Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Now Available: pfSense® Plus 25.07-RELEASE

    Scheduled Pinned Locked Moved Messages from the pfSense Team
    72 Posts 29 Posters 7.3k Views 22 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S Offline
      stephenw10 Netgate Administrator
      last edited by

      Hmm, nothing obviously wrong there. Do you see an alert after it reboots into 24.11?

      Check System > Boot Environments. Do you see the new 25.07.1 BE marked as failed?

      1 Reply Last reply Reply Quote 0
      • S Offline
        SteveITS Rebel Alliance @johan333
        last edited by

        @johan333 Based on other posts…

        see if /cf/conf/backup is full. If so delete files or visit Diagnostics >Backup> Configuration history until it doesn’t time out. There was a bug where they weren’t automatically deleted.

        Delete old/unnecessary boot environments. (Ignore the “size” shown)

        Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 1
        • stephenw10S Offline
          stephenw10 Netgate Administrator
          last edited by

          Yup, very good point. Since it appears to be failing at 'updating configuration' check for far too many backups.

          1 Reply Last reply Reply Quote 0
          • J Offline
            johan333
            last edited by

            Thank you for the help.

            @stephenw10 - I would've expected to see some type of kernel panic notice based on this behavior, but no alerts whatsoever. I have the SG2100 console port connected via USB to a RaspberryPi device and logging the console output via screen. Yes, as per the screenshots, it states the BE failed to verify.

            675af835-8b12-4dc1-b9b9-19d63d69f1c8-image.png

            5b0c24d1-c9bc-46c5-ad5e-3e92bec5ed8e-image.png

            @SteveITS - Interesting...I'll give the GUI diagnostic screen a try. Here's what /cf/conf/backup has:

            [24.11-RELEASE][root@pfSense.home.lan]/: du -sh /cf/conf/backup
            2.0G    /cf/conf/backup
            [24.11-RELEASE][root@pfSense.home.lan]/: ls -l /cf/conf/backup | wc -l
               12318
            
            
            S 1 Reply Last reply Reply Quote 0
            • S Offline
              SteveITS Rebel Alliance @johan333
              last edited by

              @johan333 said in Now Available: pfSense® Plus 25.07-RELEASE:

              12318

              That's it, then. Should be ~30 files by default.

              There were a couple bugs at play, pfBlocker updates a timestamp in the file every cron run, and the backups were not being pruned automatically. So every hour for a year or more... I've seen a few posts here and on Reddit with similar update failure.

              Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
              Upvote 👍 helpful posts!

              M J 2 Replies Last reply Reply Quote 3
              • M Offline
                mcury Rebel Alliance @SteveITS
                last edited by

                @SteveITS said in Now Available: pfSense® Plus 25.07-RELEASE:

                There were a couple bugs at play, pfBlocker updates a timestamp in the file every cron run,

                25.07.1 has this issue with pfBlockerNG.
                4e86827d-290d-42a9-9c35-7713ea20dd43-image.png

                But Maximum Backups option is working.

                dead on arrival, nowhere to be found.

                S 1 Reply Last reply Reply Quote 0
                • J Offline
                  johan333 @SteveITS
                  last edited by

                  @SteveITS Wow, very interesting and great insight. Based on the evidence, I would've never come to this discovery/conclusion. The diag page does time out BTW, so I'll just manually prune it and try the update again. Know if the bug was fixed in 25.07 and if not what is the work-around people are using (e.g. CRON job)?

                  1 Reply Last reply Reply Quote 0
                  • S Offline
                    SteveITS Rebel Alliance @mcury
                    last edited by

                    @mcury said in Now Available: pfSense® Plus 25.07-RELEASE:

                    25.07.1 has this issue with pfBlockerNG

                    I don't have a link handy but I'm pretty sure Netgate posted that's been fixed in a later version? Or there was a patch in that forum somewhere. It's worse if using pfB in HA because the secondary was getting multiple config files because of its cron plus the sync at cron time.

                    I have a note to check config history before starting an update.

                    diag page does time out

                    It will but if you keep reloading after that, and be patient it should eventually load. I think mine timed out after 10 minutes and had deleted most of the files.

                    25.7 fixed the history retention.

                    Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                    Upvote 👍 helpful posts!

                    M 1 Reply Last reply Reply Quote 1
                    • M Offline
                      mcury Rebel Alliance @SteveITS
                      last edited by

                      @SteveITS said in Now Available: pfSense® Plus 25.07-RELEASE:

                      I don't have a link handy but I'm pretty sure Netgate posted that's been fixed in a later version?

                      Redmine #14409
                      DNSBL is also disabled here, so it seems that 25.07.1 didn't bring that fix?

                      dead on arrival, nowhere to be found.

                      M 1 Reply Last reply Reply Quote 1
                      • M Offline
                        mcury Rebel Alliance @mcury
                        last edited by

                        I'm opening a new thread about the pfBlockerNG and configuration history.

                        dead on arrival, nowhere to be found.

                        1 Reply Last reply Reply Quote 1
                        • stephenw10S Offline
                          stephenw10 Netgate Administrator
                          last edited by

                          Yeah the backup config trimming is fixed now.

                          Yes if you visit the backups page it will prune them. Eventually. And if you ever visited that page previously it would have done so many users never saw it.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.