{"id":174293,"date":"2025-06-23T10:08:01","date_gmt":"2025-06-23T10:08:01","guid":{"rendered":"https:\/\/linuxiac.com\/?p=174293"},"modified":"2025-06-23T10:23:49","modified_gmt":"2025-06-23T10:23:49","slug":"ipfire-2-29-core-update-195-firewall-brings-native-wireguard-support","status":"publish","type":"post","link":"https:\/\/linuxiac.com\/ipfire-2-29-core-update-195-firewall-brings-native-wireguard-support\/","title":{"rendered":"IPFire 2.29 Core Update 195 Firewall Brings Native WireGuard Support"},"content":{"rendered":"\n<p>IPFire, a free, open-source Linux-based hardened firewall designed to be deployed as a dedicated firewall\/router system for protecting network environments, has issued IPFire 2.29 \u2013 Core Update 195.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>WireGuard Finally Lands in IPFire<\/strong><\/h2>\n\n\n\n<p>WireGuard\u2019s arrival has been on administrators\u2019 wish lists for quite some time, and for good reason. The protocol keeps configuration overhead low while providing performance that often rivals\u2014or outpaces\u2014IPsec and OpenVPN.<\/p>\n\n\n\n<p>In IPFire 2.29, WireGuard is fully integrated into the <a href=\"https:\/\/linuxiac.com\/how-to-set-up-wireguard-vpn-with-docker\/\">web-based GUI<\/a>, allowing operators to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Stand up both <em>net-to-net<\/em> and <em>host-to-net<\/em> (road-warrior) tunnels.<\/li>\n\n\n\n<li>Manage multiple peers, each with its own granular settings.<\/li>\n\n\n\n<li>Export configurations or on-screen QR codes for painless mobile device onboarding\u2014scanning a code beats copy-pasting preshared keys daily.<\/li>\n\n\n\n<li>Import third-party WireGuard profiles for cross-vendor interoperability.<\/li>\n\n\n\n<li>Leverage IPFire\u2019s Intrusion Prevention System (IPS) and connection tracking to filter and log VPN traffic like any other flow.<\/li>\n<\/ul>\n\n\n\n<p>Crucially, WireGuard can run side-by-side with existing IPsec and OpenVPN setups, giving administrators the latitude to migrate gradually rather than in one fell swoop.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Maintenance and Security Tweaks<\/h2>\n\n\n\n<p>Beyond WireGuard, Core Update 195 introduces several under-the-hood improvements:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Removal of 3CoreSec blocklists, which have been discontinued.<\/li>\n\n\n\n<li>Refactored IP blocklist and IPS ruleset download code (thanks to Stefan Schantl) for better reusability.<\/li>\n\n\n\n<li>Bcrypt hashing for proxy user database passwords, enhancing security.<\/li>\n\n\n\n<li>UI polish for Pakfire, improving usability (courtesy of Stephen Cuka).<\/li>\n\n\n\n<li>Automatic SMART database updates for hard drive monitoring.<\/li>\n<\/ul>\n\n\n\n<p>The update also includes upgraded packages, such as OpenSSL 3.5, Unbound 1.23, and OpenSSH 10.0.p1, ensuring stronger encryption and performance across the board.<\/p>\n\n\n\n<p>Lastly, several add-ons have been upgraded to newer versions, including\u00a0Alsa 1.2.14,\u00a0Monit 5.35.2,\u00a0Nano 8.4, and\u00a0Shark 4.4.6.<\/p>\n\n\n\n<p>For more information, <a href=\"https:\/\/www.ipfire.org\/blog\/ipfire-2-29-core-update-195-released-wireguard-inside\" target=\"_blank\" rel=\"noreferrer noopener\">see the announcement<\/a>.<\/p>\n\n\n\n<p>Core Update 195 is already <a href=\"https:\/\/www.ipfire.org\/downloads\/ipfire-2.29-core194\" target=\"_blank\" rel=\"noreferrer noopener\">available for download<\/a> on IPFire\u2019s website. Two build flavours cover the most common hardware: x86_64 and aarch64 for those needing a fresh install. Existing systems can be upgraded via IPFire\u2019s web UI.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>IPFire 2.29 Core Update 195 open-source firewall is out, adding long-awaited WireGuard VPN support and easy-to-configure tunneling options.<\/p>\n","protected":false},"author":10,"featured_media":174296,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7,5],"tags":[4155,6365,3374],"class_list":["post-174293","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-software","category-news","tag-firewall","tag-ipfire","tag-security"],"blocksy_meta":[],"_links":{"self":[{"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/posts\/174293","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/comments?post=174293"}],"version-history":[{"count":0,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/posts\/174293\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/media\/174296"}],"wp:attachment":[{"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/media?parent=174293"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/categories?post=174293"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/tags?post=174293"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}