Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2.7.0 Issues

    Scheduled Pinned Locked Moved General pfSense Questions
    38 Posts 7 Posters 4.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • TAC57T
      TAC57
      last edited by

      I just upgraded to 2.7.0 I'm seeing the follow two issues.

      1. Unable to check for updates

      2. An error occurred while uploading the encrypted pfSense configuration to https://acb.netgate.com/save (Connection timed out after 30000 milliseconds) @ 2023-06-30 07:33:30

      I was having these same issues with pfsense+.

      JKnottJ 1 Reply Last reply Reply Quote 0
      • jimpJ jimp moved this topic from Problems Installing or Upgrading pfSense Software on
      • JKnottJ
        JKnott @TAC57
        last edited by

        @TAC57

        2.7.0 also failed for me. I'm also getting that unable to check for updates. I also see all my installed packages are gone.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        GertjanG 1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @JKnott
          last edited by

          @JKnott
          and also "https://acb.netgate.com" is not reachable ?
          I can assure you that I can reach it - I was using 23.05 last week, 23.05.1 RC this morning and 23.05.1 right now.
          A DNS issue ?
          A 'it's using IPv6' issue (I know, don't laugh) -> force IPv4 usage on the command line, see forum how to do so.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          JKnottJ 1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @Gertjan
            last edited by

            @Gertjan said in 2.7.0 Issues:

            and also "https://acb.netgate.com" is not reachable ?

            When I put that in a browser, I can connect, but with an IPv4 address. Isn't it supposed to be IPv6 too? This forum has an IPv6 address.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @JKnott
              last edited by Gertjan

              @JKnott

              [23.05.1-RELEASE][root@pfSense.bhf.net]/root: host forum.netgate.com
              forum.netgate.com has address 208.123.73.199
              forum.netgate.com has IPv6 address 2610:160:11:18::199
              
              [23.05.1-RELEASE][root@pfSense.bhf.net]/root: host netgate.com
              netgate.com has address 199.60.103.104
              netgate.com has address 199.60.103.4
              netgate.com has IPv6 address ::ffff:199.60.103.4
              netgate.com has IPv6 address ::ffff:199.60.103.104
              netgate.com mail is handled by 30 aspmx4.googlemail.com.
              netgate.com mail is handled by 30 aspmx3.googlemail.com.
              netgate.com mail is handled by 20 alt2.aspmx.l.google.com.
              netgate.com mail is handled by 30 aspmx5.googlemail.com.
              netgate.com mail is handled by 10 aspmx.l.google.com.
              netgate.com mail is handled by 20 alt1.aspmx.l.google.com.
              netgate.com mail is handled by 30 aspmx2.googlemail.com.
              
              [23.05.1-RELEASE][root@pfSense.bhf.net]/root: host acb.netgate.com
              acb.netgate.com has address 208.123.73.212
              

              So IPv4 only.

              Only the forum uses IPv6 I guess.
              And the update servers etc.

              @JKnott said in 2.7.0 Issues:

              This forum has an IPv6 address.

              I'm posting here using IPv6 only for many years now.

              edit : compare
              pkg-static -d -6 update
              with
              pkg-static -d -4 update

              to know if it is a 4/6 issue.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              N JKnottJ 2 Replies Last reply Reply Quote 0
              • N
                nimrod @Gertjan
                last edited by

                ews.netgate.com also needs to be reachable.

                GertjanG 1 Reply Last reply Reply Quote 0
                • JKnottJ
                  JKnott @Gertjan
                  last edited by

                  @Gertjan said in 2.7.0 Issues:

                  So IPv4 only.

                  Well, whether IPv4 or IPv6, it should still work. I just checked again and still unable to update.

                  PfSense running on Qotom mini PC
                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                  UniFi AC-Lite access point

                  I haven't lost my mind. It's around here...somewhere...

                  JKnottJ 1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @nimrod
                    last edited by

                    @nimrod said in 2.7.0 Issues:

                    ews.netgate.com also needs to be reachable.

                    Dono who that is or what it does, but it resolves and replies to my pings - IPv4 only.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    TAC57T N 2 Replies Last reply Reply Quote 0
                    • TAC57T
                      TAC57 @Gertjan
                      last edited by TAC57

                      I had these same issues with 23.05. And think it was related to this issue.

                      https://forum.netgate.com/topic/178413/major-dns-bug-23-01-with-quad9-on-ssl/181

                      I was hoping this would have been fixed in 2.7 CE.

                      S 1 Reply Last reply Reply Quote 0
                      • N
                        nimrod @Gertjan
                        last edited by

                        @Gertjan said in 2.7.0 Issues:

                        @nimrod said in 2.7.0 Issues:

                        ews.netgate.com also needs to be reachable.

                        Dono who that is or what it does, but it resolves and replies to my pings - IPv4 only.

                        It needs to be reachable. Otherwise you cant update or install any package. Talking about IPv4 of course.

                        1 Reply Last reply Reply Quote 0
                        • S
                          SteveITS Galactic Empire @TAC57
                          last edited by

                          @TAC57 said in 2.7.0 Issues:

                          I was hoping this would have been fixed in 2.7 CE.

                          https://docs.netgate.com/pfsense/en/latest/releases/2-7-0.html#dns-resolver
                          "Fixed: DNS Resolver experiences intermittent resolution failures with SSL over TLS due to ASLR #14056"

                          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                          Upvote 👍 helpful posts!

                          1 Reply Last reply Reply Quote 0
                          • JKnottJ
                            JKnott @JKnott
                            last edited by

                            @JKnott

                            Any fix for this?

                            PfSense running on Qotom mini PC
                            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                            UniFi AC-Lite access point

                            I haven't lost my mind. It's around here...somewhere...

                            1 Reply Last reply Reply Quote 0
                            • T
                              Tzvia
                              last edited by

                              Hmmm... I'm not using forwarding with DOT or DOH, just straight resolving, but had issues where packages would not download and install after I imported my 2.6 backup. I hadn't upgraded (put the MSATA with 2.6 aside as an emergency 'roll back'), instead did a fresh install of 2.7. Then fixed up what was WAN and what was LAN, thinking that with at least those corrected, I could login and do the setup wizard, then restore my backup and that would handle the other interfaces/vlans and the packages. Well, nope. No packages attempted to install, no banner about packages installing please wait a few hours... nothing. I rebooted. Nothing. I should have taken a peek to see what branch it thought it was in, but instead I just imported my backup again... Finally got the dang banner and I waited maybe 8 minutes for the packages to install. So while not a perfect install execution, it did finally setup properly. If the issues here with you guys can be traced to that DOT issue not really being fixed, the issue would hopefully resolve if you sent it to resolve instead? Or maybe a host override (would that work for the firewall itself trying to resolve something?). Just thinking out loud here...

                              Tzvia

                              Current build:
                              Hunsn/CWWK Pentium Gold 8505, 6x i226v 'micro firewall'
                              16 gigs ram
                              500gig WD Blue nvme
                              Using modded BIOS (enabled CSTATES)
                              PFSense 2.72-RELEASE
                              Enabled Intel SpeedShift
                              Snort
                              PFBlockerNG
                              LAN and 5 VLANS

                              S JKnottJ 2 Replies Last reply Reply Quote 0
                              • S
                                SteveITS Galactic Empire @Tzvia
                                last edited by

                                @Tzvia Usually if packages fail to restore it’s because pfSense can’t connect out (yet) so the attempt fails. One can reinstall packages from the GUI as well.
                                https://docs.netgate.com/pfsense/en/latest/packages/manager.html#reinstalling-and-updating-packages

                                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                Upvote 👍 helpful posts!

                                T TAC57T 2 Replies Last reply Reply Quote 0
                                • JKnottJ
                                  JKnott @Tzvia
                                  last edited by JKnott

                                  @Tzvia said in 2.7.0 Issues:

                                  instead did a fresh install of 2.7

                                  I have been considering that and then reinstalling the packages. However, why is this problem even happening? Is the problem in 2.6 or the server?

                                  PfSense running on Qotom mini PC
                                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                  UniFi AC-Lite access point

                                  I haven't lost my mind. It's around here...somewhere...

                                  1 Reply Last reply Reply Quote 0
                                  • T
                                    Tzvia @SteveITS
                                    last edited by

                                    @SteveITS Yes I know- that is why before I do anything on a fresh install- at the console, I set the WAN and LAN - as my LAN is IGB0 and my WAN is IGB1 (don't ask). I set those manually, then run the wizard and afterwards, verify I have working internet. THEN I import the settings, thinking that it should be able to DL the packages... This has worked for me in the past but not this time. And as I had mentioned, no DOT/DOH or any DNS forwarding, just resolving to roots. PFSense just plain didn't attempt to download packages but it did pick up all the rest of my settings; VLANS and what packages I SHOULD have. But they were 'not installed' and no indication that they were installing either, no banner, nothing. But I had internet...

                                    I don't know if anyone here had tried to import their settings again.. or tried setting DNS back to straight resolving and then attempting to re-import... If it works, curious if it would continue to if you then manually set it back to forwarding with DOT.

                                    Tzvia

                                    Current build:
                                    Hunsn/CWWK Pentium Gold 8505, 6x i226v 'micro firewall'
                                    16 gigs ram
                                    500gig WD Blue nvme
                                    Using modded BIOS (enabled CSTATES)
                                    PFSense 2.72-RELEASE
                                    Enabled Intel SpeedShift
                                    Snort
                                    PFBlockerNG
                                    LAN and 5 VLANS

                                    1 Reply Last reply Reply Quote 0
                                    • TAC57T
                                      TAC57
                                      last edited by TAC57

                                      @Jknott I've been using pfsense forever! Not a single problem with 2.6.0. I jumped to pfsense+ and started getting issues with unable to check for updates, unable to backup my config files, problems with app updates, etc. I was told it was a DNS problem and I must a bad configuration issue somewhere. I finally went back to 2.6.0 and everything was cool. I figured when v2.7 was released the DNS issues wouldn't be there but that doesn't appear to be the case.

                                      Now I reload pfsense 2.6 iso, try to load my config file and get told it won't load any packages because I need to upgrade to 2.7. When I up grade to 2.7 I get 'No packages installed.' When I got to the package manager I'm told:
                                      6006ccaa-8870-43ad-ac31-b865bd003a5b-image.png
                                      How do I deal with this?

                                      S JKnottJ 2 Replies Last reply Reply Quote 0
                                      • TAC57T
                                        TAC57 @SteveITS
                                        last edited by

                                        @SteveITS See my additional reply below.
                                        d5ea277d-a5ff-4fdf-a492-0524ccdae43c-image.png
                                        Kind of hard to reinstall anything.

                                        1 Reply Last reply Reply Quote 0
                                        • S
                                          SteveITS Galactic Empire @TAC57
                                          last edited by

                                          @TAC57 if using 2.6 you’ll need to change the update branch to Previous Stable so it downloads packages for 2.6. Note that will work until 2.8 is released, and Previous=2.7.

                                          I’ve seen your other threads and don’t really have an answer. DNS should work out of the box. Does everything work if you reset the config to factory defaults? You can restore your config afterwards.

                                          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                          Upvote 👍 helpful posts!

                                          1 Reply Last reply Reply Quote 0
                                          • JKnottJ
                                            JKnott @TAC57
                                            last edited by

                                            @TAC57 said in 2.7.0 Issues:

                                            I've been using pfsense forever! Not a single problem with 2.6.0. I jumped to pfsense+ and started getting issues with unable to check for updates, unable to backup my config files, problems with app updates, etc. I was told it was a DNS problem and I must a bad configuration issue somewhere.

                                            I have been running pfSense for about 6.5 years and it's always been fine. When I go to the command line, in pfSense, I can successfully ping acb.netgate.com and ews.netgate.com, so that rules out any DNS problem.

                                            PfSense running on Qotom mini PC
                                            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                            UniFi AC-Lite access point

                                            I haven't lost my mind. It's around here...somewhere...

                                            N 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.