Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Which ports need to be open for Update detection ?

    Problems Installing or Upgrading pfSense Software
    4
    4
    1.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      ricardop
      last edited by

      On an AWS installarion of 2.3 I have the "Obtaining update status " continuously spinning, probably due to restrictive blocking on the NetworkACL or SecurityGroup. Do you know which ports (and possible target IPs) need to be open for Update checks to work ?
      Thanks

      1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan
        last edited by

        It's probably
        https://updates.pfsense.org/_updaters/
        This means : port 443, not a port that could be blocked.

        But I guess your  issue is different.
        DNS is working ?
        Can you
        ping updates.pfsense.org
        from the webgui ? Does it resolve to an IP ?

        PING updates.pfsense.org (162.208.119.39): 56 data bytes
        64 bytes from 162.208.119.39: icmp_seq=0 ttl=49 time=114.551 ms
        64 bytes from 162.208.119.39: icmp_seq=1 ttl=49 time=142.796 ms
        64 bytes from 162.208.119.39: icmp_seq=2 ttl=49 time=114.759 ms
        
        --- updates.pfsense.org ping statistics ---
        3 packets transmitted, 3 packets received, 0.0% packet loss
        round-trip min/avg/max/stddev = 114.551/124.035/142.796/13.266 ms
        

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • J
          JorgeOliveira
          last edited by

          In addition to the information on the above post, you should also check if your pfSense install can access https://pkg.pfsense.org. This is the repository where the 2.3.x+ updates come from.

          My views have absolutely no warranty express or implied. Always do your own research.

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            For AWS, you need 80 and 443 to firmware.netgate.com only.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.