Eduardo Jonck - 2026-07-08

🚀 BIG RELEASE: NEW ISO FOR VERSION 4.0.0 HAS BEEN RELEASED! 🚀
Highly anticipated by many, the new ISO for OpenFW UTM Community is officially available! This version brings a massive leap in stability, security, and new features.
Check out below the compilation of everything that has been improved, fixed, and implemented over the recent period:

🔹 POWERFUL FEATURES AND FUNCTIONALITIES
⚡️ Wireguard Support: Now with full support for Wireguard Server and Wireguard Client.
⚡️ Multiple OpenVPN Instances: Enabled the option to create more than one tunnel and multiple instances of the OpenVPN Server.
⚡️ GeoIP-Based Rule: New geolocation-based rules feature utilizing MaxMind DB.
⚡️ DuckDB in Logs: Firewall and system logs are now archived in a DuckDB database, bringing drastic improvements to information, charts, and access geolocation identification.
⚡️ Container Support: Now with support for containers running directly via docker-ce.
⚡️ New Network Management: New feature for creating more interfaces and subnets with 100% DHCP management via Web.
⚡️ Rules in Custom Subnets: New feature for creating firewall rules in customized subnets.
⚡️ Advanced Web Management: Added the option for system updates via WEB, addon/packet installation, and service restarts directly through the interface.

🔹 INTERFACES, MONITORING, AND USABILITY
📊 Kula Monitoring: Legacy charts have been removed and replaced with Kula Monitoring for much more modern charts.
📊 Addon Integration: NXfilter and NTopNG addons are now integrated directly into the Web interface for easier access.
📊 Revamped FailtoBan: The entire FailtoBan WebGui has been redesigned to make administration much simpler.
📊 Log Visualization: Added a log column across all firewall rule management pages to quickly check whether it is active or not.
📊 Connection Status: New connection status panels for OpenVPN and Wireguard.
📊 Improved Dashboard: Adjusted to display more network interfaces on the dashboard and corrected the unit of measurement for disks.
📊 Complete Refactoring: The DDNS feature and the SpeedTest WEB addon have been 100% rebuilt.

🔹 SECURITY, KERNEL, AND INFRASTRUCTURE
🛡 Kernel Upgrade: Massive Kernel update from 4.4 to 5.10.
🛡 IDS/IPS Migration: The intrusion prevention system has been migrated from Snort to Suricata in Inline mode (yielding much higher performance).
🛡 Network Drivers: Added more third-party Linux Firmware network drivers through the linux-firmware-network package.
🛡 New Addons: Inclusion of OpenVM Tools (for VMware environments) and EmailRelay.
🛡 Legacy Cleanup: Complete removal of old proxies (SMTP Proxy, POP Proxy, and FTP Proxy) and the WebFilter Engine and ClamAV Engine menus.

🔹 BUG FIXES AND PACKAGE UPGRADES
⚙️ Important Visual Fix: Fixed the bug where multi-select boxes turned white when checked. Now they turn gray, allowing you to clearly see what is selected.
⚙️ Subnet Validation: Added validation in the CGI to prevent registering subnets on custom interfaces (allowing IP only).
⚙️ DHCP Lease: Added scheduling for automatic purging of DHCP leases.
⚙️ Security and Core Upgrades: Upgrade of the StrongsWAN IPSEC manager (vulnerability fixes), along with updates to C-ICAP, Redis Server, NtopNG, SAMBA, and TZdata.