pfSense Plus 21.05-RELEASE Now Available
-
We are pleased to announce that pfSense Plus 21.05-RELEASE is now available for new installations and upgrades! For more information on this release, please see our blog.
Highlights for this release:
- Firewall processing engine performance improvements
- WireGuard can now be installed as an experimental add-on package
- A new OpenVPN Client Import Package that will streamline the configuration of site-to-site VPN connections
- Additional hardware support
- Fixes for AES-NI, SafeXcel, and CESA encryption modules
- 50+ bug fixes and other minor improvements
For more details, see the Release Notes, Plus Redmine, and Redmine Issues for CE and Plus.
Always take a backup of the firewall configuration prior to any major change to the firewall, such as an upgrade.
Do not update packages before upgrading! Either remove all packages or do not update packages before running the upgrade.
The upgrade will take several minutes to complete. The exact time varies based on download speed, hardware speed, and other factors such as installed packages. Be patient during the upgrade and allow the firewall enough time to complete the entire process. After the update packages finish downloading it could take 10-20 minutes or more until the upgrade process ends. The firewall may reboot several times during the upgrade process. Monitor the upgrade from the firewall console for the most accurate view.
If the update check fails, or the update does not complete, run
pkg install -y pfSense-upgrade
to ensure thatpfSense-upgrade
is present. -
-
Thanks - already got 21.05 image from support. Just in case. 5 minute total time of submit ticket to when I had link to image file for "just in case" use..
Now when I can find some down time will do the upgrade.
edit: updated sg4860 to 21.05, 5 minutes - no issues..
-
After some Days with the RC, the Update run fast and boring, just works.
Nice Work! -
SG3100 (zero packages installed). rebooted.
waited 25 minutes for the update to install. never came back available, pulled the plug / plugged back in and watched the console and the update completed...
got the latest install from support. Wiped and reloaded from a backup
-
Installed successfully in my SG-3100, everything is already UP and running.
Got 21.05 image from support, so it's a clean install.ACME and pfblockerng_dev installed and configured, everything is running smoothly.
-
Bug #11466 is still open for SG-3100. Is there a target release when this will be resolved?
-
Updated two SG5100 and two SG3100 so far with no issues.
-
How do I contact support for an image if I do not have support contract?
I have three or four 4860 that are on older versions. I want to have an image on standby in case something goes wrong. -
@brians Just email them. You don't need a support contract to download an image.
-
Exactly - I do not have any sort of support contract.
Just go here and create an account.
https://go.netgate.com/support/signup
Then create a ticket requesting firmware or maybe software upgrade prob would of been better. There are drop down options for what the ticket is for, etc. I will have to remember that for next time. Last couple of requests I have used firmware access - and just in the body of the ticket state what want - install image for whatever version your looking for, etc.
example - here was my ticket requesting 21.05
You can view your netgate id and serial number in the web gui
-
@maxk-0 said in pfSense Plus 21.05-RELEASE Now Available:
Bug #11466 is still open for SG-3100. Is there a target release when this will be resolved?
You can fix it by applying patch https://redmine.pfsense.org/issues/11466#note-32
-
@johnpoz said in pfSense Plus 21.05-RELEASE Now Available:
Thanks - already got 21.05 image from support. Just in case. 5 minute total time of submit ticket to when I had link to image file for "just in case" use..
John... they must not like you anymore... 5 minutes... pffftt! j/k
I didn't get to things until late this afternoon and even "after hours" (7:17pm Texas time) my response time was less than 2 minutes. You just can't complain about that.
Rick
-
@viktor_g Thanks. I saw that patch/workaround too but would like to know if/when a fix will be incorporated into the next release.
-
@ramosel said in pfSense Plus 21.05-RELEASE Now Available:
response time was less than 2 minutes
haha - yeah they pretty much johnny on the spot for sure.. Now when 2.5/21.02 first dropped - there was a bit of delay.. It was like 28 minutes ;)
-
Upgraded my SG-1100 this morning. Everything went well during upgrade. After reboot, Unbound was stopped and I had to manually start it. Probably due to Unbound being down, pfB said it was out of sync and a manual force reload was required to fix it. No issues otherwise.
-
Just to give a data point with a positive experience (since it is mostly the users who have problems that post about them, and that can skew the perception of how stable an upgrade might be).
I updated a plain-vanilla SG-5100 to 21.05 from 21.02.1 without issue. Plain-vanilla means no site-to-site VPN, no multi-WAN, and no shapers/limiters. Only installed packages are Snort, apcupsd, and the OpenVPN Client Export package.
-
Upgraded a SG-1100 successfully. Took about 10 minutes and everything came back just fine.
-
Update a 4560 remotely last night but my VPN tunnel did not come back. Fortunately I have other means to gain access to domain controller via my map tools. I noticed that unbound service was not started so I manually did which resolved issue. Since I use a host name to resolve IPSec endpoints this explains. I have noticed on many upgrades that dnsresolver needs to be manually started after upgrade.
Next one I do I’ll set override dns for pfsense to google first.
-
After upgrading my sshuttle connections stopped working.
-
5100 upgraded from 21.02.2 to 21.05 with no apparent issues.
My always-on OpenVPN client connection came back up with no issue.
It was quick.
Happy :)