Video summary
In August 2026, the pfSense ecosystem saw significant updates with the release of Community Edition version 2.9.0 and pfSense Plus 2607. The community edition focused primarily on security enhancements rather than visual overhauls, introducing post-quantum key exchange algorithms for SSH and deprecating weak TLS keys below 2048 bits to improve overall cryptographic strength. Additionally, a new experimental feature called endpoint independent port restricted cone outbound NAT was added to help resolve issues where multiple local clients share the same source port, alongside fixes for cross-site scripting vulnerabilities and a specific WireGuard CVE. While these updates are beneficial, administrators are reminded to check hardware compatibility notes before upgrading, as certain tunable settings may need adjustment prior to the update process.
The major shift in this release cycle is centered on pfSense Plus, which introduces the Nexus interface—a unified management system designed for multi-instance environments. This new GUI integrates threatgate and core DNS components, offering a modernized dashboard that allows users to manage multiple pfSense instances from a single location without requiring extra licenses for the base system itself. The interface retains a layout similar to the legacy version to minimize the learning curve, though some advanced options in firewall rules are now hidden behind an "advanced" toggle. A standout security feature within this new ecosystem is the zero trust egress mode in core DNS, which restricts outbound connections to only those remote hosts that have been resolved via DNS, effectively preventing systems from initiating direct IP-based connections to suspicious command and control servers.
Despite these technological advancements, the creator notes a decline in pfSense-related content production due to real-world shifts in their professional life. Having sold their managed services business in late 2025, they no longer manage large fleets of pfSense systems, which has reduced the practical, real-world experience that typically informs their video topics. Furthermore, since the community edition changes are relatively minor and the new pfSense Plus features are not yet deployed in their primary lab infrastructure for daily use, there is less incentive to produce immediate review content. The creator emphasizes a preference for demonstrating genuine, large-scale use cases over isolated lab tests, leading to a more selective approach to video creation that reflects the current state of the industry in 2026.
Read the full video transcript
It is August of 2026 and PFSense
community edition version 2.9.0 has been
released as well as pfSense plus 2607.
I'm going to talk about the changes in
these versions which there's not much
for the community edition. There's a
changes coming for the pfSense plus.
They've added some features but there's
some bigger changes with the way they're
doing the new Nexus interface that I
want to talk about and I'll also address
the bigger picture overall status of
PFSense as I see it. And too long didn't
watch. I'm not telling anyone to stop
using pfSense, but I'm also going to
address why I don't make as many videos
about pfSense in this video. So, let's
get started. I want to start with the
Netgate PFSense community edition 2.9.0.
So, this is the community
edition/opensource
edition. And there's not a lot to
visually show you here. They updated the
SSH algorithms to have postquantum key
exchange algorithms. So, better strength
and security there. They are deprecating
weak keys lower than 2048 bits. So
that's good on TLS key certificates. You
uh should note though if you're using an
older less than 248 bit key. You'll get
an error in the system. So easy enough
to generate these for self-signed. And
on the same topic of self-signed
certificates, TLS certificate autorenew.
Now this is separate from the Acme
system that will do like let's encrypt
and other automations for renewals. This
is specifically to be able to autorenew
a self-signed search. So that's great
because some people would have that
question of hey my self-signed
certificates expiring. how do I fix it?
And if you read the manual at all, it'll
show you there's a little icon with a
circle on it. You click it and it'll
renew. Now, that can be done
automatically. They have a new
experimental feature called endpoint
independent port restricted cone
outbound NAT. It's kind of a mouthful,
but for very specific use cases, this
helps avoid issues with multiple local
clients using the same source port and
the same remote host. So, this is an
experimental feature, not something I've
done any testing on. I've also just not
run into this as an issue, but I do know
if you spend time in the forums, there's
some discussion on this. There's a
handful of
minor really, but still important
crossite scripting and a CVE 202658085
uh for wireguard fix. So once again, it
was not, you know, hair on fire, but
definitely things that need to be fixed.
So this is a good update for anyone
updating uh to the new version. No
reason not to. Uh there is some hardware
arata. If you happen to have some
specific hardware, there's a specific
tunable that they ask you to set prior
to update. So always make sure to read
through that. And there is a process,
and I've covered this before and have
videos on it, of how to update PFSense.
That process really hasn't changed. Now,
before we get to the PFSense Plus
release, we do have to talk about what
was released just before then, and it's
the announcement of the new guey for
PFSense Plus, which it's not exactly
new. It's new, but not exactly new is
because I covered it before. It's just
the Nexus gooey. They're putting a lot
more into that. Now, the Nexus system is
the multi-instance management system,
but also updated UI for PFSense. So,
it's both at the same time. And I've
covered this in the previous update that
yes, if you're using multi-instance
management, you do need for managing
multiple pfenses a license for each
pfSense. Now, not your pfSense plus
license that comes with the hardware or
that you can buy, but a separate
multi-instant manage system, but you
automatically get essentially one free
license which is to manage that pfsense
system itself. And I'll show that in a
minute here, but this just lets you know
that there is the new and updated guey
and it also includes threatgate. We're
going to talk about that in a moment. Um
because if you're digging into
Threatgate and they answer it very
clearly here, Threatgate is the
evolution of PF Blocker NG redesigned
for modern threat landscapes and
optimized for performance. So there's a
couple components here and I'll leave
links to all these so you can read
through them. And uh let's actually jump
over to that new release because the new
features is core DNS and Threadgate.
These two pieces work together to give
you higher performance DNS and the
ability to load really large groups
together for massive amounts of block
lists and still being performant even on
a system that is not well resourced. So
this is why they say it's an evolution
of PF Blocker NG. By the way, this is
nothing that's coming to PFSense CE.
This is all functions only found in
PFSense Plus. So they also have Snort
version 3. And uh let's talk about using
the new guey. So that's the big thing
here. If we going to go to the tried
true tested guey that I've done most of
my videos on. If we go here to the
advanced neck 8 Nexus, this is the same
thing I showed when I showed how to set
up Nexus uh in my previous video. And
you just enable it. You can choose an
port other than 8443 if you want. I'm
going to leave it at 8443. And then you
can access that URL. And it brings you
to the Nexus dashboard. And if you
haven't seen it before, you can open up
the device management view. Even if you
had multiple pfSenses added here, the
way the multi-instant management works
in PFSense is you choose your PFSense
that you want to be the holder of all
the other pfSenses essentially. And this
is that bridging where you connect them
all into Nexus and you add all of the
systems in and then you would be able to
control all your instances of PFSense in
one place. It lets you pull up the
console and this is the one local one.
So I'm not needing any extra license for
this. Uh here's the open the settings
for it or let's click here and go to the
new UI. Now the new UI is laid out very
similar to the old UI. So you're not
going to be too lost here. The firewall
rules look very similar. So we go to
rules. We have this little uh bar at the
bottom that lets us add the rules, etc.
So not really substantially different.
There's not this huge learning curve to
start using this interface. I will point
out this. If we go over here to services
and we want to look at like core DNS or
if we look at the threat gate, they're
both here. But let's jump back over and
I want to make sure it's clear. Those
are not in this same system under
services. So they're new components are
being added to the new UI but are not in
the legacy UI. So I can still see those
same firewall rules and changes are one
and the same. So if I add or change
something here, it's going to be the
same over in the Nexus UI. But just for
clarity, they're pushing to that new UI
for management. And that is where you
should be making changes and finding any
challenges you may find and reporting
them back so that this can be updated.
But it's reaching a more featurelete uh
way to do things. I don't know anything
that's specifically not in here. I
didn't go over it with a fine tooth
comb, but it seems to be completely
functional for the usual things you may
do in pfsense such as firewall rules,
VLANs, etc. all the features seem to be
here and if any of them or something
specific isn't uh head over to the old
guey. I will say on the firewall rules
something that may not be obvious
immediately is when you're creating a
new rule if we go here and we'll add to
the rule list the extra options uh you
just have to hit display advanced down
here to get all those extra advanced
options that are just kind of below the
fold when you're doing it in the other
UI. So all this seems to work perfectly
fine. I didn't really do much in-depth
testing but so far so good. I kind of
like the new UI. Um, let me know in the
comments down below if you do or not.
Now, coming back over to Threatgate, I
want to talk about this here.
Configuring core DNS zero trust egress
mode. Zero trust egress mode in core DNS
enables administrators to restrict
access to only the remote hosts that
have resolved via core DNS. This is
accomplished with connection tagging
handled internally by core DNS and
manual firewall rules. So, they have a
whole write up on how this works. This
is clever and I've heard it referred to
as do not talk to strangers. And what
that means is a host behind pfsense with
this feature enabled reaches out and
this would be the normal process. We
resolve a website that website has to be
turned into a IP address. So that DNS
name launchsystems.com gets turned into
an IP and then the system will go and
resolve it and can go to the website
launchystems.com. But what if you were
to just go to an IP address? Well,
ideally you don't want it to. And the
reason for that is it is common and let
me go all the way back to a old post
here. Uh this is dating back to June
13th of 2017 when uh John Todd had
posted this in the PFSense forums.
There's a really common thread
especially more so in 2017. It still
exists here today. It's just a little
bit less common but it's the idea that
thread actors frequently use just IP
addresses for command and control
servers or you know random things that
pe people may have set up that just
reach out. it becomes suspicious. So you
want to know why isn't it trying to
resolve the DNS and you should have
things resolving the DNS because you
think things should be following the DNS
and looked at a suspicious one or just
going to an IP address. This is a way to
block those and then you could always
look through the block logs and try to
figure out what's reaching out to IP
only or why is it reaching out to IP
only and solve that on a case-by case
basis. So this is actually something in
2017, John T, if the name's not
familiar, he is the CTO over at Quad9.
and I've had them on the channel and
talked about how much I like Quad9 a few
times, but this is a cool security
feature and as I said, it really
probably was a much bigger deal in 2017,
but you know, old attacks are still
happening here in 2026. So, this can be
an extra layer of protection that you
can add by turning the feature on that
now exists in PFSense Plus with
Threatgate Plus Core DNS. And they have
a right up here on how to do that.
Now, to talk about why I don't make as
many PFSense videos. For those of you
that haven't been following the channel
closely or any of the things that I do,
I sold off the managed services side of
my business in November of 2025.
Therefore, I'm not managing a bunch of
PFS systems anymore. That means there's
not a lot of videos that are going to be
based on my real world experience
because I'm having less real world
experience. I still offer consulting,
but I've also just seen a decline in the
consulting calls requested for PFSense.
So, I still have people I talk to. I
still have people I help in that realm.
I still know a lot of people using it in
the industry, but I just don't have as
much interaction with it. Second thing
is because and as I mentioned with
PFSense CE, there's not really any big
changes to talk about. That means a
video on OpenVPN from several years ago
outside of those old ciphers that I
wasn't recommending then now not being
available to choose. Well, that's the
difference between a video done in
several years ago and a video done
today. And I don't make content just for
the sake of making content. So, it's
kind of led to a decline in the number
of videos I produce. And that's just the
reality of where we are here in 2026. I
guess I could consider making some
videos on the new Neckgate PFSense Plus
version with the Threatgate and the Core
DNS, but I'm not actively using it
myself. Therefore, I have this set up in
my lab only. And just showing you how to
set something in a lab maybe of limited
value because I want to know what the
reality is. And I'm not swapping out all
my stuff just to test it and see if I
run into problems with that particular
feature cuz it's not a feature that I'm
excited to run out and implement and
swap all of my network infrastructure
over just to try. I can try it in a lab,
but I think labs are well somewhat
limited. I really try to bring on this
channel realworld use cases for the
things I do, not just some lab test.
That's uh what you can get with a lot of
other channels. I try to bring a little
bit more in depth on that whenever
possible, whenever reasonable from any
of the videos or content that I make.
But I love hearing from you. What are
your thoughts on current status of
PFSense here in 2026? Leave those
thoughts and comments down below. Head
over to my forums, forums.
For a more in-depth discussion on this
topic, or connect with me on the socials
and reach out to me via lawsystems.com.
Easy place to find me. I'm not that hard
of a person to uh share your opinion
with and send me an email if you like.
All right. Intex. [music]
[music]
>> [music]