IPFire 2.29 Core Update 204 Heads to Testers
IPFire 2.29 Core Update 204 is now available for testing. Its headline fix repairs a DNS regression the previous release introduced, and there's a good deal more under the hood than a pure housekeeping build would suggest.
IPFire 2.29 Core Update 204 has reached the testing stage, and the most important thing about it is a DNS bug that IPFire's own previous release quietly introduced. If you run a VPN through IPFire, this is the build you should try first.
It's a testing release, so think of it as a candidate sitting just in front of the stable line. IPFire ships each Core Update as a complete, installable ISO rather than a patch you pile on top of the last one. Core Update 204 is deliberately a housekeeping release, and developer Michael Tremer announced the build on ipfire.org, framing it as a broad sweep of package updates anchored by one very specific repair.
The regression that broke DNS over VPN
Core Update 203 swapped Unbound for Knot Resolver and most users liked the result. DNS got snappier, and a few long-standing complaints just vanished. Then people started reporting that clients connected over IPsec, WireGuard, or OpenVPN couldn't resolve names at all.
The Core Update lprit was that Knot Resolver was replying from the wrong source IP address, breaking reverse routing for tunnel-connected clients. Fixing it needed real work in the I/O layer of Knot Resolver, so IPFire contributed the changes back upstream. That's a tell worth pausing on: the project's Core Update stomizations run deep enough that they have to be folded into the upstream project itself. Until that lands, remote workers and site-to-site VPN users feel it most.
It's arguably the single best reason to test this build right now.
A preemptive anti-phishing ruleset
The other genuine headline is IPFire adding Julio Lira's Advanced Phishing Protection ruleset to its Suricata IPS. The project is GPLv3 and built around a "Day Zero" model, meaning it tries to catch phishing infrastructure before it goes mainstream rather than after a report shows up.
It watches newly registered domains and applies heuristics like typosquatting detection, homoglyphs, brand impersonation patterns, and keyword analysis to flag emerging domains while they're still young. The pipeline reportedly churns through more than 1.5 million candidate domain combinations, spanning DNS queries, TLS Server Name Indication, HTTP inspection, and destination intelligence.
Keep in mind the built-in caveat. The Antiphishing project itself warns that "suspicious does not mean confirmed malicious." Predictive indicators carry a sharper false-positive edge, so you'll want to whitelist and tune alerts before this bites something legitimate.
Still, dropping a community-sourced, network-level phishing defense straight into the IPS is a sensible addition, even if it deserves a light hand.
Everything else
On top of those two, Core Update 204 is a routine-but-thorough maintenance release. The kernel is rebased to Linux 6.18.54, pulling mostly stability and seCore Update rity fixes from upstream. A WireGuard import bug (#13951) that choked on space-separated subnets is now fixed, and the experimental RISC-V builds have been retuned for out-of-order cores.
That last bit is more interesting than it sounds. IPFire's RISC-V nights used to take 54 to 56 hours under emulation. After the team dropped a real Milk-V Jupiter 2 board into the build pipeline, those builds now finish in about seven. Native hardware changes the math entirely.
The rest is a large package sweep. The core tier picked up OpenSSH 10.4p1 and OpenSSL 3.6.5, sitting right at the heart of remote access and cryptography, alongside BIND 9.20.24, Knot Resolver 6.4.2, Core Update RL 8.21.0, systemd 261.1, and Apache 2.4.68. Add-ons got their own refresh, with dnsdist 2.1.0, HAProxy 3.4.2, Postfix 3.11.4, ffmpeg 8.1.2, and clamav 1.5.3 among the bumps.
The monitoring add-ons saw real sharpening, not just version stamps. Observium Agent can now report Apache status, Zabbix finally reports Knot Resolver metrics (closing the gap left by the DNS migration), and Avahi's shutdown hang is fixed, since stopping the daemon while it wasn't running used to leave the operation wedged.
Why it matters
Core Update 204 isn't a feature release in the way Core Update 201 (DNS Firewall) or Core Update 203 (the Knot Resolver swap) were. But it still does three things that keep a production firewall honest: it repairs a regression that left VPN clients blind, it hardens the network edge against phishing before it lands, and it keeps the base continuously patched. That last promise is the whole point of IPFire's frequent-release model.
The announcement also teases a "serious upgrade" to monitoring and reporting coming down the line, promising a much clearer view of what your firewall is actually doing. The expanded Observium and Zabbix integration here reads as a preview of that direction.
For testers
IPFire explicitly asks volunteers to install this on non-production systems and report back. The one check it repeats: if you connect via IPsec, WireGuard, or OpenVPN, verify that name resolution works as expected.
Submit findings on the Bugzilla tracker and hash it out on the community forum.
Head here to the official release announcement.
