24.08 Sneak Peek: Improvements to Kea DHCP for Improved High Availability and Unbound DNS Resolution in pfSense® Software
-
We’re excited to announce important updates to the integration of Kea DHCP into pfSense software, adding support for DHCP High Availability and improved support for registration of DHCP hostnames with the Unbound DNS Resolver. With the release of pfSense Plus software version 24.08, users who require DHCP HA support or DNS resolution of DHCP hostnames can now migrate from the ISC DHCP backend to the Kea DHCP backend.
Key benefits include:
- Simplified Setup: Kea DHCP uses a single, global HA configuration, which is easier to set up and manage than ISC DHCP's per-interface configuration.
- More Reliable Failover: Kea operates in "hot standby" mode, providing more reliable failover, especially when booting a secondary node.
- IPv6 Support: Those using IPv6 will benefit from HA support for DHCPv6, a feature not available with ISC DHCP.
- Improved Security: Kea DHCP supports optional TLS encryption for HA traffic, enhancing the security of your DHCP setup.
Learn more here: https://www.netgate.com/blog/improvements-to-kea-dhcp
-
-
Very interesting indeed. Happy that KEA is picking up the slack and missing features for ISC
Will KEA in 24.08 reach feature parity + its own new features, or is it still considered experimental with other key features missing?
-
@keyser Hmm, cannot edit the above post.
The blog is a little vague in declaring what is considered missing from KEA before feature parity is reached.
-
does not require restarting the Unbound service
-
@mwatch One other thing I REALLY hope KEA will bring to the table:
A new DHCP Relay Service that kan work in combination with the DHCP service (on different interfaces of course), and - VERY IMPORTANTLY - works through IPSEC Tunnels out of the hosting firewall.
-
What about the community version?
-