Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Clean install of pfSense 23.05 Plus (Non-Netgate hardware)

    Problems Installing or Upgrading pfSense Software
    5
    18
    1.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Raffi_R
      Raffi_
      last edited by Raffi_

      https://docs.netgate.com/pfsense/en/latest/install/migrate-to-plus.html

      I would think the best way to do this would be fresh install of latest CE. Then follow docs to migrate to Plus (don't worry about version for now). Once you're on Plus, you should then be able to update to latest 23.05 Plus. If you have the same issues other's had including myself, the GUI upgrade from 23.01 to 23.05 may not work, from console run "pfsense-upgrade". It should solve that.

      E 1 Reply Last reply Reply Quote 0
      • E
        emikaadeo @Raffi_
        last edited by

        @raffi_ said in Clean install of pfSense 23.05 Plus (Non-Netgate hardware):

        https://docs.netgate.com/pfsense/en/latest/install/migrate-to-plus.html

        I would think the best way to do this would be fresh install of latest CE. Then follow docs to migrate to Plus (don't worry about version for now). Once you're on Plus, you should then be able to update to latest 23.05 Plus. If you have the same issues other's had including myself, the GUI upgrade from 23.01 to 23.05 may not work, from console run "pfsense-upgrade". It should solve that.

        This is what I did:

        • fresh install of 2.6.0 CE

        • upgrade to 23.01 Plus (23.05 wasn't available in GUI)

        • upgrade to 23.05

        • restore config

        Whole process went without any problems.

        4 Raffi_R Dobby_D 3 Replies Last reply Reply Quote 1
        • 4
          4o4rh @emikaadeo
          last edited by

          @emikaadeo i have put both CE 6 and CE 7 on. both can see the packages from its own branch. but when I select to upgrade to plus, it says unable to check for updates

          Raffi_R 1 Reply Last reply Reply Quote 0
          • Raffi_R
            Raffi_ @emikaadeo
            last edited by

            @emikaadeo perfect! Glad to hear that worked. Yes, that sounds like the only way.

            1 Reply Last reply Reply Quote 0
            • Raffi_R
              Raffi_ @4o4rh
              last edited by Raffi_

              @gwaitsi said in Clean install of pfSense 23.05 Plus (Non-Netgate hardware):

              @emikaadeo i have put both CE 6 and CE 7 on. both can see the packages from its own branch. but when I select to upgrade to plus, it says unable to check for updates

              Did you try following this doc from a fresh 2.6.0 CE?
              https://docs.netgate.com/pfsense/en/latest/install/migrate-to-plus.html

              1 Reply Last reply Reply Quote 0
              • Dobby_D
                Dobby_ @emikaadeo
                last edited by

                @emikaadeo said in Clean install of pfSense 23.05 Plus (Non-Netgate hardware):

                @raffi_ said in Clean install of pfSense 23.05 Plus (Non-Netgate hardware):

                https://docs.netgate.com/pfsense/en/latest/install/migrate-to-plus.html

                I would think the best way to do this would be fresh install of latest CE. Then follow docs to migrate to Plus (don't worry about version for now). Once you're on Plus, you should then be able to update to latest 23.05 Plus. If you have the same issues other's had including myself, the GUI upgrade from 23.01 to 23.05 may not work, from console run "pfsense-upgrade". It should solve that.

                This is what I did:

                • fresh install of 2.6.0 CE

                • upgrade to 23.01 Plus (23.05 wasn't available in GUI)

                • upgrade to 23.05

                • restore config

                Whole process went without any problems.

                Me too on PC Engines APU6B4 three time and
                until now all is fine now.

                #~. @Dobby

                Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
                PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
                PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

                4 1 Reply Last reply Reply Quote 0
                • 4
                  4o4rh @Dobby_
                  last edited by 4o4rh

                  @emikaadeo said in Clean install of pfSense 23.05 Plus (Non-Netgate hardware):

                  So I managed to get back up with the help of TAC Lite. In addition to yours below, I add my experience:

                  This is what I did:
                  fresh install of 2.6.0 CE

                  raise TAC Lite ticket to reset the authentication certificate (required if you can only get Update info/packages for Branch 2.6 or 2.7 - check from the console if you have athentication errors when running pfSense-upgrade

                   upgrade to 23.01 Plus (23.05 wasn't available in GUI)
                   upgrade to 23.05
                  

                  install missing packages i.e.pfblockerng, suricata, etc.

                     restore config
                  

                  The original backup should have a different backup Device ID (from a fresh install). When selecting the last "Creating restore point before package installation." and install this version, you will probably get the error "The downloaded file does not appear to contain an encrypted pfSense configuration.Could not decrypt config.xml. Check the encryption key and try again: Could not decrypt. Different encryption key?"

                  • click on the Show Info for the version to be restored and you will should have both the encrypted and unencrypted version if you used correct password.
                  • copy and paste the unencypted version to a new file config.xml
                  • transfer config.xml to /conf
                  • remove /tmp/config.cache
                  • reboot

                  I forgot to install a couple of packages, are discovered after the reboot that again my authentication certiface was bad. i guess it probably restored the original. Had to request a 2nd reset, before i could see the available packages again.

                  the root cause for my issues appears to be, impatience. When the gui says restarting in 10s and i was watching on the serial connection, it was actually a couple of minutes before the reboot occured. Then the installation continues a short while. so once kicking off the upgrade. I suggest to go grab a coffee and let it do its thing

                  E S 2 Replies Last reply Reply Quote 0
                  • E
                    emikaadeo @4o4rh
                    last edited by

                    @gwaitsi said in Clean install of pfSense 23.05 Plus (Non-Netgate hardware):

                     upgrade to 23.01 Plus (23.05 wasn't available in GUI)
                     upgrade to 23.05
                    

                    install missing packages i.e.pfblockerng, suricata, etc.

                    If you do a default config backup you don't have to install missing packages before config restore. When restoring config pfSense will install this packages for you.

                    4 1 Reply Last reply Reply Quote 0
                    • 4
                      4o4rh @emikaadeo
                      last edited by

                      @emikaadeo interesting, but the restore didn't restore the two missing packages for me

                      E 1 Reply Last reply Reply Quote 0
                      • E
                        emikaadeo @4o4rh
                        last edited by

                        @gwaitsi said in Clean install of pfSense 23.05 Plus (Non-Netgate hardware):

                        @emikaadeo interesting, but the restore didn't restore the two missing packages for me

                        My packages are only:

                        • pfBlockerNG

                        • System_Patches

                        • WireGuard

                        Every time I restore the config on fresh install, pfSense also install this packages by himself.

                        4 1 Reply Last reply Reply Quote 0
                        • 4
                          4o4rh @emikaadeo
                          last edited by

                          @emikaadeo said in Clean install of pfSense 23.05 Plus (Non-Netgate hardware):

                          @gwaitsi said in Clean install of pfSense 23.05 Plus (Non-Netgate hardware):

                          @emikaadeo interesting, but the restore didn't restore the two missing packages for me

                          My packages are only:

                          • pfBlockerNG

                          • System_Patches

                          • WireGuard

                          Every time I restore the config on fresh install, pfSense also install this packages by himself.

                          The packages i had forgot were wireguard and filer, but wouldn't make any difference, because the authentication certificate was no longer valid. It needed to be reset before any packages could be installed.

                          1 Reply Last reply Reply Quote 0
                          • S
                            SteveITS Galactic Empire @4o4rh
                            last edited by

                            @gwaitsi re: timing, yes it can take a while especially for an OS upgrade. See my sig.

                            Re:packages, if for some reason the WAN isn’t up yet the package install will fail. But it’s supposed to try. Note the upgrade guide recommends removing packages before upgrading. I usually remove “big” ones like pfBlocker and Suricata.
                            https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide-prepare.html#packages

                            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                            Upvote 👍 helpful posts!

                            Dobby_D 1 Reply Last reply Reply Quote 0
                            • Dobby_D
                              Dobby_ @SteveITS
                              last edited by

                              @SteveITS

                              24.05.2023 - 20:29 h (8:29 PM)
                              The last upgrade went faster, it was not rebooting in 10 seconds, it went more smooth and liquid and on
                              top of all it was also upgrading 3 pkg`s, well done.

                              2.7 devel vuln 4.jpg 2.7 devel vuln 3.jpg

                              #~. @Dobby

                              Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
                              PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
                              PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.