Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unplug WAN before device flash?

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 3 Posters 743 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      furom
      last edited by furom

      Hi,

      had my fair share of reinstalls between 22.05 and 23.01 and wonder what the normal, or best practice even for this might be. I usually download what I need locally and then unplug WAN. But as good as it may be, also comes with implications of not being able to download latest patches, packages and what-not during install. So, does the Netgate block WAN as usual during flash/setup procedures, or is it in fact a good or necessary strategy to unplug?

      And while at it, which is the recommended method? Upgrading or bare-metal flash?

      S Dobby_D 2 Replies Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @furom
        last edited by

        @furom Installs do reinstall packages (though upgrade advice is to uninstall yourself first, and reinstall after). So I would not disconnect WAN. Restores will also install packages in the restored config file.

        Normally there is no problem upgrading. Upgrading doesn't replace the file system so for instance when ZFS became the default (on most hardware) it needs a new install. If something goes haywire during the upgrade then reinstalling and restoring from backup config is often the fastest and most reliable way to recover. I've only had that problem I think twice in about 15 years on all our clients, not counting the current bug on the older models 1100/2100 upgrading to 23.01.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        F 1 Reply Last reply Reply Quote 1
        • F
          furom @SteveITS
          last edited by

          @steveits agreed. I usually prefer the upgrade over bare-metal too. Over the years I have seen it as a last resort "when all else failed". But now even that gave me a bit och challenge. @stephenw10 spotted the issue quickly though. :)

          1 Reply Last reply Reply Quote 0
          • Dobby_D
            Dobby_ @furom
            last edited by

            @furom

            It all depends also where you are using this firewall in my eyes! If you use it in production case it is better to have a spare unit or testing unit or perhaps a HA setup that you
            can swap over in the case of problems and for the private
            usage it might be not really interesting. In both cases a backup and settings backup may be the best.

            I prefer to install 2.7 (zfs) and then upgrade to 23.01 RC
            installing the packets and reinstall the setting backup.

            #~. @Dobby

            Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
            PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
            PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

            F 1 Reply Last reply Reply Quote 1
            • F
              furom @Dobby_
              last edited by

              @dobby_ said in Unplug WAN before device flash?:

              It all depends also where you are using this firewall

              Good point! Totally agree that the environment it is used in is key to what procedure would be preferred in most cases. Point of my question here was mainly to find out if my network is vulnerable during the flash process, ie is my network still safe with a half installed netgate device between my network and the internet... Perhaps I'm being just a tiny bit too paranoid, but I do take security seriously, and not claiming to know or assume I know it all... Just curious and want to learn best practice whenever I can :)

              S 1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @furom
                last edited by

                @furom OK I understand your question now. My impression is it downloads, then installs during the reboot so I would think everything would be off at that point. You can try pinging out during the reboot but I fully expect nothing is routing in that state.

                The word "flash" I usually associate with a firmware update as opposed to a software update. That's closer to how the Netgate ARM devices work where you boot to a Marvell> prompt and run a process to copy the image from USB to the hard drive. In that state no OS is running, so no routing.

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote ๐Ÿ‘ helpful posts!

                F 1 Reply Last reply Reply Quote 1
                • F
                  furom @SteveITS
                  last edited by

                  @steveits said in Unplug WAN before device flash?:

                  In that state no OS is running, so no routing

                  Perfect, this was what I was after. Thank you

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.