Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2.7.0 Issues

    Scheduled Pinned Locked Moved General pfSense Questions
    38 Posts 7 Posters 5.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG
      Gertjan @JKnott
      last edited by

      @JKnott
      and also "https://acb.netgate.com" is not reachable ?
      I can assure you that I can reach it - I was using 23.05 last week, 23.05.1 RC this morning and 23.05.1 right now.
      A DNS issue ?
      A 'it's using IPv6' issue (I know, don't laugh) -> force IPv4 usage on the command line, see forum how to do so.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @Gertjan
        last edited by

        @Gertjan said in 2.7.0 Issues:

        and also "https://acb.netgate.com" is not reachable ?

        When I put that in a browser, I can connect, but with an IPv4 address. Isn't it supposed to be IPv6 too? This forum has an IPv6 address.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        GertjanG 1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @JKnott
          last edited by Gertjan

          @JKnott

          [23.05.1-RELEASE][root@pfSense.bhf.net]/root: host forum.netgate.com
          forum.netgate.com has address 208.123.73.199
          forum.netgate.com has IPv6 address 2610:160:11:18::199
          
          [23.05.1-RELEASE][root@pfSense.bhf.net]/root: host netgate.com
          netgate.com has address 199.60.103.104
          netgate.com has address 199.60.103.4
          netgate.com has IPv6 address ::ffff:199.60.103.4
          netgate.com has IPv6 address ::ffff:199.60.103.104
          netgate.com mail is handled by 30 aspmx4.googlemail.com.
          netgate.com mail is handled by 30 aspmx3.googlemail.com.
          netgate.com mail is handled by 20 alt2.aspmx.l.google.com.
          netgate.com mail is handled by 30 aspmx5.googlemail.com.
          netgate.com mail is handled by 10 aspmx.l.google.com.
          netgate.com mail is handled by 20 alt1.aspmx.l.google.com.
          netgate.com mail is handled by 30 aspmx2.googlemail.com.
          
          [23.05.1-RELEASE][root@pfSense.bhf.net]/root: host acb.netgate.com
          acb.netgate.com has address 208.123.73.212
          

          So IPv4 only.

          Only the forum uses IPv6 I guess.
          And the update servers etc.

          @JKnott said in 2.7.0 Issues:

          This forum has an IPv6 address.

          I'm posting here using IPv6 only for many years now.

          edit : compare
          pkg-static -d -6 update
          with
          pkg-static -d -4 update

          to know if it is a 4/6 issue.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          N JKnottJ 2 Replies Last reply Reply Quote 0
          • N
            nimrod @Gertjan
            last edited by

            ews.netgate.com also needs to be reachable.

            GertjanG 1 Reply Last reply Reply Quote 0
            • JKnottJ
              JKnott @Gertjan
              last edited by

              @Gertjan said in 2.7.0 Issues:

              So IPv4 only.

              Well, whether IPv4 or IPv6, it should still work. I just checked again and still unable to update.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              JKnottJ 1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan @nimrod
                last edited by

                @nimrod said in 2.7.0 Issues:

                ews.netgate.com also needs to be reachable.

                Dono who that is or what it does, but it resolves and replies to my pings - IPv4 only.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                TAC57T N 2 Replies Last reply Reply Quote 0
                • TAC57T
                  TAC57 @Gertjan
                  last edited by TAC57

                  I had these same issues with 23.05. And think it was related to this issue.

                  https://forum.netgate.com/topic/178413/major-dns-bug-23-01-with-quad9-on-ssl/181

                  I was hoping this would have been fixed in 2.7 CE.

                  S 1 Reply Last reply Reply Quote 0
                  • N
                    nimrod @Gertjan
                    last edited by

                    @Gertjan said in 2.7.0 Issues:

                    @nimrod said in 2.7.0 Issues:

                    ews.netgate.com also needs to be reachable.

                    Dono who that is or what it does, but it resolves and replies to my pings - IPv4 only.

                    It needs to be reachable. Otherwise you cant update or install any package. Talking about IPv4 of course.

                    1 Reply Last reply Reply Quote 0
                    • S
                      SteveITS Galactic Empire @TAC57
                      last edited by

                      @TAC57 said in 2.7.0 Issues:

                      I was hoping this would have been fixed in 2.7 CE.

                      https://docs.netgate.com/pfsense/en/latest/releases/2-7-0.html#dns-resolver
                      "Fixed: DNS Resolver experiences intermittent resolution failures with SSL over TLS due to ASLR #14056"

                      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                      Upvote 👍 helpful posts!

                      1 Reply Last reply Reply Quote 0
                      • JKnottJ
                        JKnott @JKnott
                        last edited by

                        @JKnott

                        Any fix for this?

                        PfSense running on Qotom mini PC
                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                        UniFi AC-Lite access point

                        I haven't lost my mind. It's around here...somewhere...

                        1 Reply Last reply Reply Quote 0
                        • T
                          Tzvia
                          last edited by

                          Hmmm... I'm not using forwarding with DOT or DOH, just straight resolving, but had issues where packages would not download and install after I imported my 2.6 backup. I hadn't upgraded (put the MSATA with 2.6 aside as an emergency 'roll back'), instead did a fresh install of 2.7. Then fixed up what was WAN and what was LAN, thinking that with at least those corrected, I could login and do the setup wizard, then restore my backup and that would handle the other interfaces/vlans and the packages. Well, nope. No packages attempted to install, no banner about packages installing please wait a few hours... nothing. I rebooted. Nothing. I should have taken a peek to see what branch it thought it was in, but instead I just imported my backup again... Finally got the dang banner and I waited maybe 8 minutes for the packages to install. So while not a perfect install execution, it did finally setup properly. If the issues here with you guys can be traced to that DOT issue not really being fixed, the issue would hopefully resolve if you sent it to resolve instead? Or maybe a host override (would that work for the firewall itself trying to resolve something?). Just thinking out loud here...

                          Tzvia

                          Current build:
                          Hunsn/CWWK Pentium Gold 8505, 6x i226v 'micro firewall'
                          16 gigs ram
                          500gig WD Blue nvme
                          Using modded BIOS (enabled CSTATES)
                          PFSense 2.72-RELEASE
                          Enabled Intel SpeedShift
                          Snort
                          PFBlockerNG
                          LAN and 5 VLANS

                          S JKnottJ 2 Replies Last reply Reply Quote 0
                          • S
                            SteveITS Galactic Empire @Tzvia
                            last edited by

                            @Tzvia Usually if packages fail to restore it’s because pfSense can’t connect out (yet) so the attempt fails. One can reinstall packages from the GUI as well.
                            https://docs.netgate.com/pfsense/en/latest/packages/manager.html#reinstalling-and-updating-packages

                            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                            Upvote 👍 helpful posts!

                            T TAC57T 2 Replies Last reply Reply Quote 0
                            • JKnottJ
                              JKnott @Tzvia
                              last edited by JKnott

                              @Tzvia said in 2.7.0 Issues:

                              instead did a fresh install of 2.7

                              I have been considering that and then reinstalling the packages. However, why is this problem even happening? Is the problem in 2.6 or the server?

                              PfSense running on Qotom mini PC
                              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                              UniFi AC-Lite access point

                              I haven't lost my mind. It's around here...somewhere...

                              1 Reply Last reply Reply Quote 0
                              • T
                                Tzvia @SteveITS
                                last edited by

                                @SteveITS Yes I know- that is why before I do anything on a fresh install- at the console, I set the WAN and LAN - as my LAN is IGB0 and my WAN is IGB1 (don't ask). I set those manually, then run the wizard and afterwards, verify I have working internet. THEN I import the settings, thinking that it should be able to DL the packages... This has worked for me in the past but not this time. And as I had mentioned, no DOT/DOH or any DNS forwarding, just resolving to roots. PFSense just plain didn't attempt to download packages but it did pick up all the rest of my settings; VLANS and what packages I SHOULD have. But they were 'not installed' and no indication that they were installing either, no banner, nothing. But I had internet...

                                I don't know if anyone here had tried to import their settings again.. or tried setting DNS back to straight resolving and then attempting to re-import... If it works, curious if it would continue to if you then manually set it back to forwarding with DOT.

                                Tzvia

                                Current build:
                                Hunsn/CWWK Pentium Gold 8505, 6x i226v 'micro firewall'
                                16 gigs ram
                                500gig WD Blue nvme
                                Using modded BIOS (enabled CSTATES)
                                PFSense 2.72-RELEASE
                                Enabled Intel SpeedShift
                                Snort
                                PFBlockerNG
                                LAN and 5 VLANS

                                1 Reply Last reply Reply Quote 0
                                • TAC57T
                                  TAC57
                                  last edited by TAC57

                                  @Jknott I've been using pfsense forever! Not a single problem with 2.6.0. I jumped to pfsense+ and started getting issues with unable to check for updates, unable to backup my config files, problems with app updates, etc. I was told it was a DNS problem and I must a bad configuration issue somewhere. I finally went back to 2.6.0 and everything was cool. I figured when v2.7 was released the DNS issues wouldn't be there but that doesn't appear to be the case.

                                  Now I reload pfsense 2.6 iso, try to load my config file and get told it won't load any packages because I need to upgrade to 2.7. When I up grade to 2.7 I get 'No packages installed.' When I got to the package manager I'm told:
                                  6006ccaa-8870-43ad-ac31-b865bd003a5b-image.png
                                  How do I deal with this?

                                  S JKnottJ 2 Replies Last reply Reply Quote 0
                                  • TAC57T
                                    TAC57 @SteveITS
                                    last edited by

                                    @SteveITS See my additional reply below.
                                    d5ea277d-a5ff-4fdf-a492-0524ccdae43c-image.png
                                    Kind of hard to reinstall anything.

                                    1 Reply Last reply Reply Quote 0
                                    • S
                                      SteveITS Galactic Empire @TAC57
                                      last edited by

                                      @TAC57 if using 2.6 you’ll need to change the update branch to Previous Stable so it downloads packages for 2.6. Note that will work until 2.8 is released, and Previous=2.7.

                                      I’ve seen your other threads and don’t really have an answer. DNS should work out of the box. Does everything work if you reset the config to factory defaults? You can restore your config afterwards.

                                      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                      Upvote 👍 helpful posts!

                                      1 Reply Last reply Reply Quote 0
                                      • JKnottJ
                                        JKnott @TAC57
                                        last edited by

                                        @TAC57 said in 2.7.0 Issues:

                                        I've been using pfsense forever! Not a single problem with 2.6.0. I jumped to pfsense+ and started getting issues with unable to check for updates, unable to backup my config files, problems with app updates, etc. I was told it was a DNS problem and I must a bad configuration issue somewhere.

                                        I have been running pfSense for about 6.5 years and it's always been fine. When I go to the command line, in pfSense, I can successfully ping acb.netgate.com and ews.netgate.com, so that rules out any DNS problem.

                                        PfSense running on Qotom mini PC
                                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                        UniFi AC-Lite access point

                                        I haven't lost my mind. It's around here...somewhere...

                                        N 1 Reply Last reply Reply Quote 0
                                        • N
                                          nimrod @JKnott
                                          last edited by

                                          I did fresh install of 2.7 and restored my old 2.6 config. No issues whatsoever.

                                          JKnottJ TAC57T 2 Replies Last reply Reply Quote 0
                                          • JKnottJ
                                            JKnott @nimrod
                                            last edited by

                                            @nimrod

                                            I guess I'll have to do the same, if a better solution doesn't turn up.

                                            PfSense running on Qotom mini PC
                                            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                            UniFi AC-Lite access point

                                            I haven't lost my mind. It's around here...somewhere...

                                            JKnottJ 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.