OPNsense 25.7.11 Enhances Network Visibility With Host Discovery Feature
The OPNsense team has announced the release of version 25.7.11, introducing a significant networking enhancement: a native host discovery service. This development improves visibility into connected devices and enhances policy control across the firewall.
The OPNsense team has announced the release of version 25.7.11, introducing a significant networking enhancement: a native host discovery service. This development improves visibility into connected devices and enhances policy control across the firewall.
The primary feature of version 25.7.11 is the host discovery service based on the hostwatch component. This service automatically resolves and retains MAC addresses for IPv4 and IPv6 hosts across connected networks. The data collected is integrated into key subsystems, including firewall MAC-based aliases and captive portal clients. This enhancement allows administrators to maintain accurate and timely knowledge of network devices and their identification at Layer 2.
The service is enabled by default but can be disabled for users who prefer manual privacy control. This flexibility supports various operational models, from home labs to enterprise environments.
This release also includes kernel-level fixes related to IPv6, improving address lifetime management, router advertisement processing, and IPv6 traffic handling behaviors.
Feature Category Component New Capability Description
Network Discovery Host Discovery Service Native MAC address resolution Resolves and remembers MAC addresses for IPv4/IPv6 via the hostwatch component
Network Discovery MAC Aliases Dynamic MAC data integration Firewall MAC aliases now use live host discovery data
IPv6 Stack Kernel IPv6 Address lifetime management Improves handling of address expiration checks and lifetime updates
IPv6 Stack Router Advertisements RA lifetime validation Ensures RA lifetime is checked before script execution
IPv6 Stack DHCPv6 Client Infrastructure preparation Prepares for major dhcp6c update in 26.1
The OPNsense team has announced the release of version 25.7.11, introducing a significant networking enhancement: a native host discovery service.
Core Migration ISC-DHCP Removal Plugin-based architecture ISC-DHCP is being removed from core; a plugin is available
System Security Safe Execution exec() call elimination Removes numerous exec() calls across system scripts
Certificate Management Trust Store DNS SAN preservation Properly fills DNS Subject Alternative Names from existing certificates
Firewall Automation ICMP Handling Protocol-aware options Adds multi-select ICMP6 options
Captive Portal Client Tracking Host discovery integration Utilizes host discovery for ARP table monitoring
VPN Services OpenVPN Client export enhancements Improves search functionality and reduces exec() usage
DNS Services Unbound Reporting and management Adds quick actions and UI layout fixes
Monitoring Suricata IDS Security update integration Updated to Suricata 8.0.3 for vulnerability fixes
Routing FRR Plugin Protocol enhancements os-frr 1.50 brings routing protocol improvements
IPv6 Proxy NDP Proxy Infrastructure updates os-ndp-proxy-go 1.3 improves IPv6 neighbor discovery
Monitoring Telegraf Metrics collection updates os-telegraf 1.12.14 includes updates and bug fixes
Kernel Network netlink subsystem Buffer management fixes Prevents overwriting existing data in linear buffers
Kernel Network pf firewall IPv6 divert packet handling Fixes handling of IPv6 divert packets
Kernel Network netmap Memory allocator control Memory allocator parameters now set via loader.conf
Interface handling has been enhanced to prefer longer address lifetimes when multiple exist. The update also refines PPP checks and adjusts "sharednet" tuning to the correct sysctls. These improvements lay the groundwork for the upcoming 26.1 release, which will feature a larger dhcp6c update. Additionally, version 25.7.11 marks the gradual removal of ISC-DHCP from the OPNsense core, with a replacement plugin available in the development branch.
Version 26.1-RC1 is anticipated early next week, followed by RC2, with a final 26.1 release targeted for Sun, Jan 28, 2024. This update also includes several enhancements across the firewall, services, and security stack, including improved ICMP/ICMPv6 handling, more robust captive portal handling, and enhancements in core services and security monitoring.
Based on reporting by GBHackers.
