Free to update; Free to upgrade on original Netgate hardware.
Please call us when you need pfsense+ version 25.07 on own infrastructure ...
Netgate/pfsense plus, version 25.07 New Features and Changes
This is a regularly scheduled software release including new features and bug
fixes.
Security / Errata
This release fixes several security issues in pfSense Plus software, including:
Netgate pfSense Plus version 25.07 update notes
Changes in this version of pfSense Plus software.
Auto Configuration Backup
Fixed: Long configuration revision reasons can cause AutoConfigBackup upload to fail #12249
Fixed: Potential XSS in AutoConfigBackup backup list on services_acb.php #15927
Fixed: AutoConfigBackup remote revision timestamps may not be unique due to batch uploads #16011
Fixed: “Reset” button on AutoConfigBackup Restore tab does not submit the form #16012
Changed: AutoConfigBackup code cleanup and GUI refresh #16013
Added: Download function for AutoConfigBackup entries #16014
Added: Method to change the AutoConfigBackup device key #16015
Changed: Change AutoConfigBackup default key generation format #16016
Fixed: AutoConfigBackup entries show incorrect timestamps #16209
Captive Portal
Fixed: PHP error in Captive Portal with undefined zone interface list #15907
Fixed: Captive Portal does not function with MAC filtering disabled #15926
Fixed: Captive Portal service management via pfSsh.php svc fails when the zone name contains uppercase letters #16030
Fixed: Creating a Captive Portal zone with uppercase letters overwrites existing zones of the same name #16032
DHCP (IPv4)
Added: Kea DHCP Custom Configuration Support (IPv4 and IPv6) #15321
Fixed: Kea fails to start if DHCP pool configuration contains default lease time or max lease time #15332
Added: Kea Static ARP Support (IPv4 only) #15654
Fixed: Kea can unintentionally attempt to spawn multiple processes and fail #16019
Fixed: Static lease DNS records are incorrectly removed when backing lease expires #16022
Dashboard
Fixed: Clicking the picture widget image downloads the image with an invalid filename instead of showing it inline #15767
Fixed: Dashboard widgetkey values are not validated on save or load, can lead to configuration corruption or other problems #15844
Changed: Improve the system load impact from Dashboard widgets #15969
Fixed: Potential XSS in OpenVPN Widget #16258
Diagnostics
Fixed: Adding Wake-On-LAN entry from ARP table view can incorrectly include OEM text in MAC address field #15162
Fixed: PHP error from invalid IPv6 address on diagnostics_ping.php #16005
Fixed: The filtered states shown may include states for interfaces other than the selected interface #16043
Fixed: Cannot kill states using the post-NAT address #16047
Fixed: Memory leak in pftop #16347
Dynamic DNS
Added: Improve Dynamic DNS client IPv6 support #11177
Added: Per-instance options to control Dynamic DNS client Check IP Service behavior #14067
Fixed: Dynamic DNS uses the default gateway interface instead of the specified interface #14605
Added: Support LuaDNS provider #15089
Changed: Update Gandi LiveDNS service with API changes #15258
Fixed: RFC 2136 Dynamic DNS cannot update AAAA records over IPv6 #16028
Fixed: Dynamic DNS IP address may not be updated after changing the interface of a Dynamic DNS entry #16046
Fixed: Dynamic DNS fails to update AAAA record for Route53 and No-IP services #16249
Changed: Update list of Dynamic DNS services that are only reachable over IPv4 for AAAA record updates #16251
IPsec
Fixed: Input validation for duplicate remote gateways does not work when using the duplicate P1 button #15598
Fixed: Firewall generates invalid rules for IPsec tunnels with descriptions containing special symbols #16095
Fixed: Potential XSS in IPsec Phase 1 #16115
Fixed: IPsec unnecessarily prompts to apply changes after input errors #16162
IPv6 Router Advertisements (radvd/rtsold)
Fixed: Incorrect warning from radvd about AdvRDNSSLifetime value #12938
Added: PREF64 support in Router Advertisements #15808
Fixed: Routing Advertisements daemon fails to start when configured with more than 3 RDNSS entries in a prefix #15876
Interfaces
Fixed: Config access error with null static routes #16104
Fixed: Config access error after changing an interface from DHCP to Static #16105
Fixed: Using IPv4 VIPs on PPPoE interfaces with if_pppoe causes looping #16235
Fixed: PPPoE IPv6 gateways are unavailable without Router Advertisements when using if_pppoe #16265
Multi-Instance Management
OpenVPN
Fixed: OpenVPN Status Page and Dashboard Widget use input values without validation #15856
Fixed: Configuration upgrade from before revision 19.1 removes OpenVPN settings #15895
Fixed: Kernel panic in OpenVPN if_ovpn due to use-after-free of mbuf #16319
Operating System
Fixed: pftop core dump with ICMP states #15595
Fixed: Azure: User credentials entered during new VM deployments are not applied to the system #15871
Fixed: Values obtained from sysctl are sometimes unexpectedly empty, leading to PHP and other math errors #14648
Fixed: Errors on the console when starting/stopping services #15912
Fixed: RAM disk configuration check fails at boot #16023
Fixed: RAM Disk cron jobs are not saved correctly #16059
Fixed: Panic accessing sysctl OID net.inet.ip.nhdispatch with an INVARIANTS kernel #16081
Fixed: Kernel Panic in if_qlnxe kernel module when loaded via kldload #16101
Changed: Reduce writes to disk when using ZFS #16210
Added: Allow custom ZFS pool names #16212
Fixed: Panic in pf if the declared packet length is longer than the actual packet #16318
Fixed: Multiple removable filesystem panics #16320
Package System
Fixed: Deleting one pre-installed package may delete other pre-installed packages #15643
Fixed: The package post-install script does not run with a system upgrade on ZFS #16057
Changed: pkg no longer supports setting ALTABI manually at run-time #16060
Rules / NAT
Fixed: Separators for Ethernet rules span past the actions column #16079
Added: NAT64 support #2358
Fixed: SCTP states not purged causing subsequent SCTP INIT to be blocked #15924
Fixed: Incorrect rule may be opened for editing after rule order has changed #15935
Fixed: Tracking information for firewall rules is not shown when editing the rule #15936
Fixed: Warning message in logs when changing firewall rules after setting Require Firewall Interface #15961
Fixed: Deleting or adding a firewall rule may result in an unexpected rule order #16076
Fixed: Potential XSS in Firewall Schedules #16114
Fixed: Input validation prevents creating port forwards for the same port using a different address family #16130
Fixed: Firewall rules using interface subnet aliases may prevent filter rules from loading after upgrades #16182
Fixed: Firewall rules with an interface address for the NAT64 source always use the interface itself #16250
Fixed: Firewall rules are not performing source tracking when Sticky Connections option is enabled #16282
Traffic Shaper (Limiters)
Fixed: Limiters saved while MIM is enabled disappear after reboot #16051
Fixed: Input validation error when applying limiter changes #13158
Fixed: Setting a limiter queue length greater than 100 prevents the limiter from loading #13662
Fixed: Cannot add limiters named new #13687
Fixed: PHP error when a queue is added with the same name as a limiter #15914
UPnP IGD & PCP
Changed: Update UPnP IGD & PCP GUI text #15864
Changed: Make the UPnP IGD & PCP STUN port optional #15865
Fixed: UPnP IGD & PCP status page does not show “disabled” message after the service has been enabled then disabled #16274
Upgrade
Fixed: Upgrade available LED not set before branch is selected. #15880
Changed: Link to release information on the system update page #15953
Fixed: Boot loader is not upgraded on UFS installs #16064
User Manager / Privileges
Fixed: Users with Deny Config Write privilege can trigger some VLAN interface operations #15282
Fixed: Users with Deny Config Write privilege can trigger some QinQ interface operations #15318
Fixed: PHP error when a user is denied access to the dashboard #15873
Fixed: Users with Deny Config Write privilege can trigger logging operations #15874
Fixed: Users with Deny Config Write privilege can change their own password #15908
Web Interface
Added: Custom message text for the login screen #9293
Changed: Update nginx HTTP2 syntax #15863
Fixed: Incorrect color in button text within disabled rows #15977
Please call us when you need pfsense+ version 25.07 on own infrastructure