Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Why is auto-update not recommended

    General pfSense Questions
    6
    8
    223
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      atclaus last edited by

      In searching for ways to automatically upgrade pfSense, I have come across many posts that recommend against automatic updates to pfSense via executing pfSense-upgrade -y but I do not see concrete reasons why this is bad? I would want to be on the latest version and run it at a time when my network traffic is off and not critical. What am I missing?

      Gertjan 1 Reply Last reply Reply Quote 0
      • Gertjan
        Gertjan @atclaus last edited by Gertjan

        @atclaus said in Why is auto-update not recommended:

        What am I missing?

        The subject is known, you saw the posts. If none of them are show-stoppers for you, you could implement a daily cron job that executes "pfSense-upgrade -y".

        No "help me" PM's please. Use the forum.

        1 Reply Last reply Reply Quote 0
        • stephenw10
          stephenw10 Netgate Administrator last edited by

          Yes, there are some example methods in other posts but as you saw you should not do this in general.

          Asides from the fact that an upgrade almost always necessitates a reboot which breaks whatever is happening at that moment there may be something in the release notes that applies specifically to you that breaks everything. Until you read the notes you don't know.

          Steve

          1 Reply Last reply Reply Quote 0
          • johnpoz
            johnpoz LAYER 8 Global Moderator last edited by

            Yeah would never in a million years suggest auto update your firewall..

            As mentioned you should really read and adhere to anything in the release notes before update.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 23.01 | Lab VMs CE 2.6, 2.7

            1 Reply Last reply Reply Quote 0
            • bmeeks
              bmeeks last edited by bmeeks

              +3 for the above responses. I worked for a Fortune 500 U.S. corporation in the IT group for many years. We were a complete Windows shop for the majority of the business network. Even with that, while we did regularly install updates, it was a very controlled process with lots of application testing required before any update was placed on the WSUS servers for distribution to client devices and servers on the business network.

              I was also involved in process control network security for power plants, and the testing requirements there were even more extreme before any software change was made or an update installed.

              So the auto-update idea might be OK for a home user, but still potentially aggravating if an update goes south. But auto-update is a potential disaster waiting to happen for a large business network. How would you like to be the IT guy that enabled an auto-update that took down the power plant control network and plunged your entire region of the country into complete and utter darkness? ... ☺ .

              JKnott 1 Reply Last reply Reply Quote 1
              • johnpoz
                johnpoz LAYER 8 Global Moderator last edited by johnpoz

                Home user example of problem... You just left for 2 week vacation, and your update goes south and your connection is dead.. Now no vpn back home, now no access to your plex, etc.

                If you want to automate something - automate a notification that you will notice that an update is available, so you can then do the update when it makes sense to do it.. After!! you have read the notes for any special things that might have to be taken into account before the update.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 23.01 | Lab VMs CE 2.6, 2.7

                1 Reply Last reply Reply Quote 1
                • JKnott
                  JKnott @bmeeks last edited by

                  @bmeeks said in Why is auto-update not recommended:

                  +3 for the above responses. I worked for a Fortune 500 U.S. corporation in the IT group for many years. We were a complete Windows shop for the majority of the business network. Even with that, while we did regularly install updates, it was a very controlled process with lots of application testing required before any update was placed on the WSUS servers for distribution to client devices and servers on the business network.

                  Many years ago, I was in 3rd level support (OS/2 and OS/2 & Windows apps) at IBM Canada. Part of my job was to do integration testing of updates, before inflicting them on the users.

                  PfSense running on Qotom mini PC
                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                  UniFi AC-Lite access point

                  I haven't lost my mind. It's around here...somewhere...

                  1 Reply Last reply Reply Quote 0
                  • A
                    atclaus last edited by

                    Thanks all for your input. Very helpful. I forgot for a moment that this is enterprise class software/hardware that I am using at home/small business. That being said, @johnpoz your at home case makes a lot of sense too! I followed another post with some PHP that should check and email me about updates (albeit is not working yet - weekend troubleshooting). Will use that and not auto update. Appreciate the education!

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post