A New Release Candidate for pfSense Plus Software Version 26.07 Available!
-
Netgate
has made a new Release Candidate for pfSense
Plus version 26.07 available for testing.This release marks another significant step forward in the Netgate Nexus controller architecture, which is our new Go-based controller that is replacing the legacy PHP GUI and serving as the modern foundation for pfSense software. Netgate Nexus continues to deliver further improvements and new feature development, bringing exclusive capabilities that enhance performance, scalability, and functionality to pfSense Plus.
Key new features exclusive to the Netgate Nexus controller include:
CoreDNS: A high-performance, integrated DNS component that handles DNS-based tasks with exceptional speed and efficiency, powered by a new and exclusive Netgate plugin called rexdns.
Threatgate: A powerful, high-performance component that manages bulk lists of addresses and domains for firewall rules, aliases, and CoreDNS groups. Administrators can block these lists outright or create custom rules based on their content.
Threatgate and CoreDNS were built to integrate tightly together, enabling rapid processing and utilization of even massive lists - all while maintaining excellent performance on small, resource-constrained devices.
Snort Version 3: The updated version of the popular open-source intrusion prevention system (IPS), featuring multi-threading support, and a faster rule syntax, is now available exclusively via the new Netgate Nexus controller GUI.
In addition to the features listed above, this release candidate includes critical security updates for WireGuard (CVE-2026-58085), and other security enhancements.
Other fixes and enhancements were made to:
- DHCP
- DNS Resolver
- DynamicDNS
- Gateways and Monitoring
- IPsec
- VXLAN Interfaces
- OpenVPN
- Firewall Rules and NAT
- Traffic Shaper
- Wireless
This release includes numerous updates, bug fixes, and enhancements, with more to come as pfSense Plus and Netgate Nexus development accelerates.
Using the New GUI
The Netgate Nexus controller is the future of the pfSense Plus GUI.
Whether you manage a single pfSense Plus firewall or an entire fleet, the Netgate Nexus controller delivers a modern, refreshed management experience built for the way you work today.Getting started is simple:
- Go to System > Advanced.
- Switch to the Netgate Nexus tab and enable it.
- Log in to Nexus on port 8443 of your firewall.
More detailed documentation can be found here. Start using it today and get immediate access to the new features and capabilities coming to pfSense Plus.
Note: Virtual machines as well as some third-party platforms may not support the new GUI due to missing machine information required to correctly run the software.
Call for Testing
Testing of this release candidate software is essential. Testing is the most effective way to ensure that the software is robust and reliable for all users, given the diversity of their environments and configurations. By downloading and testing this release candidate, and providing feedback on any issues, our users can play a vital role in improving the software for everyone.Release Notes:
https://docs.netgate.com/pfsense/en/latest/releases/26-07.html -
P pfGeorge pinned this topic
-
P pfGeorge unpinned this topic
-
P pfGeorge pinned this topic
-
@pfGeorge said in A New Release Candidate for pfSense Plus Software Version 26.07 Available!:
CoreDNS: A high-performance, integrated DNS component that handles DNS-based tasks...
Threatgate: A powerful, high-performance component that manages bulk lists of addresses and domains for firewall rules, aliases, and CoreDNS groups
Do these components enable pfsense to circumvent the filerdns bugs in particular:
- intersecting host IP addresses / duplicate removal but not restoration
- more than 749 entries total across all aliases containing at least one FQDN
-
Updated to latest rc and enabled nexus

And various virtualization not supported errors.
So, is netgate abandoning virtualization eventually?
-
@netblues don't panic yet, people. Nexus is the future but I'm sure they are sensible enough to not remove the current GUI before Nexus works on all systems. They are just not good at communication, been like that forever.
In Proxmox, adding a random serial number for the VM option 'SMBIOS settings (type1)', field 'Serial' solved it. Not tried UEFI yet.
-
@netblues (can't edit my own post) have you also got an entry like:
Aug 4 16:25:22 pfp pfnet-controller[99182]: WARNING Nexus cannot be licensed on this system due to: serial number un available, unsupported virtualization. -
@patient0 said in A New Release Candidate for pfSense Plus Software Version 26.07 Available!:
They are just not good at communication, been like that forever.
For a couple of days I've this on my pfSense dashboard :

-
@patient0 Yes I also have this..
-
So with a random serial number in kvm I can see the "dashboard" however errors pop everywhere about being unlicensed too.
-
@netblues known issue on Reddit
-
@pfGeorge The 26.07 UI also exposes a new mDNS service that does seem a bit like something from Avahi. It's not mentioned in the release notes.
What is that service based on and I assume it is mDNS only? -
@pfGeorge There is also a new "local address monitor" service. What is that based on, and what is it destined to be used for?
-
@keyser said in A New Release Candidate for pfSense Plus Software Version 26.07 Available!:
@pfGeorge The 26.07 UI also exposes a new mDNS service that does seem a bit like something from Avahi. It's not mentioned in the release notes.
What is that service based on and I assume it is mDNS only?I'm afraid that actually is the old Avahi. This isn't a great naming choice for a service identified simply as "mDNS" in the new UI. It really should be named "Avahi", and given all the various issues surrounding Avahi, it also should not be installed by default.
-
@dennypage said in A New Release Candidate for pfSense Plus Software Version 26.07 Available!:
@keyser said in A New Release Candidate for pfSense Plus Software Version 26.07 Available!:
@pfGeorge The 26.07 UI also exposes a new mDNS service that does seem a bit like something from Avahi. It's not mentioned in the release notes.
What is that service based on and I assume it is mDNS only?I'm afraid that actually is the old Avahi. This isn't a great naming choice for a service identified simply as "mDNS" in the new UI. It really should be named "Avahi", and given all the various issues surrounding Avahi, it also should not be installed by default.
Ohh, well that is unfortunate - and a rather poor choise of negate to force include in the Nexus Package. I'm not sure I like this "Nexus as a container for services" concept :-(
Services should be independant of the Nexus package, and should be individually upgradable/installable.
Luckily it seems one can elect not to enable it, which I assume means it won't cause issues with your fabulous mDNS-Bridge :-) -
@keyser said in A New Release Candidate for pfSense Plus Software Version 26.07 Available!:
Services should be independant of the Nexus package, and should be individually upgradable/installable
As I understand it CoreDNS and ThreatGate are all in one executable too. Not sure if the source code gets published or not.
-
Besides having UUID and Serial set for SMBIOS (at least it's shown bei
dmidecode), Nexus still complains about "not licensed" or having no license active, besides the VM having 2y or Plus/TAC remaining.

-
@JeGr said in A New Release Candidate for pfSense Plus Software Version 26.07 Available!:
Nexus still complains about "not licensed" or having no license active
Yes, I do see that too. Although it seems not to result in functional limitation for me.
-
@patient0 said in A New Release Candidate for pfSense Plus Software Version 26.07 Available!:
Yes, I do see that too. Although it seems not to result in functional limitation for me.
Try opening the packages menu...
-
@dennypage said in A New Release Candidate for pfSense Plus Software Version 26.07 Available!:
Try opening the packages menu...
Indeed, very much a work in progress.
-
@patient0 It looks like they want to impose a yearly subscription for each instance using the new interface? If your only instance is the firewall itself, it should be free, otherwise it's a deal breaker for me. I'm not paying a yearly subscription for something I already own, when I bought my 6100 it was for the harware and all updates going forward.
-
@dstacey147 I think, only MIM has a fee.
Privacy Policy · Cookie Policy