news
IPFire 2.29 Core Update 203 Firewall Distro Replaces Unbound with Knot Resolver
Coming one and a half months after IPFire 2.29 Core Update 202, the IPFire 2.29 Core Update 203 is here to revamp the DNS resolution from the ground up by replacing Unbound with Knot Resolver, which introduces encrypted upstream forwarding (DNS over TLS), DNS firewall, encrypted zone data (over TLS), SafeSearch, conditional forwarding, local overrides, DHCP integration, persistent cache, and shared state across multiple workers.
IPFire 2.29 Core Update 203 also intorduces support for the 6 GHz Wi-Fi band, the ability to retrieve EC2 instance metadata using the token-based and secure IMDSv2 metadata service, a newer microcode for Intel CPUs to mitigate a vulnerability, support for sysklogd to listen on localhost, and a new OpenVPN icon to download the configuration, along with the ability to show the name of the subnet next to the connection for Roadwarrior clients with a static IP.
Linux Magazine:
-
Substantial Update to IPFire Now Available
If you're a user of IPFire, get ready for a major update in IPFire 2.29 – Core Update 203, because the developers have replaced Unbound with Knot Resolver for handling DNS for a more flexible foundation and new capabilities, such as a DNS firewall and encrypted upstream forwarding.
"This is a significant change under the hood, and not one we made lightly," the official IPFire blog states. "Unbound has served IPFire well for many years and remains an excellent resolver. But DNS has quietly become one of the most important parts of the modern network. It is no longer only about turning names into addresses – it increasingly carries the information other protocols rely on to connect quickly, securely and privately, from encrypted transport to the records clients use to establish encrypted connections."
With Knot Resolver, you also get encrypted zone data (over TLS), SafeSearch, conditional forwarding, local overrides, and DHCP integration. Besides Knot Resolver, IPFire 2.29 also includes persistent cache (for surviving restarts), shared state across multiple workers (sharing one cache and state for more efficient use of multi-CPU core systems without cache fragmentation), and WiFi 6 support (for cleaner airtime and more stable connections, wider channels, and no radar detection).