IPFire 2.29 Core Update 199 strengthens network and Wi-Fi security

  • New support for Wi-Fi 6 and Wi-Fi 7 with more control over wireless modes and SSID protection enabled by default.
  • Improved network visibility thanks to LLDP and CDPv2 integrated into the web interface for multi-switch environments.
  • Strengthening security with Suricata 8.0.2, mitigating vulnerabilities in the proxy and adjusting firewall rules and web filtering.
  • Massive update of key packages such as OpenSSL, OpenSSH, FFmpeg, Samba, Tor and other network and security components.

IP Fire 2.29 Core Update 199

The new IPFire 2.29 Core Update 199 is now available and represents a significant revision of this Linux-based firewall distribution, widely used as a router and dedicated firewall. The update focuses on strengthening security, improving the management of next-generation wireless networks, and refining several critical functions for the daily administration of professional networks.

With this launch, IPFire takes another step towards adapting to increasingly complex network environments, where high-speed Wi-Fi, advanced segmentation, and stringent monitoring requirements coexist . Although it is a global project, many of the new features are particularly relevant for security and network operations teams in Spain and the rest of Europe, where the deployment of Wi-Fi 6 and Wi-Fi 7 and regulatory pressure on cybersecurity are constantly growing.

Support for Wi-Fi 6 and Wi-Fi 7 with more control

One of the most noticeable changes in IPFire 2.29 Core Update 199 is the addition of native support for Wi-Fi 6 and Wi-Fi 7 standards . The system now allows you to select your preferred wireless mode and can automatically detect the capabilities of your installed hardware, enabling compatible features without requiring overly complex manual configurations.

The update also enables SSID protection by default , a measure designed to strengthen the security of wireless networks against various types of attacks and spoofing. In addition, it incorporates the ability to convert multicast packets to unicast packets by default, which can improve efficiency and stability in certain Wi-Fi deployments, especially in networks with a large number of clients.

Another new feature related to the wireless component is background radar detection , key to complying with regulations on the use of the radio spectrum, something especially relevant in Europe. This function helps avoid interference with priority systems operating in certain frequency bands, aligning the platform with regulatory requirements.

Greater network visibility with LLDP and CDPv2

In corporate and service provider environments, visibility into what connects to what is critical. That's why IPFire 2.29 Core Update 199 integrates native support for LLDP (Link-Local Discovery Protocol) and Cisco Discovery Protocol version 2 directly into its web interface, within the dedicated LLDP services section.

Thanks to this integration, the firewall can identify network devices connected to its interfaces and, more importantly in large installations, determine which switch ports they are connected to. This information can feed network monitoring and inventory tools used in large deployments, facilitating diagnostics, auditing, and topology reorganization.

For administrators managing multiple sites, communications closets, or data centers, having this data centralized in IPFire's own web interface helps reduce intervention times and minimize errors when modifying physical connections or making changes to the configuration of adjacent switches and routers.

Kernel update and system core changes

The development team has updated the Linux kernel used by IPFire, bringing it to version 6.12.58 . This update incorporates numerous stability and security fixes from the Linux ecosystem, resulting in more robust firewall performance, especially under load or in scenarios with highly varied traffic.

Along with this core update, a significant change has been made to the initramfs generation system: the dracut tool has been replaced by dracut-ng , after the original project was abandoned by its lead maintainer. This move aims to ensure long-term maintainability and greater adaptability to future platform changes.

Furthermore, the D-Bus daemon now runs by default in IPFire, paving the way for future enhancements and new features that can leverage this internal communication bus. These kinds of adjustments aren't always immediately apparent, but they are often essential for incorporating more advanced functionality without compromising stability.

Strengthening the intrusion prevention system (IPS)

In terms of security, IPFire 2.29 Core Update 199 updates its intrusion prevention system engine to Suricata 8.0.2 . This version introduces fixes related to alert handling and reporting system behavior, critical elements for security teams that rely on this data to respond to incidents.

The IPS reporting schedule has also been adjusted, so that reports are now always sent at 1:00 AM . This decision aims to standardize and simplify daily review tasks, allowing for a more predictable routine for teams analyzing events outside of normal business hours.

Additionally, an issue has been resolved where the new reporting functionality could miss some alerts when the internal SQLite database was busy . This fix is ​​especially relevant for organizations that require the most comprehensive log possible of security events, as it reduces the risk of suspicious activity going undetected in high-load scenarios.

Improvements to OpenVPN and remote connectivity

IPFire is widely used for remote access and site-to-site VPN connections, so the project has also introduced changes to its OpenVPN implementation . Among the new features is the ability to send clients multiple DNS and WINS servers, facilitating more flexible configurations for resolving names on networks with different internal domains.

The OpenVPN server can now operate in multi-home mode permanently , which is useful in cases where the firewall has multiple WAN interfaces or outbound routes, something common in companies that combine different connectivity providers to gain resilience.

In addition, the directive has been removed from the client configuration files. auth-nocache, considered ineffective in this context. A problem that could have prevented the first custom route The information defined by the administrator will be correctly distributed to clients, thus avoiding unexpected behavior in more complex topologies.

Adjustments to the web interface and operational management

The browser-based administration interface, a key tool for many technicians, incorporates several improvements to make it clearer and more reliable. The notification message that appears when the system is not compatible with SMT (Simultaneous Multithreading) has been refined , providing the administrator with a more precise explanation of this hardware limitation.

In the email section, IPFire 2.29 Core Update 199 improves the handling of credentials that include special characters , reducing issues when configuring notification systems or sending alerts via email. These types of issues are common in corporate environments where complex password policies are in place.

A bug that prevented the creation of new location groups on the firewall page has also been fixed . This is an important element when organizing rules by region, IP range, or different security zones. For administrators who segment traffic based on geographic origin or network function, this fix simplifies management and avoids the need for compromise solutions.

Proxy security mitigations and race condition correction

In the proxy area, the new version includes a specific mitigation for the vulnerability identified as CVE-2025-62168 . This measure strengthens protection against potential attacks that exploit this vector, a point to consider for organizations that use IPFire's proxy as a core component of web traffic filtering.

Several race conditions that could cause erratic behavior have also been resolved . One of these could force the termination of the URL filtering process during database compilation, directly impacting the ability to block unwanted or malicious sites.

Another race condition that was fixed affected the application of firewall rules , allowing previously applied rules to be overridden when a new one was inserted. These types of errors are particularly critical, as they can create temporary gaps in network security policy if not detected promptly, making their resolution a significant improvement in operational reliability.

Update of key packages and components

In addition to functional changes, IPFire 2.29 Core Update 199 includes a massive update of packages and plugins. Notable updates include FFmpeg 8.0 for multimedia processing, ClamAV 1.5.1 as an antivirus engine, GNU nano 8.7 as a text editor, Samba 4.23.2 for file and print services in mixed environments, and Tor 0.4.8.19 for anonymous communications.

In the area of ​​networking and security, the update includes Fetchmail 6.5.7, cURL 8.17.0, OpenSSL 3.6, SQLite 3.51.0, OpenLDAP 2.6.10, OpenSSH 10.2p1, and BIND 9.20.16 , among others. These versions also incorporate their own security fixes and performance improvements, which is especially relevant for organizations that must comply with regulations and best practices regarding software updates.

The suite of add-ons is expanded with new tools, including dma , a utility designed to create local mailboxes. These additions allow IPFire to be better adapted to environments where it's necessary to log and distribute notifications or messages internally without deploying heavier email solutions.

Availability and installation options for different architectures

IPFire 2.29 Core Update 199 is now available for download from the project's official website in ISO and USB image formats. The update maintains support for x86_64 (64-bit) and AArch64 (ARM64) architectures, enabling its deployment on both traditional servers and appliances, as well as on ARM-based platforms, which are gaining traction in Europe, particularly in low-power environments and dedicated devices.

For those already using IPFire in production, the update is part of the regular Core Updates channel and can be applied following standard distribution procedures. However, as with any major version change, it is recommended to back up your configuration and plan an appropriate maintenance window to minimize the impact on end users.

In the case of new installations, the availability of images prepared for different media makes it easier to test IPFire in laboratories, small offices or pilot deployments before fully integrating it into critical network infrastructures.

With this package of changes, IPFire 2.29 Core Update 199 consolidates itself as a more mature option to act as a firewall and router in modern networks, combining support for next-generation Wi-Fi, reinforcements in the intrusion prevention system, security mitigations in the proxy and a broad renewal of key components , all aimed at offering a more stable platform prepared for the current cybersecurity needs in Spain and the rest of Europe.

OpenSSH 10.1
Related article:
OpenSSH 10.1: Everything new in security, networking, and configuration

Add as preferred source in Google