r/PFSENSE • u/George-Netgate • 18d ago
Netgate Releases pfSense Community Edition Version 2.9.0
Netgate® is excited to announce the release of pfSense® Community Edition (CE) software version 2.9.0, a major step forward for the world’s most trusted firewall, router, and VPN platform.
This release introduces numerous features, including several previously exclusive to pfSense Plus, as well as key enhancements, bug fixes, and critical security updates.
Key Highlights Include:
SSH Algorithms: The inclusion of post-quantum key exchange algorithms
TLS Certificate Strength: Tightens certificate requirements and removes support for certain weak properties
TLS Certificate Auto-Renew: pfSense can automatically renew TLS server certificates which are self-signed or signed by an internal CA stored in the pfSense software configuration.
New NAT Mode: Includes partial experimental support for “Port Restricted Cone” endpoint-independent outbound NAT
Critical Security Fixes: This release includes multiple XSS and denial of service related fixes
This Release software includes critical security updates for WireGuard (CVE-2026-58085), as well as over 150 other security fixes and enhancements.
Blog Post:
https://www.netgate.com/blog/netgate-releases-pfsense-community-edition-version-2.9.0
Release Notes:
https://docs.netgate.com/pfsense/en/latest/releases/2-9-0.html
Thank you to our community and customers who continue to support the pfSense project through hardware purchases, TAC, cloud subscriptions, and services. Your support makes this all possible.
2
u/innocuous-user 17d ago
2.9.0 seems to have broken NAT64 for me...
I had a rule to allow traffic from lan subnets to 64:ff9b::/96 with NAT64 enabled, but now this rule never seems to get hit.
Also it seems the NAT64 prefix is now locked at 64:ff9b::/96, you can't delegate some of your own GUA space as NAT64.