The developers behind IPFire have officially released IPFire 2.29 Core Update 203. As the newest stable version of this open-source, hardened Linux firewall distro, this update focuses heavily on modernizing network security and fine-tuning core capabilities.
If you manage network traffic, secure remote workers, or run dedicated security hardware, this release brings several game-changing enhancements under the hood.
Overhauling DNS: Farewell Unbound, Hello Knot Resolver
The biggest highlight of Core Update 203 is a complete ground-up revamp of IPFire’s DNS resolution engine. The development team has swapped out Unbound in favor of Knot Resolver.
DNS is no longer just about converting domain names into IP addresses; it carries critical infrastructure for modern, encrypted protocols. Transitioning to Knot Resolver enables several powerful features natively:
- Encrypted Upstream Forwarding: Native support for DNS over TLS (DoT).
- Deeper Network Integration: Native conditional forwarding, DNS firewall filtering, local overrides, and automatic DHCP integration.
- High Performance: Persistent caching and shared state memory across multiple worker threads.
"DNS has quietly become one of the most important parts of the modern network... To keep building on top of DNS, we needed a resolver we can extend and integrate deeply with the rest of IPFire," explained IPFire developer Michael Tremer.
Next-Gen Wireless and Cloud Improvements
Core Update 203 isn't just about DNS. The distribution also adds native support for the 6 GHz Wi-Fi band, unlocking faster speeds and lower latency for modern wireless access points.
Cloud admins will appreciate new support for
Amazon EC2 IMDSv2, allowing instances to retrieve metadata
using token-based session requests for tighter cloud security. On top of
that, sysklogd can now be configured to listen directly on
localhost.
For OpenVPN administrators, managing Roadwarrior clients with static IPs gets much smoother. The Web UI now displays the corresponding subnet name right next to the active connection, paired with a dedicated download action for client configuration files.
Major Package and System Updates
As expected, this update refreshes a massive portion of the underlying system toolchain and add-on software catalog:
- Core Networking & VPN: BIND 9.20.23, OpenVPN 2.7.4, Postfix 3.11.3, Samba 4.24.2, and Strongswan 6.0.7.
- System Utilities: Boost 1.90.0, GNU Coreutils 9.11, btrfs-progs 7.0, GRUB 2.14, LVM2 2.03.41, and Suricata 8.0.6.
- Security & Firmware: Includes updated Intel CPU microcode mitigations to patch hardware-level security vulnerabilities.
How to Upgrade
The new ISO and USB installation images are available immediately from the official IPFire download portal. If you are already running IPFire, you can perform an in-place upgrade directly through the Pakfire package manager without rebuilding your server from scratch.

Comments
Post a Comment