Free to update; Free to upgrade on original Netgate hardware.
Please call us when you need pfsense+ version 25.11 on own infrastructure ...
pfsense+ v25.11 New Features and Changes
dedicated for Netgate firewall appliances
General
Base OS updated to FreeBSD 16-CURRENT
OpenSSL upgraded to 3.5.3
OpenSSH upgraded to 10.0p2
PHP updated to 8.4
VXLAN interface support has been re-added
Endpoint-independent Port Restricted Cone Outbound NAT
This version includes partial experimental support for “Port Restricted Cone”
endpoint-independent outbound NAT. This functionality must be manually enabled
on a per-rule basis.
“Port Restricted Cone” NAT mappings attempt to preserve port and external
address mappings for clients when speaking to multiple remote hosts, but in a
dynamic way that does not rely on static port NAT. This helps avoid issues with
multiple local clients using the same source port to the same remote host. These
rules enable a client communicating with multiple remote hosts using the same
source port to receive the same external IP address and port on outbound
connections to any destination. This behavior facilitates use cases such as
online gaming, peer-to-peer connections, and VoIP.
Inbound communication from a remote host and port is only possible after a local
client initiates first contact to that remote host and port. While this is more
secure, it is not yet capable of “full cone” NAT which some use cases may
require such as certain types of online gaming.
pfSense Plus
Changes in this version of pfSense Plus software.
Dynamic DNS
Added: Preserve other record types when updating IPv4 or IPv6 using deSEC DDNS #12495
Fixed: Dynamic DNS does not use preferred VIP in Gateway Group #16326
Fixed: Custom Dynamic DNS services ignore the monitor interface #16368
Hardware / Drivers
Fixed: Netgate 2100/3100 LED controller not responding to gpioctl #16526
Fixed: QLink/Marvell 41000 NIC bug #16248
Added: Support 2.5G SGMII (SFP GPON ONT) in bxe driver (QLogic NetXtreme II BCM57810) #16321
Fixed: e1000 network interfaces unexpectedly link at half-duplex #16449
IPv6 Router Advertisements (radvd/rtsold)
Interfaces
Added: VXLAN Interfaces #11732
Added: Option to change QinQ ethertype to Service VLAN Tag #13340
Fixed: Retain previous QinQ VLAN tag type value for existing entries on upgrade #13622
OpenVPN
Fixed: Automatic IPv6 gateways for OpenVPN servers are created with the wrong gateway address #16351
Fixed: OpenVPN servers will not start with DH parameter lengths less than 2048 #16421
Fixed: OpenVPN does not include client-to-client in generated configuration for Peer-to-Peer SSL/TLS servers #16428
PPP Interfaces
Changed: Sanitize PPPoE configuration parameters #16128
Fixed: PPPoE interfaces using if_pppoe increase error counters due to normal ALTQ traffic shaping operations #16216
Fixed: Virtual IP addresses on PPPoE interfaces using if_pppoe can prevent PPP session termination #16487
Rules / NAT
Added: Allow floating rules using the “match” action to match based on IP Options #16215
Added: Block non-global NAT64 addresses by default #16241
Changed: Refactor PF ruleset generation #16307
Added: Avoid traffic stalls from unnecessary filter reloads #16308
Fixed: NAT64 rules using reply-to do not forward packets #16429
Fixed: Filter rule evaluation continues after matching a match quick rule #16475
Added: Support state killing on gateway recovery for policy-routed traffic from the firewall itself #16502
Added: Endpoint-independent Port Restricted Cone Outbound NAT rules #16517
Fixed: NAT64 rules do not pass traffic when a gateway is specified for the rule #16546
Changed: Update output and parsing behavior for PHP shell pfanchordrill #16551
Traffic Shaper (Limiters)
User Manager / Privileges
Fixed: sshguard does not trigger for GUI logins from usernames containing unexpected characters #16312
Fixed: GUI login events from usernames containing special
characters or long strings can cause ambiguous or confusing log messages
#16314
end.