NethSecurity 8.8.0: Geoblocking, Alerts, metrics, emergency CLI tool

We are pleased to announce the release of NethSecurity 8.8.0.

This version is a major platform update: NethSecurity 8.8.0 is based on OpenWrt 25.12.5, while version 8.7.2 was based on 24.10.5.

The rebase introduces significant updates to the system, kernel, main networking and VPN components, as well as numerous security fixes.

Update now :backhand_index_pointing_left:

:control_knobs: Controller compatibility

Using NethSecurity 8.8.0 with Controller requires at least Controller version 2.2.7-dev.3.

:fire: Release highlights

NethSecurity 8.8.0 introduces a major update to the system base.

This includes:

  • update of the Linux kernel to version 6.12
  • update of many system and networking components
  • switch from the opkg package manager to the new apk package manager
  • update of OpenVPN to version 2.7.4
  • update of IPsec/strongSwan to version 6.0.3
  • numerous vulnerabilities fixed in base components, the kernel, network services and system libraries
  • general improvements in stability, compatibility and hardware support

The new package manager is one of the most relevant changes: apk replaces opkg as the package management system.

For users who only use the web interface, the impact should be minimal, while those who install or manage packages from the CLI will need to take the new command syntax into account.

:rocket: New features

:earth_africa: Geoblocking in Threat Shield IP

The Threat Shield IP section introduces the ability to manage IP geoblocking directly from the firewall interface.

It is now possible to apply geoblocking rules, allowing more flexible management of policies based on the geographic origin or destination of IP addresses.
Blocking is active only for inbound traffic, blocking all requests from the internet while allowing hosts on the network to browse freely.

:bell: Alerts and notifications

A new section dedicated to alerts and notifications has been introduced, designed to inform the administrator in case of firewall anomalies or relevant conditions.

This feature provides greater visibility into system status and allows faster action when events requiring attention are detected.

:bar_chart: Integrated native metrics

NethSecurity introduces a new section of natively managed metrics, integrated directly into the firewall interface.

The new section allows you to view information on many aspects of system operation, including:

  • network traffic
  • firewall load
  • interface trends
  • latency graphs
  • useful indicators to check the overall status of the appliance

Some of this information was already available through Netdata, but it is now integrated directly into the NethSecurity UI, making consultation more immediate and providing higher retention.

If storage is configured, metrics retention reaches up to 52 weeks.

:identification_card: DHCP server with multiple ranges

The new UI allows you to specify multiple IP ranges for the same DHCP server. This simplifies configuration in environments where the network includes a mix of devices with static and dynamic IP addresses.

:computer: Emergency CLI tool

NethSecurity 8.8.0 also introduces a CLI configuration tool, designed for emergency situations where it is not possible to access the firewall web interface.

By accessing the system via console or SSH and running the setup command, it is possible to open a text-based menu that allows basic network configuration to be modified without using the browser UI.

The tool allows you to:

  • configure the LAN interface
  • configure the WAN interface
  • modify the IPv4 address and interface protocol
  • apply network changes
  • modify the console keyboard layout

This feature is especially intended for cases where an incorrect network configuration makes the web UI unreachable, or when working directly from the local console during installation, recovery or troubleshooting.

:package: Management of additional packages and image updates

Management of manually installed additional packages has been improved, an especially important aspect in this version due to the switch to the new apk package manager.

The goal is to make the behavior of additional packages more reliable in image update scenarios and customized installations.

:floppy_disk: DHCP lease persistence on mounted storage

On appliances with configured storage, DHCP leases are preserved even in case of shutdown.

This change is useful in scenarios where maintaining DHCP lease status after reboots or updates is desired, improving service continuity in networks where address assignment is particularly important.

:satellite: Avahi / mDNS support

The Avahi (mDNS) package has been added to the NethSecurity repositories.

This makes it possible to enable local discovery scenarios based on mDNS, useful for example for devices, services or environments where automatic discovery of resources on the local network is required.

:shield: New firewall action “NOTRACK”

A new action has been introduced in firewall rules: NOTRACK.

This action allows you to exclude specific traffic from connection tracking. It is useful in advanced scenarios where you want to reduce connection tracking overhead or handle specific network flows differently (e.g. local network probes).

Note: IP addresses subject to the NOTRACK action may not have Internet connectivity.

:busts_in_silhouette: More features available in the community version

Starting with NethSecurity 8.8.0, some features previously reserved for installations with an active subscription are now also available in the community version.

The following actions, previously visible but not clickable, can now be used:

  • ability to enable automatic updates

  • ability to connect to external user databases (for OpenVPN roadwarrior access)

:arrows_counterclockwise: Features already introduced with 8.7.2 updates

Version 8.8.0 also includes some features that were already made progressively available through automatic updates of 8.7.2.

We report them here because they are part of the overall experience of the new version, but they may already be present on firewalls updated to 8.7.2.

:closed_lock_with_key: Permanent OpenVPN connection logs

OpenVPN connection logs are permanent for all firewalls equipped with storage.

Storage is configured by default on all physical appliances, making it possible to keep a more reliable VPN connection history without requiring additional configuration in most installations.

:bug: Bug fixes

This version includes several already verified fixes, including:

  • fixed the count of OpenVPN client tunnels in the dashboard, where disconnected tunnels could be shown as connected
  • fixed the status of users from an external database, who could appear disconnected even when they were actually connected
  • fixed restoration of extra packages after image update
  • fixed a Threat Shield DNS issue with empty lists after repeated changes
  • fixed issues related to disabled packages after updates
  • fixed a netifyd migration issue after image update
  • added additional logs when DPI blocks traffic

:bug: Known bugs

The complete list of known bugs is available here.

How to update NethSecurity :arrow_up:

  1. Go to the System → Updates section in the UI
  2. The UI should show a new available version (NethSecurity 8.8.0)
  3. Click Update system (the update includes automatic device reboot)

:question: What is NethSecurity?

NethSecurity is a powerful, open-source Linux firewall designed to simplify network security deployment. It offers full-featured protection and an easy-to-use interface.

Choose your preferred Subscription Plan

A NethSecurity subscription ensures that your deployment is backed by top-tier technical expertise and the support necessary to maintain your organization’s security infrastructure.

Subscribing also grants exclusive access to the Enterprise repository, which includes Automatic Updates and VPN integration with LDAP/AD user databases.

It also provides advanced DPI-based application and protocol detection, with over five times more applications and protocols recognized compared to the Community version.

:point_right: Get your subscription

:rocket: Help shape NethSecurity’s future

Your feedback is invaluable as we continue to refine and enhance NethSecurity. Please share your thoughts, report issues, and suggest features by opening a new topic in the NethSecurity category, using tags like Feature, Bug, or Support.

:point_right: Download and use it! :point_left:

3 Likes

Is it possible to connect to the NS8 LDAP ?
And which URL must i use in Nethsecurity ?