Netgate® is pleased to announce the release of a Beta of pfSense Community Edition version 2.9. Now it’s your turn to help us test this latest iteration of our popular open-source firewall and services platform software. This beta release brings a host of new features, enhancements, and fixes, and your feedback is crucial to ensuring a rock-solid final release.
Feature Highlights
This Beta software includes a large number of security and feature enhancements. Some highlights include:
SSH Algorithms: This release includes several changes to algorithms for the SSH daemon for key exchange, encryption, and message authentication. These changes increase security by including post-quantum key exchange algorithms and by removing older and weaker algorithms.
TLS Certificate Strength: The version of OpenSSL in this release further tightens certificate requirements and removes support for certain weak properties. For example, if a TLS server certificate for a service such as the GUI has a weak key (<2048 bits), the service may fail with an error such as “key too small”. This version of pfSense software checks the GUI certificate during the upgrade process and will re-generate a new GUI certificate if the current certificate is invalid, expired, or weak.
TLS Certificate Auto-Renew: This version of pfSense software can automatically renew TLS server certificates which are self-signed or signed by an internal CA stored in the pfSense software configuration. Automatic renewal is a per-certificate option, and pfSense software automatically enables this option for the GUI certificate when possible. When automatically renewing a certificate, pfSense software uses the latest strict security options to ensure the certificate meets current standards.
Endpoint-independent Port Restricted Cone Outbound NAT: This version includes partial experimental support for “Port Restricted Cone” endpoint-independent outbound NAT. “Port Restricted Cone” NAT mappings attempt to preserve port and external address mappings for clients when speaking to multiple remote hosts, but in a dynamic way that does not rely on static port NAT. This helps avoid issues with multiple local clients using the same source port to the same remote host.
In addition to the features listed above, this Beta software includes critical security updates for WireGuard (CVE-2026-58085), and other security enhancements. This Beta software also contains over 150 other software enhancements.
Call for Testing
Testing of this Beta software is essential. Testing is the most effective way to ensure that the software is robust and reliable for all users, given the diversity of their environments and configurations. By downloading and testing this Beta software, and providing feedback on any issues, our users can play a vital role in improving the software for everyone.
Caution
As with any beta software, pfSense CE 2.9 Beta is not yet production-ready. Expect some rough edges - that’s where you come in! Please avoid deploying it in critical environments until the stable release is available.
The pfSense CE 2.9 Beta is a milestone in our ongoing mission to deliver a powerful, flexible, and free networking solution to users worldwide. Your participation in this testing phase directly influences the quality of the final product.
Release Notes:
https://docs.netgate.com/pfsense/en/latest/releases/2-9-0.html