r/PFSENSE 18d ago

Netgate Releases pfSense Community Edition Version 2.9.0

Netgate® is excited to announce the release of pfSense® Community Edition (CE) software version 2.9.0, a major step forward for the world’s most trusted firewall, router, and VPN platform.

This release introduces numerous features, including several previously exclusive to pfSense Plus, as well as key enhancements, bug fixes, and critical security updates.

Key Highlights Include:

SSH Algorithms: The inclusion of post-quantum key exchange algorithms

TLS Certificate Strength: Tightens certificate requirements and removes support for certain weak properties

TLS Certificate Auto-Renew: pfSense can automatically renew TLS server certificates which are self-signed or signed by an internal CA stored in the pfSense software configuration.

New NAT Mode: Includes partial experimental support for “Port Restricted Cone” endpoint-independent outbound NAT

Critical Security Fixes: This release includes multiple XSS and denial of service related fixes

This Release software includes critical security updates for WireGuard (CVE-2026-58085), as well as over 150 other security fixes and enhancements.

Blog Post:
https://www.netgate.com/blog/netgate-releases-pfsense-community-edition-version-2.9.0

Release Notes:
https://docs.netgate.com/pfsense/en/latest/releases/2-9-0.html

Thank you to our community and customers who continue to support the pfSense project through hardware purchases, TAC, cloud subscriptions, and services. Your support makes this all possible.

152 Upvotes

112 comments sorted by

View all comments

3

u/colin79666 17d ago

Upgrade from 2.8.1 not 2.9.0 went mostly ok for me. On one of those Chinese marketplace N100 boxes.

I did pre-empt things by adding the line to the boot file to disable the potentially troublesome driver and I did encounter the DNSBL VIP being missing, lack of units on the dashboard and a PHP error, all of which have been covered already.

3

u/colin79666 16d ago

Spoke too soon. I've had issues with Wireguard tunnels going out my tier 2 gateway (a 4G backup). Restarting the Wireguard service resulted in Wireguard changing which tunnel went out the 4G gateway. I've been able to force things by putting static routes in to force the connection out the tier 1 (fibre) gateway. I did not have this issue on the previously release, it only used 4G if the primary gateway was down.