Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Updating pfBlockerNG-devel on 23.09 caused instability. Upgrading to 23.09.1 (w/ 3.2.0_8) solved it.

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    28 Posts 8 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Raffi_R
      Raffi_
      last edited by Raffi_

      I ran into this same exact issue with pfblockerNG-devel update hanging and then the GUI also hanging.

      I was able to solve this via SSH. Make sure you close your browser.

      ran

      pkg delete pfSense-pkg-pfblockerNG-devel
      

      It complained another process was holding it up.

      kill <whatever process ID # it complained about>
      

      ran this again

      pkg delete pfSense-pkg-pfblockerNG-devel
      

      It got stuck loading something or other like the GUI update.

      Opened a second SSH session.

      top -aSH
      
      kill <process ID # of the php-fpm process(es) which are at or near 100% CPU usage>
      

      I had three of them I had to kill.

      ran this one more time to confirm it was removed.

      pkg delete pfSense-pkg-pfblockerNG-devel
      

      If it complains again about a process holding it, kill that again.

      Then I was able to login to the GUI and install pfblockerNG-devel no problem.

      I'm on 24.03. I checked to see if there was a pfsense update since this behavior is very similar to what happens when you update a package before updating pfsense. I am not seeing any pfsense updates available.

      I ended up with the crash report below when I got back into the GUI.

      [24-Sep-2024 11:10:26 America/New_York] PHP Fatal error:  Maximum execution time of 900 seconds exceeded in /etc/inc/util.inc on line 3733
      [24-Sep-2024 11:12:31 America/New_York] PHP Fatal error:  Maximum execution time of 900 seconds exceeded in /etc/inc/util.inc on line 3733
      
      
      1 Reply Last reply Reply Quote 2
      • J
        jc1976
        last edited by

        these are the clearest problems thus far on remedying this problem..

        Thank you for providing them.

        I had this issue last night, although i'm on ce 2.7.2. do you think that'll matter?

        at the moment i get an nginx 502 error when i try to go to the pfsense gui. is that what you experienced as well?

        Raffi_R 1 Reply Last reply Reply Quote 0
        • Raffi_R
          Raffi_ @jc1976
          last edited by

          @jc1976 yeah I had the same error. My steps fixed that.

          J 1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            The pfBlockerNG development pkg has now been updated to remove that issue. 3.2.0_17 is safe to upgrade to.

            Raffi_R J 2 Replies Last reply Reply Quote 2
            • Raffi_R
              Raffi_ @stephenw10
              last edited by

              @stephenw10 thanks for the tip.
              It seems like 3.2.0_17 is the version the GUI ended up installing after having all this trouble and going through the steps outlined.

              1 Reply Last reply Reply Quote 2
              • J
                jc1976 @Raffi_
                last edited by

                @Raffi_

                THANK YOU THANK YOU THANK YOU!!

                that worked.. took a bit of figuring out, dunno how you only had 3 php processes holding you up because I had 20+, but it worked!!

                once i got into the gui i was able to go to the package manager and run the install of 3.2.0_17 and that went through without a hitch..

                thankfully, all my configs were still there so when it installed, all came back without any interaction from me..

                thanks again!

                1 Reply Last reply Reply Quote 3
                • J
                  jc1976 @stephenw10
                  last edited by

                  @stephenw10

                  i have another firewall that i manage and it shows the update to 3.2.0_8..

                  obviously i want to skip that upgrade.. is it possible to upgrade directly to 3.2.0_17, bypassing 3.2.0_8 so I don't have to deal with it's problems?

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    3.2.0_8 is OK. That's the package version for the non-devel package.

                    The problem versions were _15 and _16 but that was only ever the development package. Neither of those should be available anywhere now. You should only see no update for non-dev or _17 for the devel.

                    J 1 Reply Last reply Reply Quote 0
                    • J
                      jc1976 @stephenw10
                      last edited by

                      @stephenw10

                      I use the dev version on both firewalls. both firewalls have the same configuration and the one that blew up on me was for _8.

                      as of this moment, looking at installed packages, mine says it's on 3.2.0_8, with a prompt to update.
                      this was the same on my other firewall that i had to repair.

                      i don't see anything to indicate the update would be to 3.2.0_17.

                      am i reading this wrong? I always thought the version shown in the package manager is the version it would be updated to.

                      my fear is that being this is my firewall at my office that many others are dependent on, i can't risk the downtime so i just want to be sure that it will update to the latest repaired version without any issue.

                      thanks!!

                      Raffi_R 1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Well the safest option is to do nothing. Just don't update it.

                        If you mouse-over the update symbol in the package manager it shows what version is available:

                        Screenshot from 2024-09-25 16-19-16.png

                        J 1 Reply Last reply Reply Quote 0
                        • J
                          jc1976 @stephenw10
                          last edited by

                          @stephenw10

                          ahh, didn't know about the mousing-over part.. so yeah, i see it..

                          Thanks!!

                          1 Reply Last reply Reply Quote 1
                          • Raffi_R
                            Raffi_ @jc1976
                            last edited by

                            @jc1976

                            my fear is that being this is my firewall at my office that many others are dependent on, i can't risk the downtime so i just want to be sure that it will update to the latest repaired version without any issue.

                            lol I had this issue on the office firewall when I first ran into it. I can assure you there was no downtime. Everything still worked as intended including my OpenVPN for remote access. Just the GUI access and the pfblocker update was an issue. I'm not entirely sure if pfblocker was still functional during this time, but that was really not a big deal if it was down for the few minutes it took me to resolve this issue. Pfblocker was back up after the update and then force reload.

                            T 1 Reply Last reply Reply Quote 0
                            • T
                              tordini @Raffi_
                              last edited by

                              @Raffi_ Thx, thx and thx for your advice, This saved my day. I didn't use ssh but the built in command promt. Killed every pid associating with "pkg delete yes pfSense-pkg-pfblockerNG-devel" and finally
                              I could use the dashboard again. What a relief, and the package was removed from package manager.
                              Now I installed the none dev version of pfblock. It's been two days of nervousness since my firewall is in a production environment. Many thx Raffi_, my command vas kill pid_nr & pkg delete --yes pfSense-pkg-pfblockerNG-devel. I created an account here on netgate only to express my gratitude.👍

                              Raffi_R 1 Reply Last reply Reply Quote 3
                              • Raffi_R
                                Raffi_ @tordini
                                last edited by

                                @tordini

                                Now I installed the none dev version of pfblock. It's been two days of nervousness since my firewall is in a production environment. Many thx Raffi_, my command vas kill pid_nr & pkg delete --yes pfSense-pkg-pfblockerNG-devel. I created an account here on netgate only to express my gratitude.👍

                                I haven't been on these forums for some time. Is the pfblockerNG-devel an actual development version now? I'm getting the feeling it is now, but it wasn't in the past. In the past it was just the name given to the latest version.

                                When you installed pfblockerNG non dev, did all your config and settings carry over?

                                T 1 Reply Last reply Reply Quote 0
                                • stephenw10S
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  The config is the same for both packages. It will carry across if you uninstall/install either.

                                  Raffi_R 1 Reply Last reply Reply Quote 1
                                  • Raffi_R
                                    Raffi_ @stephenw10
                                    last edited by

                                    @stephenw10 said in Updating pfBlockerNG-devel on 23.09 caused instability. Upgrading to 23.09.1 (w/ 3.2.0_8) solved it.:

                                    The config is the same for both packages. It will carry across if you uninstall/install either.

                                    Thanks, good to know.

                                    Is the dev version an actual dev version now? In other words, is the non dev version recommended for production environments ?

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      It still is the development version, new features/fixes are added there first. However it's now much closer to the non-dev package. A while ago it was a long way ahead but that's no longer the case.

                                      1 Reply Last reply Reply Quote 1
                                      • T
                                        tordini @Raffi_
                                        last edited by

                                        @Raffi_ Yes sir, it worked perfectly, no error and no hickups

                                        Raffi_R 1 Reply Last reply Reply Quote 1
                                        • Raffi_R
                                          Raffi_ @tordini
                                          last edited by

                                          @tordini thanks, I switched over to the non-devel package also and it's working fine.

                                          The only minor issue I have now is the percentage of domains blocked counter on the dashboard is pegged at 100% which is wrong. I had this issue a long time ago, I ignored it back then and I'll do the same now.

                                          1 Reply Last reply Reply Quote 0
                                          • GPinzoneG GPinzone referenced this topic on
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.