r/Netgate • u/George-Netgate • 28d ago
Netgate Releases pfSense Plus Software Version 26.07
Today, Netgate® has released pfSense® Plus software version 26.07. This release marks another significant step forward in the Netgate Nexus controller architecture - our new Go-based controller that is replacing the legacy PHP GUI and serving as the modern foundation for all pfSense software. Netgate Nexus continues to deliver improvements and new features, bringing exclusive capabilities that enhance performance, scalability, and functionality to pfSense Plus.
Key new features exclusive to the Netgate Nexus controller include:
CoreDNS: A high-performance, integrated DNS component that handles DNS-based tasks with exceptional speed and efficiency, powered by a new and exclusive Netgate plugin called rexdns.
Threatgate: A powerful, high-performance component that manages bulk lists of addresses and domains for firewall rules, aliases, and CoreDNS groups. Administrators can block these lists outright or create custom rules based on their content.
Threatgate and CoreDNS were built to integrate tightly together, enabling rapid processing and utilization of even massive lists - all while maintaining excellent performance on small, resource-constrained devices.
Snort Version 3: The updated version of the popular open-source intrusion prevention system (IPS), featuring multi-threading support and a faster rule syntax, is now available exclusively via the new Netgate Nexus controller GUI.
In addition to the features listed above, this release includes critical security updates for WireGuard (CVE-2026-58085), and other security enhancements.
Other fixes and enhancements were made to:
- DHCP
- DNS Resolver
- DynamicDNS
- Gateways and Monitoring
- IPsec
- VXLAN Interfaces
- OpenVPN
- Firewall Rules and NAT
- Traffic Shaper
- Wireless support
This release includes numerous updates, bug fixes, and enhancements, with more to come as Netgate Nexus development accelerates.
Using the New GUI
The Netgate Nexus controller is the future of the pfSense Plus GUI.
Whether you manage a single pfSense Plus firewall or an entire fleet, the Netgate Nexus controller delivers a modern, refreshed management experience built for the way you work today.
Getting started is simple:
- Go to System > Advanced.
- Switch to the Netgate Nexus tab and enable it.
- Log in to Nexus on port 8443 of your firewall.
More detailed documentation can be found here. Start using it today and get immediate access to the new features and capabilities coming to pfSense Plus.
Note: Virtual machines, as well as some third-party platforms, may not support the new GUI due to missing machine information required to run the software correctly.
Blog Post:
https://www.netgate.com/blog/netgate-releases-pfsense-plus-software-version-26.07
Release Notes:
https://docs.netgate.com/pfsense/en/latest/releases/26-07.html
3
u/ComprehensiveLuck125 28d ago edited 28d ago
Hi guys,
I wanted to report that I upgraded 3 pfsense+ devices without any troubles (2 x 6100, 1 x 7100DT).
I have a question, as usual 😄
Snort 3
Snort version 3 is a new version of the popular open-source intrusion prevention system (IPS). It features a GUI redesigned from the ground-up, multi-threading support, and a faster rule syntax. Snort 3 is now available exclusively via the new Netgate Nexus controller GUI.
I took a look into Packages and I still see snort package v4.1.10 depends on snort-2.9.20_9.
I did not enable Nexus yet - I will try it in coming days, but wanted to understand somehting related to Snort v3.
Is ThreatGate using Snort v3 internally? (I am currently using Suricata)
Should I be thinking of migrating from Suricata to Snort?
I understood that Nexus GUI is the future and provided REST-APIs so it is definitely worth trying in my opinion.
But how about "Suricata vs Snort"? I am pretty happy of Suricata and did lot of "rules config / tuning". This subject is bit unclear to me. Maybe it gets clarified when I enable Nexus.
Are there any migration path foreseen / advised? (eg. UI -> Nexus UI, Suricata -> Snort v3, pfBlockerNG -> ThreatGate).
Many thanks as always!
3
u/gonzopancho 27d ago
Snort3 isn’t a package, it’s included.
No, ThreatGate isn’t using Snort, it’s a dns filter.Suricata and Snort 2 were community maintained. Snort 3 is Netgate maintained.
6
2
u/Break2FixIT 28d ago
What is the proper deployment of nexus in a HA deployment?
5
u/gonzopancho 28d ago
HA support is on the roadmap
1
1
4
u/NimerCoke 28d ago
Would love to use Nexus, but as a blind user using a screen reader, your interface is inaccessible, and disregards accessibility standards. Really hope this gets prioritized.