Good morning everyone,Security updates for Squid, Suricata and NTP are now available, although more are pending which would indicate a version 18.1.4 later this week. Also, a number of firewall section fixes have been included.Here are the full patch notes:o system: account for variable headers in top outputo system: move gateway status into main pageso system: slightly reorder routing configuration callso system: optimize reading of SSL crypto library version string (contributed by Alexander Shursha)o system: rework LDAP authentication container selectiono interfaces: avoid interaction of overview details with menu itemso interfaces: allow "reject leases from" option in DHCP advanced settingso firewall: set alias cron update interval to 1 minuteo firewall: align alias cron update with its background callo firewall: URL IP alias type missing in selectionso firewall: fix defunct alias target in outbound NATo firewall: ignore alias case while searchingo firewall: move rule category filter to the top of the pageo firewall: show IPv6 ports in live log and fix details for TCPo firewall: move general settings to AliasParser and fix Alias constructor to receive themo firewall: if the name of the alias equals its content try to resolveo dhcp: advertisement problem on PPPoE link without public IPv6 address (contributed by Team Rebellion)o dhcp: UEFI 64 network boot using wrong arch typeo dhcp: validate maximum interface MTUo dhcp: add validation for DUID fieldso ipsec: auto-route disable setting (contributed by Namezero)o network time: inline NMEA checksum calculator (contributed by Fabian Franz)o network time: fix stratum level writeo unbound: optimize outgoing-range differentlyo unbound: local zone setting (contributed by NOYB)o ui: fix cropped dropdown regressiono mvc: translate option values (contributed by Alexander Shursha)o mvc: fix access to undefined property translatoro mvc: fix typo in getBase()o mvc: improve phpdoco rc: protect console menu again, but keep shell invoke for rc.d subsystemo rc: fix some typos (contributed by John Eismeier)o rc: proper includes for plugin post-install hooko rc: recover all known shellso plugins: os-clamav 1.5 fixes log file parsingo plugins: os-frr 1.1 fixes service start on booto plugins: os-haproxy 2.5[1] with PROXY support and HAProxy 1.8 (contributed by Frank Wall)o plugins: os-monit 1.5 (contributed by Frank Brendel)o ports: mpd 5.8[2]o ports: ntp 4.2.8p11[3]o ports: squid 3.5.27[4][5]o ports: suricata 4.0.4[6]Stay safe,Your OPNsense team--[1] https://github.com/opnsense/plugins/pull/541 [2] https://reviews.freebsd.org/D9848 [3] http://support.ntp.org/bin/view/Main/SecurityNotice#February_2018_ntp_4_2_8p11_NTP_S [4] http://www.squid-cache.org/Advisories/SQUID-2018_1.txt [5] http://www.squid-cache.org/Advisories/SQUID-2018_2.txt [6] https://suricata-ids.org/2018/02/14/suricata-4-0-4-available/