Version 4.16.0-1 Scheduled Release is out for pfSense®, ASUS®, and VyOS® and OpenWRT as of 2 July 2026.
The major feature addition to this release is Underminr mitigation:
- Underminr (UMR): implemented mitigations as seen on the Dashboard → Policy UI
- Underminr: implemented a quarantine action on UMR detection
- Underminr: implemented a feature to strip ECH details from DNS answers
- Underminr: implemented packet monitor parser to kill flows upon UMR detection
Muscle changes on all platforms:
- Implemented Multiple Enablers to use the same FQDN
- Implemented default deny of query of type
ANY - Implemented default rate limited for non-enroled sources
- Implemented
block-local-queriesconfig switch - Implemented
block-ip-addressesconfig switch - Implemented a default to block
AandAAAArecords for domains ending inip6.arpaip4.arpaandin-addr.arpa - Added the following config switches to control the otherwise automatic endpoint enrolment:
disable-discovery-arp– disable device discovery using ARP (IPv4 neighbour discovery)
disable-discovery-nd– disable device discovery using ND (IPv6 neighbour discovery)
disable-discovery-netbios– disable device discovery using NETBIOS
disable-discovery-fm– disable device discovery using file monitor (e.g. DHCP files)
disable-discovery-dns– disable device discovery using DNS - Added support for wireguard interfaces in packet monitor. Previously, WireGuard traffic did not separately appear in the traffic log.
- Added new traffic log DTTS column label of
Active Traffic(UDP and non-syn TCP packets, usually established traffic).
pfSense® changes:
- Restructured Enablers for performance and efficiency reasons (some checkins times are now reduced by over 95%)
ASUS® changes:
- N/A
VyOS® changes:
- New
IP_ONLY_DISCOVERY_SUBNETSenvironment variable to configure subnets where you want the MAC hardware address to be ignored. - New
HIJACK_DNSenvironment variable to auto-configure DNS hijacking. - Fix for extra newlines being added to the configuration file.
OpenWRT changes:
- This is our second major release on this platform and is available on limited OpenWRT routers with aarch64 and x86_64 architectures running OpenWrt v24.10. For Early Access, request it here.
Special thanks to all the testers that made this possible.
For installation of adam:ONE® see:
- pfSense®: adamnet.io/pfsense
- ASUS®: adamnet.io/asus
- VyOS®: adamnet.io/vyos
- OpenWRT instructions coming soon
Note on automatic upgrades
During adamone-setup configure installation wizard, we recommend the default to automatically upgrade adam:ONE® software. When that default is selected, the attempt will be made based on contents in /etc/crontab (pfSense®) or cru l (on ASUS®).
Thank you
– Adam Networks team