Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense Plus Software Version 24.11 is here!

    Scheduled Pinned Locked Moved Messages from the pfSense Team
    75 Posts 33 Posters 9.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • keyserK
      keyser Rebel Alliance @keyser
      last edited by

      @keyser said in pfSense Plus Software Version 24.11 is here!:

      Going to try out KEA DHCP now.....
      The switch to KEA DHCP has so far introduced no issues other than it starts handing new leases out (with no prior lease on record) - meaning clients will change their IP address at next renewal.
      I dunno if it will cause IP conflicts down the line with new clients getting IPs from still working ISC leases belonging to continuously active clients.

      But it upgraded with all settings kept - including static leases.

      I enabled Dynamic DNS and Early Dynamic DNS registration. Seems to works quite flawless this far :-)

      Love the no fuss of using the official appliances :-)

      keyserK 1 Reply Last reply Reply Quote 0
      • keyserK
        keyser Rebel Alliance @keyser
        last edited by

        @keyser I seem to no longer be able to edit my replies in this forum.... a little annoying with "quote" error in my last response

        Love the no fuss of using the official appliances :-)

        1 Reply Last reply Reply Quote 0
        • keyserK
          keyser Rebel Alliance
          last edited by

          Upgraded the first of many 2100's and it went flawlessly albeit it does take some time :-)

          Like my 6100 it upgraded with pfBlockerNG, Freeradius, NUT, TFTP, LLDP packages running - all without issues.

          I also moved to KEA DHCP4 backend after the upgrade, end experienced no problems on this box either. Seems like an overall good upgrade package. Let's see how it behaves the coming weeks.

          Love the no fuss of using the official appliances :-)

          1 Reply Last reply Reply Quote 1
          • M
            markster
            last edited by

            Upgraded 5100 without issues.

            Packages running include avahi, ntpd and nut. Switched to KEA DHCP no issues. Run external Unbound DNS on docker synology.
            No issues experienced.
            Great update. Thank you team.

            1 Reply Last reply Reply Quote 0
            • C
              coxhaus @mwatch
              last edited by

              @mwatch I put on 24.11-RC version a couple of days ago and everything was working great. So, this morning it said 24.11 was available and I thought it should work great since the RC is running so well. I upgraded and my Dell PC no longer worked. I could not ping my LAN interface. I assumed my license expired but it did not warn me. So, I pulled the NIC and installed it in an older Dell PC using 2.7.2

              1 Reply Last reply Reply Quote 0
              • J
                joedan
                last edited by

                Upgraded my custom box yesterday without drama and immediatly switched to using Kea.

                (Intel i5-8365U CPU @ 1.60GHz / 16GB memory / 2.5Gb igc)

                No issues at all, noticed slight connection improvements showing up on the monitoring graphs.

                I looked back to my monthly data and a previous reboot just over a week ago made no difference so something changed for the better in this upgrade for me.

                5573360e-7a54-4229-a15f-e3315b60e1da-image.png

                1 Reply Last reply Reply Quote 0
                • JonathanLeeJ
                  JonathanLee @delphin_007
                  last edited by

                  @delphin_007 has this issue resolved ?

                  Make sure to upvote

                  1 Reply Last reply Reply Quote 0
                  • S
                    SwissSteph
                    last edited by

                    Update carried out on my 8200, just a little scared because it took pkusieurs perides of “20 seconds” more for me to get the login page again.

                    All's well for now.

                    THANK YOU to all the team and happy new year!!!!

                    I started with two "no-name" pfsense, one for use at home and the other as a backup in case of problems (which can happen when you're new to pfsense).
                    ... And now I'm living with a Netgate 8200
                    ... And sorry for my bad English...

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      SwissSteph @SwissSteph
                      last edited by

                      @SwissSteph said in pfSense Plus Software Version 24.11 is here!:

                      Update carried out on my 8200, just a little scared because it took pkusieurs perides of “20 seconds” more for me to get the login page again.

                      All's well for now.

                      THANK YOU to all the team and happy new year!!!!

                      Update carried out on my 8200, just a little scared because it took several periods of “20 seconds” longer for me to get the login page again.

                      All's well for now.

                      THANK YOU to the whole team and happy new year! !!!

                      Modified my text for a better translation (sorry)

                      And a question, can we switch to “KEA” having “pfBbockerNG” trasparently or do we have to wait for a “tuto”!? Thanks again!

                      I started with two "no-name" pfsense, one for use at home and the other as a backup in case of problems (which can happen when you're new to pfsense).
                      ... And now I'm living with a Netgate 8200
                      ... And sorry for my bad English...

                      keyserK S 2 Replies Last reply Reply Quote 0
                      • keyserK
                        keyser Rebel Alliance @SwissSteph
                        last edited by

                        @SwissSteph said in pfSense Plus Software Version 24.11 is here!:

                        And a question, can we switch to “KEA” having “pfBbockerNG” trasparently or do we have to wait for a “tuto”!? Thanks again!

                        I have switched to KEA after 24.11 on alll my boxes without any issues. All of them runs pfBlockerNG so no tutorial needed - I just switched and have not done any additional config apart from enabling dynamic DNS registration.

                        Love the no fuss of using the official appliances :-)

                        S 1 Reply Last reply Reply Quote 0
                        • C
                          Cylosoft
                          last edited by

                          Am I just missing it or do the DHCP logs not show IP/MAC on IP registrations when you switch to Kea on 24.11?

                          stephenw10S 1 Reply Last reply Reply Quote 0
                          • S
                            SwissSteph @keyser
                            last edited by

                            @keyser

                            Thank you for your message and confirmation that “everything should go smoothly”. 👍

                            I started with two "no-name" pfsense, one for use at home and the other as a backup in case of problems (which can happen when you're new to pfsense).
                            ... And now I'm living with a Netgate 8200
                            ... And sorry for my bad English...

                            1 Reply Last reply Reply Quote 0
                            • GertjanG
                              Gertjan
                              last edited by

                              Upgraded to 24.11 from 24.03.
                              Selected in the GUI, System > Update > System Update : "24.11".
                              Then, from the console, as the views is so much better, option 13.

                              Better take a drink while you sit this one out, I thought.
                              When I came back search for one, everything was already downloaded and installing was well underway.
                              Love the small detail : while all this was going one, the Internet connection was just fine.

                              After the install, the system rebooted into the new "Boot environment" : no issues at all.
                              De reboot took slightly longer as usual as I didn't bother removing packages before upgrading.
                              A couple of seconds more, and there was the console menu.

                              Re connected to the GUI, and everything was as before.

                              4e56bb15-ece2-42d0-9a99-2a3a8a7ab295-image.png

                              Even connected portal users were still there ...
                              Less then 60 seconds down time.

                              I tested the OpenVPN server access (for my own personal remote admining ) : worked fine.
                              FreeRadius ; all ok.
                              pfBlockerng : still blocking.

                              No "help me" PM's please. Use the forum, the community will thank you.
                              Edit : and where are the logs ??

                              1 Reply Last reply Reply Quote 1
                              • M
                                marcosm Netgate @FollyDude 0
                                last edited by

                                @FollyDude-0 said in pfSense Plus Software Version 24.11 is here!:

                                @mwatch

                                Installed on SG-6100 went OK. The only issue I see at this time is that the dashboard System Services Status widget is showing Wireguard as down.

                                I have checked the Wireguard connection and it looks OK, it is connected. I have tried a reboot (also tried a cold start) and no change. I have tried starting Wireguard from the widget play button. So it looks like the widget has an issue, not wireguard itself.

                                Cheers

                                Steve

                                Create a new thread if you're still seeing the issue. For reference, the status looks for the process name stored in the config. You can test this by running pgrep php_wg - if it's running, you should see e.g. 40125.

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S
                                  stephenw10 Netgate Administrator @Cylosoft
                                  last edited by

                                  @Cylosoft Yes the logging options in Kea are limited right now. This was better than the default 'flood'! More options coming.

                                  M 1 Reply Last reply Reply Quote 1
                                  • M
                                    michmoor LAYER 8 Rebel Alliance @stephenw10
                                    last edited by

                                    @stephenw10
                                    BTW....That nice feeling i get when MIM is faster than going through the pfsense GUI
                                    You guys did a great job here with the responsiveness. So far I'm making changes that way as its more performant i find and that's on a SG1100

                                    Firewall: NetGate,Palo Alto-VM,Juniper SRX
                                    Routing: Juniper, Arista, Cisco
                                    Switching: Juniper, Arista, Cisco
                                    Wireless: Unifi, Aruba IAP
                                    JNCIP,CCNP Enterprise

                                    1 Reply Last reply Reply Quote 3
                                    • T
                                      tman222
                                      last edited by

                                      I went ahead and upgraded to 24.11 yesterday and overall things went fairly smoothly. Ran into a few issues along the way, some of which have already been documented in other posts:

                                      1. Higher CPU usage when viewing dashboard:

                                      https://forum.netgate.com/topic/190824/cpu-load-on-1100

                                      1. “Another instance of pfSense-upgrade is running” - saw this as well when when I first tried to upgrade. Error went away after waiting a couple minutes:

                                      https://forum.netgate.com/topic/195329/huh-another-instance-of-pfsense-upgrade-is-running

                                      1. FreeRadius BlastRADIUS warnings in the System Logs - not sure yet how to mitigate these; have started a thread:

                                      https://forum.netgate.com/topic/195376/freeradius-blastradius-warning-in-system-logs-how-to-mitigate

                                      1. Abnormally high SERVFAIL messages from DNS look ups after upgrading - these were high enough that websites would regularly fail to load. I'm still investigating the cause as everything worked fine in pfSense 24.03 and prior versions. I do see that unbound was upgraded from 1.19.3 to 1.22.0 so perhaps some changes were made that resulted in this behavior. For now the workaround that has helped to get rid of the excessive SERVFAIL errors, has been to explicitly disable IPv6 in unbound by setting do-ip6 to no in the Custom options section (I don't currently use IPv6 so this should not cause any issues). However, more investigation will be needed.

                                      Overall though this has been a great release - thanks Netgate team for all your hard work!

                                      1 Reply Last reply Reply Quote 0
                                      • T
                                        tgl @mwatch
                                        last edited by

                                        @mwatch Updated a 4200 to this release about six hours ago. Saw the same “Another instance of pfSense-upgrade is running” strangeness others have reported, though that clearly must be the fault of the prior release (24.03) not this one. Otherwise, smooth upgrade and no problems noted since then. The dashboard widgets fill in noticeably more quickly than in 24.03. I don't see any indication of increased CPU load, although I use a fairly minimal set of widgets.

                                        1 Reply Last reply Reply Quote 0
                                        • S
                                          SteveITS Galactic Empire @SwissSteph
                                          last edited by

                                          @SwissSteph ignore the countdown timer. Upgrades take from a few minutes to 10-15 minutes or so depending on disk write speed and CPU power, and whether one removes packages first (per the upgrade guide).

                                          After a half hour if you still see the timer, connect a console cable, do not just power off.

                                          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                          Upvote 👍 helpful posts!

                                          S 1 Reply Last reply Reply Quote 1
                                          • S
                                            SwissSteph @SteveITS
                                            last edited by

                                            @SteveITS
                                            Thank you for this message and your advice, I'll keep it to the letter. For me and this new version everything went very well.
                                            I also got the message “Another instance of pfSense-upgrade is running”, I rebooted pfsense and the message was no longer present)

                                            I also switched to “KEA”, thanks to your encouragement ... all OK for me

                                            I started with two "no-name" pfsense, one for use at home and the other as a backup in case of problems (which can happen when you're new to pfsense).
                                            ... And now I'm living with a Netgate 8200
                                            ... And sorry for my bad English...

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.