With Core Update 203, IPFire is fundamentally restructuring the DNS infrastructure: instead of Unbound, Knot Resolver will be used in the future. The change should, among other things, enable encrypted forwarding via DNS over TLS, DNS-based filter rules and a persistent cache. In addition, the integrated WLAN access point now supports the 6 GHz band of Wi-Fi 6E and Wi-Fi 7.
Read more after the ad
IPFire is a Linux distribution focused on security and network gateways. It is typically used as a firewall and VPN gateway with an intrusion prevention function.
Knot Resolver becomes the new DNS base
According to the release notes, with the update the IPFire developers are replacing the previously used resolver Unbound with Knot Resolver. The change affects a core function of the system: DNS not only resolves host names into IP addresses, but now also provides information for encrypted connections and modern transport protocols.
Knot Resolver is intended to provide IPFire with a more extensible architecture. The resolver works modularly and can be scripted. IPFire uses this for its own extensions, such as connecting DHCP leases and DNS filter lists.
New features include the ability to forward DNS requests to external resolvers in encrypted form via DNS over TLS. This allows requests to be protected from eavesdropping and manipulation on the way to the selected upstream resolver. For example, administrators can use an external resolver without sending unencrypted DNS queries over public Internet access.
DNS firewall, SafeSearch and shared cache
With the new DNS basis, IPFire introduces a DNS firewall. It can block domains for malware, advertising or other categories as early as name resolution. The new zone-sync tool downloads the zones and filter data required for this in encrypted form. It updates the data incrementally instead of always transferring complete lists.
Read more after the ad
The SafeSearch filter mechanism can also be enforced network-wide: IPFire then redirects search queries to the SafeSearch variants of supported search engines and YouTube. Additionally, local DNS records and conditional redirects remain available. The latter send requests for defined zones specifically to specific DNS servers, for example for an internal company network or a domain that can be reached via VPN.
The resolver cache will survive restarts in the future. This is intended to speed up name resolution after a reboot and reduce the load on higher-level DNS servers. Knot Resolver also uses multiple worker processes that share cache and state. This allows IPFire to use multiple CPU cores without each process maintaining its own isolated cache.
However, administrators have to rework existing DNS forwardings: IPFire no longer accepts fully qualified domain names (FQDN) configured as forward zones. Such entries on the DNS forwarding page must be replaced with IP addresses.
6GHz Wi-Fi and AWS improvements
The IPFire WLAN access point now supports the 6 GHz band. This allows the distribution to use the additional spectrum of Wi-Fi 6E and Wi-Fi 7. Especially in densely populated environments, this promises less interference from old devices and more space for wide channels with 80 or 160 MHz.
Unlike parts of the 5 GHz band, radar detection via DFS is not required in the 6 GHz spectrum. Access points therefore do not have to search for a free channel before starting and do not have to change the channel when radar signals are detected. This is intended to avoid connection interruptions caused by such changes. The update also fixes a bug that could prevent the access point from starting when the channel was manually selected and the channel width was 40 MHz.
For IPFire instances on AWS, the release adds support for IMDSv2. EC2’s token-based metadata service is considered more secure than the first version and may be mandatory in newer configurations. Existing installations with IMDSv1 should continue to work.
Security updates and updated components
Core Update 203 also updates Intel microcode for certain processors. This is intended to address a security vulnerability listed under INTEL-SA-01420. A bug with UTF-8 processing in Perl has also been corrected; This should ensure that translations with non-ASCII characters appear correctly in the web interface again.
In addition, IPFire updates numerous basic and additional packages, including BIND, OpenVPN, Suricata, strongSwan, Samba, Postfix and Zabbix Agent. With OpenVPN, among other things, the configuration download button has been revised and additional information has been added for Roadwarrior connections with static IP assignment.
Read also
(fo)
