Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Now Available: pfSense® CE 2.8.0-RELEASE

    Scheduled Pinned Locked Moved Messages from the pfSense Team
    112 Posts 24 Posters 18.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      ramup
      last edited by

      Add on to the update policy of pfSense CE:

      I understand that maintaining CE software needs time and efforts and I am very fine with the update policy of pfSense itself (now two years since last bigger release) because I love pfSense and its stability since many years and do not consider to switch the product like others do and I don`t want to argue about update policy here.

      The only thing I find a bit inconsequent in the upgrade policy is my following example in respect of security issues of pfSense product / packages.

      I use SQUID package since years because of caching and ClamAV scanning (with MITM interception). I didnt notice that Netgate deprecated the package 1,5 years ago: [link Deprecation message](https://www.netgate.com/blog/deprecation-of-squid-add-on-package-for-pfsense-software) because I wasnt aware of and therefore proceeded using SQUID without awareness of security flaws.
      The issue with SQUID were obvious some security flaws in SQUID software but they were fixed with 6.10 version. Although these circumstances the package on pfSense (which still could be installed by users) stayed on version 6.8.
      I am happy that pfsense 2.8.0 now uses 6.12 SQUID version and I can proceed using pfSense with SQUID package.

      What I want to say is that it is a bit inconsequent to stop developing because of security issues (but still provide the package) and not fixing it when the security issues have been resolved.

      I know pfSense offers patches during lifetime for pfSense itself. But maybe you consider at least to offer also package updates during lifetime when security issues arise.

      Otherwise great job and I hope pfSense 2.8.0 keep on to fulfill my firewall needs with stability the upcoming years!

      B 1 Reply Last reply Reply Quote 0
      • W
        Waqar.UK
        last edited by

        Updated this morning. Using pfgblocker as an add on. Its service needed to be manually restarted and CPU was running at 52%. A restart of Pfsense and CPU usage went down to 1%. All so good so far.
        RAM drive usage went up from 8% to 13%.

        1 Reply Last reply Reply Quote 1
        • R
          ramup
          last edited by

          Further update on SQUID package. I just noticed that updating to 2.8.0 breaks SQUID package from running:

          1. Received PHP error after update from LightSquid described above

          2. System logs:

          May 29 10:20:45 php-fpm 409 /rc.start_packages: The command '/usr/local/sbin/squid -f /usr/local/etc/squid/squid.conf' returned exit code '1', the output was 'ld-elf.so.1: /usr/local/sbin/squid: Undefined symbol "_ZTVNSt3__117bad_function_callE"'

          May 29 10:20:44 php-fpm 409 /rc.start_packages: The command '/usr/local/libexec/squid/security_file_certgen -c -s /var/squid/lib/ssl_db -M 4MB' returned exit code '1', the output was 'ld-elf.so.1: /usr/local/libexec/squid/security_file_certgen: Undefined symbol "_ZTTNSt3__119basic_ostringstreamIcNS_11char_traitsIcEENS_9allocatorIcEEEE"'

          1. Reinstalling SQUID package and Lightsquid package does not fix the issue.
          1 Reply Last reply Reply Quote 0
          • B
            b3rt @ramup
            last edited by

            @ramup

            @ramup said in Now Available: pfSense® CE 2.8.0-RELEASE:

            I use SQUID package since years because of caching and ClamAV scanning (with MITM interception). I didnt notice that Netgate deprecated the package 1,5 years ago: [link Deprecation message](https://www.netgate.com/blog/deprecation-of-squid-add-on-package-for-pfsense-software) because I wasnt aware of and therefore proceeded using SQUID without awareness of security flaws.
            The issue with SQUID were obvious some security flaws in SQUID software but they were fixed with 6.10 version. Although these circumstances the package on pfSense (which still could be installed by users) stayed on version 6.8.

            the squid security issues have been patched as of december 2024... i think the documentation needs to be updated

            R 1 Reply Last reply Reply Quote 0
            • R
              ramup
              last edited by

              Fix for SQUID users updating from 2.7.2 to 2.8.0

              Found here: Topic

              Thanks to @JeGr

              -> Login to SSH console as root:

              mv /usr/lib/libc++.so.1 /root
              

              Reinstall Squid package -> service runs!

              J 1 Reply Last reply Reply Quote 0
              • R
                ramup @b3rt
                last edited by

                @b3rt I am not 100% sure but I believe pfSense CE 2.7.2 users did not receive a package update.

                B 1 Reply Last reply Reply Quote 0
                • B
                  b3rt @ramup
                  last edited by

                  @ramup said in Now Available: pfSense® CE 2.8.0-RELEASE:

                  @b3rt I am not 100% sure but I believe pfSense CE 2.7.2 users did not receive a package update.

                  I think there is no difference between CE / pfsense + package, it's all based on this package, no?
                  https://github.com/pfsense/FreeBSD-ports/commits/devel/www/pfSense-pkg-squid
                  And that by itself is behind the more up-to-date freebsd version.

                  R 2 Replies Last reply Reply Quote 0
                  • fireodoF
                    fireodo
                    last edited by

                    Hi,

                    the GUI update is offering me, when choosing 2.8.0 stable branch, the version 2.8.0.1500029 - is this correct?

                    Regards,
                    fireodo

                    Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                    SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                    pfsense 2.8.0 CE
                    Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                    stephenw10S 1 Reply Last reply Reply Quote 0
                    • P
                      Popolou
                      last edited by

                      Great news and thank you. Two years is a looong time in this industry mind you but the mob will indeed be pleased (if not reassured!).

                      1 Reply Last reply Reply Quote 0
                      • R
                        ramup @b3rt
                        last edited by

                        @b3rt
                        Yes there were differences between CE / plus users in respect of squid package.
                        CE users package stayed at 0.4.somewhat version while up-to-date-package was 0.5.3

                        1 Reply Last reply Reply Quote 0
                        • R
                          ramup @b3rt
                          last edited by

                          @b3rt
                          pfsense 2.7.2 users stayed at "Config Rev 23.3"
                          pfSense Versions
                          while pfSense Plus users changed to "Config Rev 23.6" on 2024-11-25 and higher since then.
                          pfSense 2.8.0 now uses "Config Rev 24.0" equally to pfSense Plus

                          B 1 Reply Last reply Reply Quote 0
                          • B
                            b3rt @ramup
                            last edited by

                            @ramup said in Now Available: pfSense® CE 2.8.0-RELEASE:

                            @b3rt
                            pfsense 2.7.2 users stayed at "Config Rev 23.3"
                            pfSense Versions
                            while pfSense Plus users changed to "Config Rev 23.6" on 2024-11-25 and higher since then.
                            pfSense 2.8.0 now uses "Config Rev 24.0" equally to pfSense Plus

                            right, that's all ok (:
                            are you sure this impacts the list of available packages? given these packages are by default not part of any pfsense version?

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator @fireodo
                              last edited by

                              @fireodo said in Now Available: pfSense® CE 2.8.0-RELEASE:

                              the version 2.8.0.1500029 - is this correct?

                              Yes, that's correct. The appended kernel version is the result of build system changes. The display code is fixed in 2.8.0 but 2.7.2 will still show that until you upgrade.

                              fireodoF 1 Reply Last reply Reply Quote 1
                              • fireodoF
                                fireodo @stephenw10
                                last edited by

                                @stephenw10 said in Now Available: pfSense® CE 2.8.0-RELEASE:

                                @fireodo said in Now Available: pfSense® CE 2.8.0-RELEASE:

                                the version 2.8.0.1500029 - is this correct?

                                Yes, that's correct. The appended kernel version is the result of build system changes. The display code is fixed in 2.8.0 but 2.7.2 will still show that until you upgrade.

                                Thanks!

                                Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                pfsense 2.8.0 CE
                                Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                                N 1 Reply Last reply Reply Quote 1
                                • N
                                  nimrod @fireodo
                                  last edited by

                                  Is there going to be offline installation image ? I dont see it here:

                                  https://atxfiles.netgate.com/mirror/downloads/

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Not currently. New installs of 2.8.0 are via the Net Installer only.

                                    N S K 3 Replies Last reply Reply Quote 0
                                    • N
                                      nimrod @stephenw10
                                      last edited by

                                      I just performed dirty update and it all worked without any issues. Good work guys and keep it up.

                                      1 Reply Last reply Reply Quote 1
                                      • S
                                        sTicKs23 @stephenw10
                                        last edited by

                                        @stephenw10 Did you guys atleast managed to include the other kernel drivers in the default kernels like iscsi or rs232? Or we need to compile it ourselves again?

                                        1 Reply Last reply Reply Quote 0
                                        • stephenw10S
                                          stephenw10 Netgate Administrator
                                          last edited by

                                          For any specific driver? It's pretty much the same included drivers as 2.7.2.

                                          1 Reply Last reply Reply Quote 0
                                          • K
                                            kikuyu @stephenw10
                                            last edited by

                                            @stephenw10
                                            I performed today a fresh install on new SSD from 2.7.2 to 2.8.0 with restore configuration from media during install. All went smooth. Perfect !!!

                                            1 Reply Last reply Reply Quote 1
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.