distribution package is managed through a web interface, providing functionality for user access control on both wired and wireless networks. Features such as Captive Portal, NAT, VPN (IPsec, OpenVPN), and PPPoE are available for use. Users can limit bandwidth, connections, filter traffic, and set up fault-tolerant configurations using CARP. The system displays operation statistics in graphical or tabular formats and supports authorization through local user bases, as well as via RADIUS and LDAP.
The main changes in this release include updating base system components to FreeBSD 16-CURRENT and upgrading program versions such as PHP 8.5, OpenSSL 3.5.7, OpenSSH 10.3p1, Kea 3.0.2, Unbound 1.24.2, and strongSwan 6.0.3. The SSH server now supports post-quantum encryption algorithms and disables outdated cryptographic algorithms.
Support for cryptographic keys less than 2048 bits in length has been discontinued. The system will automatically generate and install new certificates if untrusted or expired web interface access certificates are detected during updates. Additionally, a new function has been added to automatically extend the validity period of self-signed certificates or those issued by the built-in certification authority.
Experimental support for the new “Port Restricted Cone” address translation mode has been included in this release. This feature enables dynamic mapping between a client’s source port and the external IP address, particularly useful in scenarios where multiple clients use the same source port number when connecting to the same host.