Release Notes

[x86] Version 3.5.0

Release Date: September 4, 2026

New Features

  • Out-of-band file extraction for FTP and SMB: files transferred over FTP and SMB can be carved from network traffic out-of-band and submitted for inspection, without interrupting the transfer.

  • SPAN monitoring in Transparent mode: SPAN port mirroring is now supported for transparent pairs, with a simplified SPAN configuration workflow.

  • NAT and IPsec enhancements: NAT for IPsec tunnels, and Virtual IP support for IPsec; network and IPsec tunnel interfaces now support configurable MTU; an IPsec VPN tunnel can be selected as the egress path for the OT Access gateway.

  • Force password change on first login: administrators are now required to change the default password at first access.

  • MetaDefender Core integration: Scanning a file extraction.

Improvements/Updates

  • Updated Monitor mode enforcement: firewall rules are now enforced in Monitor mode: traffic without a matching firewall rule is blocked, while traffic that does not match the DPI profile continues to be detected and reported without being blocked.

  • Service status columns: configuration pages now display the live operational status of each entry, in addition to its enabled/disabled setting: External Services (Connected / Unreachable / Failed), Static ARP (Valid / Invalid), Virtual IP (Not / Partially / Fully Configured), Time Server (Synchronized / Not Synchronized / Failed), VRRP (Master / Backup / Fault), IPsec (Established / Connecting / Inactive), Static Routing (Valid / Invalid), and Management Access (Valid / Invalid).

  • Dashboard now displays per-core CPU usage instead of a single aggregate number.

  • Improved external-service logging, including NTP service events.

  • VPN: Local WAN IP is auto-populated from the selected Local Gateway interface.

  • Various UI refinements (rule-table direction tooltips, DPI profile editing consistency).

  • Bug fixes

  • Upgrade from versions 3.3.x and 3.4.x to 3.5.x works as expected.

[ARM] Version 3.5.0

Release Date: August 28, 2026. New 2-ports hardware.

Improvements/Updates

  • ARM platform support: MetaDefender Industrial Firewall can now be deployed on ARM64-based appliances, extending hardware options beyond x86.

  • MetaDefender Kiosk integration: Integrates with MetaDefender Kiosk so that [removable-media scan results / device check-in status] can be [enforced at the firewall / viewed centrally], closing the gap between media scanning and network enforcement.

Version 3.4.3

Release Date: August 11, 2026

Improvements/Updates

  • Layer-2 switching feature set: Spanning Tree (STP/MSTP/MRP), management on a VLAN interface, SPAN/RSPAN port mirroring in Transparent mode, and duplication of outgoing traffic to two ports.

  • Password policy: password strength/expiry and authorization, with expiry warning banners.

  • New user roles: the "User" role is renamed Auditor and a new Operator role with alert-acknowledge permission is added.

  • Silent Capture: background packet capture with day-grouped file browsing and a redesigned capture page.

  • Central Management (OCM) improvements: enable/disable interfaces from CM, import/export of routing firewall rules, agent-token refresh lifecycle with CM-unreachable/token-expired warnings, automatic re-enrollment on 401.

  • Improve log for external services (NTP and RADIUS)

  • Improve IPSec:

    • Configurable MTU for network interfaces and IPsec tunnel interfaces.

    • OTA Gateway: select an IPsec VPN tunnel as egress path to the OT device

  • Bug Fixes

  • Upgrade from versions 3.2.x and 3.3.x to 3.4.x works as expected.

Version 3.4.2

Release Date: June 30, 2026

Improvements/Updates

  • Command-Line Interface (CLI): A full SSH command-line interface for managing the device — System Settings, Time Settings, Network (IP Configuration and Port Mode), Firewall Rules (Routing & Transparent), Routing- and Transparent-mode settings, Learning Mode (Routing & Transparent), DoS Protection, ARP Protection, Management Access, DPI Profiles, and configuration/system backup export/import via USB.

  • Deep Packet Inspection for VNC: VNC is now available as a DPI profile protocol, so VNC remote-desktop traffic can be inspected and controlled at the function level.

  • Switching: New Layer 2 switching capabilities — VLAN-aware bridge, MAC Address Table management, and SPAN/RSPAN port mirroring.

  • 8-Port Model: Support for up to three transparent pairs, plus load balancing in Routing mode.

  • Port Controls: Enable or disable USB ports and individual Ethernet ports.

  • RADIUS / TACACS+ Authentication: External authentication server support for administrator login.

  • Read-Only User Role: A user account role with view-only access to firewall rules and configuration.

  • Dashboard Customization: Customizable dashboard with new widgets — Alert by Protocol, Alert Over Time, Inbound & Outbound Monitor, and Rule Hit Count Monitor.

  • Object Management in Firewall Learning Mode: Reuse named IP objects when reviewing and accepting learned policies.

  • OPSWAT Central Management (OCM): System backup, enable/disable Ethernet ports, and log viewing are now available from OCM.

  • Smaller firmware image: Reduced image size.

  • Upgrade from versions 3.2.x and 3.3.x to 3.4.x works as expected.

Version 3.4.1

Release Date: May 29, 2026

Improvements/Updates

  • Stronger Network Protection: ARP Protection, ARP Binding (routing + transparent), violation logging.

  • Broader Hardware Support: MetaDefender Industrial Firewall 8-Port multi-revision installation.

  • Manage Your Fleet from One Place**:**

    • Full OCM feature inventory (rules, DPI, NAT, MAC filter, VLANs, VRRP, OSPF/RIP, ARP, Object Management, External Services, etc.).

    • Apply Policies/Firmware to Many Devices at Once.

  • Multi-gateway OTA support: devices can connect to multiple OTA Server.

  • Support Dial-up IPSec, IPSec UI fixes.

  • Fix minor bugs.

  • Upgrade from versions 3.2.x and 3.3.x to 3.4.x works as expected.

Version 3.4.0

Release Date: March 31, 2026

Improvements/Updates

  • Separate Layer 2 (L2) and Layer 3 (L3) rules for Transparent Mode

  • ARP Protection

  • Change System Rules to Management Access

  • OCM Integration, including:

    • Dashboard

    • Alerts page

    • License activation

    • Port and IP configuration

    • Firewall rule management

    • Management access

  • Fix existing bugs

  • Upgrade from versions 3.2.x and 3.3.x to 3.4.0 works as expected.