• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

pfSense Community Edition (CE) 2.5.0 and pfSense Plus 21.02 now available!

Scheduled Pinned Locked Moved Messages from the pfSense Team
115 Posts 49 Posters 63.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    SebM @AndrewZ
    last edited by Feb 19, 2021, 3:43 PM

    @andrewz thanks for the suggestions. I actually did all that yesterday for quite a while, but seemed to also have DNS issues etc, so have re-installed 2.4.5-p1 and restored a backup.

    Re-install and restore was a challenge in itself since I run pfBlockerNG. Had to reinstall packages manually before the restore, and make sure it was using the right repo.

    E 1 Reply Last reply Feb 19, 2021, 3:52 PM Reply Quote 0
    • E
      edmund @SebM
      last edited by Feb 19, 2021, 3:52 PM

      @sebm - Mine "worked" initially but then quit after 12 hours - I think the cache emptied. I went to the DNS resolver settings and checked the box that says "Use SSL/TLS for outgoing DNS queries..." and it's working now.

      S 1 Reply Last reply Feb 19, 2021, 4:15 PM Reply Quote 0
      • S
        SebM @edmund
        last edited by Feb 19, 2021, 4:15 PM

        @edmund Thanks for adding this info. I was planning to upgrade again in a week or two once I’ve gathered enough troubleshooting data from others, so this will be useful.

        1 Reply Last reply Reply Quote 0
        • P
          plfinch
          last edited by Feb 19, 2021, 8:09 PM

          I attempted an upgrade of my SG-2440 backup firewall from 2.4.5p1 to 21.02 thru the GUI. Appliance no longer boots or functions. Console shows following on startup:

          Loading configured modules...
          can’t find ‘/etc/hostid’
          /boot/entropy size=0x1000
          -
          

          Then nothing.

          I was able to successfully clean-install 21.02 from USB memstick to this device without issue after the upgrade failed.

          C J P 3 Replies Last reply Feb 19, 2021, 8:19 PM Reply Quote 1
          • C
            chudak @plfinch
            last edited by Feb 19, 2021, 8:19 PM

            @plfinch said in pfSense Community Edition (CE) 2.5.0 and pfSense Plus 21.02 now available!:

            I attempted an upgrade of my SG-2440 backup firewall from 2.4.5p1 to 21.02 thru the GUI. Appliance no longer boots or functions. Console shows following on startup:

            Loading configured modules...
            can’t find ‘/etc/hostid’
            /boot/entropy size=0x1000
            -
            

            Then nothing.

            I was able to successfully clean-install 21.02 from USB memstick to this device without issue after the upgrade failed.

            not sure but maybe this is related https://twitter.com/NetgateUSA/status/1362791245546946561 ?

            1 Reply Last reply Reply Quote 0
            • J
              JeffV @plfinch
              last edited by Feb 19, 2021, 9:23 PM

              @plfinch
              Where did you get the 21.02 image? I have the same device and mine updated to 2.5.0 instead of 21.02. How do I get the 21.02 download link?

              J 1 Reply Last reply Feb 19, 2021, 9:31 PM Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator @JeffV
                last edited by Feb 19, 2021, 9:31 PM

                @jeffv said in pfSense Community Edition (CE) 2.5.0 and pfSense Plus 21.02 now available!:

                Where did you get the 21.02 image?

                If you want an actual image to do a clean install with - open a ticket with netgate, they will send you a link to image very quickly.. Took a whole 28 minutes the other day during the drop of new, while I am sure they are quite busy with legit tickets and not just requests for images.

                If you updated to 2.5 vs 21.02 - you were prob running the CE version on your netgate appliance vs the FE (factory edition)..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 1
                • M
                  matthijs
                  last edited by Feb 20, 2021, 7:51 AM

                  One big mess after upgrading to 2.5 with named/Bind, this is it, I am done with PFsense Netgate. I have those Issues with conflicting rndc ports between named and unbound for years forcing me to run the named/bind rndc port on a virtual IP instead of localhost/172.0.0.1 I am migrating to OPNSense now, bye bye PFSense

                  M 1 Reply Last reply Feb 20, 2021, 10:09 AM Reply Quote 1
                  • M
                    matthijs @matthijs
                    last edited by Feb 20, 2021, 10:09 AM

                    Update !

                    The issue is de Bind package,

                    [1/5] Installing protobuf-3.13.0,1...
                    [1/5] Extracting protobuf-3.13.0,1: .......... done
                    [2/5] Installing protobuf-c-1.3.2_6...
                    [2/5] Extracting protobuf-c-1.3.2_6: .......... done
                    [3/5] Installing fstrm-0.6.0...
                    [3/5] Extracting fstrm-0.6.0: .......... done
                    [4/5] Installing bind916-9.16.11...
                    [4/5] Extracting bind916-9.16.11: .......... done
                    [5/5] Installing pfSense-pkg-bind-9.16_9...
                    [5/5] Extracting pfSense-pkg-bind-9.16_9: .......... done
                    Saving updated package information...
                    overwrite!
                    Loading package configuration... done.
                    Configuring package components...
                    Loading package instructions...
                    Custom commands...
                    Executing custom_php_install_command()...done.
                    Executing custom_php_resync_config_command()...rndc: connect failed: 10.17.19.1#8953: timed out

                    The install procedure (resync config command) is trying to find de rncd port on the interface Bind/Named is bind to in my configuration (a virtual IP address) but I guess it is bind to 127.0.0.1 instead failing the installation/upgrade

                    Sucks Big Time because I have a very big and complex bind configuration with Acme integration, and have have this rndc issues for years now.

                    So this sucks big time for me !!

                    1 Reply Last reply Reply Quote 0
                    • E
                      edmund @dennis_s
                      last edited by Feb 20, 2021, 11:56 AM

                      @dennis_s said in pfSense Community Edition (CE) 2.5.0 and pfSense Plus 21.02 now available!:

                      Always take a backup of the firewall configuration prior to any major change to the firewall, such as an upgrade.

                      Everything would go much better if the upgrade process made a backup automatically and offered users the ability to quickly return to the previous release when they run into problems. I would see this as a major feature.

                      1 Reply Last reply Reply Quote 3
                      • M
                        mmichael @froussy
                        last edited by Feb 20, 2021, 2:51 PM

                        Hello,

                        thanks for the new Release. Update on two VM's was easy! But I have a issue with my IPSEC-Tunnels. The tunnels to Machines with 2.4.1 didn't come online.
                        A IPSEC-Tunnel between two 2.5 Machines is up - but on one Machine "marked as down" (but working).
                        For business use - I'll wait a bit bevor upgrading
                        Regards
                        Martin

                        1 Reply Last reply Reply Quote 0
                        • P
                          plfinch @plfinch
                          last edited by Feb 20, 2021, 3:17 PM

                          Upgrade of my primary firewall, an SG-5100, was successful via GUI update. I did experience the following:

                          1. Could not connect OpenVPN. Looks like pfSense Dynamic DNS did not actually update Google DNS after boot. I forced the update (“Save & Force Update”) and all good once propogated.

                          2. Arpwatch continually reported 2 devices flip-flopping on one IP. Rebooted both devices to resolve.

                          C 1 Reply Last reply Feb 20, 2021, 4:01 PM Reply Quote 0
                          • C
                            chudak @plfinch
                            last edited by Feb 20, 2021, 4:01 PM

                            @plfinch said in pfSense Community Edition (CE) 2.5.0 and pfSense Plus 21.02 now available!:

                            Upgrade of my primary firewall, an SG-5100, was successful via GUI update. I did experience the following:

                            1. Could not connect OpenVPN. Looks like pfSense Dynamic DNS did not actually update Google DNS after boot. I forced the update (“Save & Force Update”) and all good once propogated.

                            2. Arpwatch continually reported 2 devices flip-flopping on one IP. Rebooted both devices to resolve.

                            Did you have to redo OpenVPN ovpn config files for clients ?

                            P 1 Reply Last reply Feb 21, 2021, 12:43 AM Reply Quote 0
                            • G
                              gpfsenser
                              last edited by Feb 20, 2021, 9:12 PM

                              The update bricked my SG-1100. Had to access via serial (which took a bit because my OSX tool was not compatible with recent OS). After this serial connect issue was solved - lots of errors on the menu on pretty much every option. Opened a support ticket, downloaded recovery image, and reinstalled. Would recommend anyone with a netgate device to actually do this first just to have as a standby. Things running well now. Having your configuration backed up is a must. Thanks for the update! I hope the reliability of updates improves - I'm like 0/3 now. ;-) New version UI runs faster, package manager runs better - no downsides discovered yet.

                              S P 2 Replies Last reply Feb 20, 2021, 11:24 PM Reply Quote 2
                              • S
                                SebM @gpfsenser
                                last edited by Feb 20, 2021, 11:24 PM

                                @gpfsenser said in pfSense Community Edition (CE) 2.5.0 and pfSense Plus 21.02 now available!:

                                Opened a support ticket, downloaded recovery image, and reinstalled. Would recommend anyone with a netgate device to actually do this first just to have as a standby.

                                Underrated comment right there!

                                1 Reply Last reply Reply Quote 0
                                • P
                                  plfinch @chudak
                                  last edited by Feb 21, 2021, 12:43 AM

                                  Did you have to redo OpenVPN ovpn config files for clients ?

                                  No. No changes at all are required on the pfSense appliance or the openvpn client devices after upgrading. The openvpn config information is fully contained in the pfSense backup file. Even swapping to my standby/backup firewall loaded from the same config file, my client devices can connect without issue.

                                  1 Reply Last reply Reply Quote 1
                                  • P
                                    plfinch @gpfsenser
                                    last edited by Feb 21, 2021, 12:50 AM

                                    Opened a support ticket, downloaded recovery image, and reinstalled. Would recommend anyone with a netgate device to actually do this first just to have as a standby.

                                    Even after successfully upgrading my SG-5100 via the GUi, I went back and did a clean install from the memdisk image and reloaded the post-upgrade config backup. I always do this on updates to ensure I have a fresh clean build.

                                    S 1 Reply Last reply Feb 21, 2021, 1:38 AM Reply Quote 1
                                    • S
                                      SebM @plfinch
                                      last edited by Feb 21, 2021, 1:38 AM

                                      @plfinch said in pfSense Community Edition (CE) 2.5.0 and pfSense Plus 21.02 now available!:

                                      Opened a support ticket, downloaded recovery image, and reinstalled. Would recommend anyone with a netgate device to actually do this first just to have as a standby.

                                      Even after successfully upgrading my SG-5100 via the GUi, I went back and did a clean install from the memdisk image and reloaded the post-upgrade config backup. I always do this on updates to ensure I have a fresh clean build.

                                      Sounds pretty good actually, I like it the idea of a fresh install and also installing the default file system and other options (I think it’s ZFS now, right?)

                                      So restoring the backup of 2.4.5-p1 onto 21.02 shouldn’t be a problem, right?

                                      G 1 Reply Last reply Feb 21, 2021, 1:43 AM Reply Quote 0
                                      • G
                                        gpfsenser @SebM
                                        last edited by Feb 21, 2021, 1:43 AM

                                        @sebm For me - no issues faced, configuration restore worked on the first attempt.

                                        1 Reply Last reply Reply Quote 0
                                        • T
                                          tele_01
                                          last edited by Feb 21, 2021, 11:39 AM

                                          I've updated an APU2C4 from 2.4.5p1 to 2.5. After adjusting "Fallback Data Encryption Algorithm" to "None (No Encryption)" the setup was working fine with my uploaded backup data from 2.4.5p1. Also Squid and pfBlockerNG Devil are working well. A real impact is the VPN speed even if I've used nearly the same settings as my VPN provider taught and were existent under 2.4.5p1. I use OpenVPN with NordVPN and after updating the d/l speed is the half. Under 2.4.5p1 I've had about 96mbit now at about 50mbit. I've tried different options also under "Allow Compression" in the VPN Client settings but no change achieved so far. If this will is not getting better I'll go back to 2.4.5p1.

                                          T 1 Reply Last reply Feb 21, 2021, 11:43 AM Reply Quote 0
                                          62 out of 115
                                          • First post
                                            62/115
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received