IPFire Core Update 203 Swaps Unbound for Knot Resolver and Adds Native DNS Firewall

Published by

IPFire 2.29 Core Update 203 has been released, making a significant change by replacing the long-used Unbound resolver with the Knot Resolver, allowing for enhanced features like DNS over TLS and a native DNS Firewall. This update also introduces support for the 6 GHz WiFi band, IMDSv2 for AWS EC2 deployments, and includes important security patches for strongSwan and Intel processor microcode. Administrators must be aware that forwarded zones must be changed from fully-qualified domain names to IP addresses before or during the upgrade to avoid breaking custom routing. Overall, this release represents a major modernization for IPFire, with a focus on meeting contemporary DNS requirements while ensuring smoother operation across various network environments



IPFire Core Update 203 Swaps Unbound for Knot Resolver and Adds Native DNS Firewall

IPFire 2.29 Core Update 203 is live, marking the project's biggest backend shift as it replaces the long-standing Unbound resolver with the modular Knot Resolver. The swap unlocks DNS over TLS, a native DNS Firewall, network-wide SafeSearch enforcement, and persistent caching that survives reboots. Beyond the DNS overhaul, the release brings 6 GHz WiFi band support, IMDSv2 authentication for AWS EC2 deployments, and critical patches for strongSwan and Intel processor microcode. Upgrading administrators should be aware that forwarded zones can no longer use fully-qualified domain names, requiring a quick manual swap to IP addresses before the transition completes.

IPFire Core Update 203 Swaps Unbound for Knot Resolver and Adds Native DNS Firewall @ Linux Compatible