Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    pfSense Plus version 22.01 and pfSense CE version 2.6.0 Software are Now Available!

    Messages from the pfSense Team
    20
    28
    20268
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mleighton Administrator last edited by

      We are excited to announce the release of pfSense Plus software version 22.01 and pfSense Community Edition (CE) software version 2.6.0, now available for new installations and upgrades! Read our blog post for more information.

      This version of pfSense CE software includes new functionality allowing CE installations to upgrade to pfSense Plus. See HERE for more details!

      For more details, see the release notes and Redmine.

      Always take a backup of the firewall configuration prior to any major change to the firewall, such as an upgrade.

      Do not update packages before upgrading! Either remove all packages or do not update packages before running the upgrade.

      The upgrade will take several minutes to complete. The exact time varies based on download speed, hardware speed, and other factors such as installed packages. Be patient during the upgrade and allow the firewall enough time to complete the entire process. After the update packages finish downloading it could take 10-20 minutes or more until the upgrade process ends. The firewall may reboot several times during the upgrade process. Monitor the upgrade from the firewall console for the most accurate view.

      Consult the Upgrade Guide for additional information about performing upgrades to pfSense software.

      G J U 3 Replies Last reply Reply Quote 12
      • Pinned by  M mleighton 
      • Referenced by  viktor_g viktor_g 
      • Referenced by  viktor_g viktor_g 
      • G
        gnordoff @mleighton last edited by

        @mleighton upgrade community edition installed without any issues, except the memory usage doubled. Is this the predicted outcome?

        G S 2 Replies Last reply Reply Quote 0
        • G
          gnordoff @gnordoff last edited by

          @gnordoff I should note the upgrade was from 2.5.2 to 2.6.0

          1 Reply Last reply Reply Quote 0
          • J
            jdeloach @mleighton last edited by

            @mleighton

            Just upgraded from 2.5.2 to CE 2.6.0, everything went smooth and quick. I don't have a lot of packages installed including Suricata and pfBlockerNG but everything appears to be working at the present time. I may be cussing later but for now, things are working. I'm happy.

            Great job as always by the Netgate folks.

            1 Reply Last reply Reply Quote 0
            • M
              MoonKnight last edited by

              Hi,
              Just upgraded from 2.5.2 to CE 2.6.0, everything went smooth and quick.
              All my packages are working as it should, haproxy, pfBlockerNG_Dev, all my Wireguard tunnels, all my VLANs, Firewall rules.
              I'm very happy so far with this update, great job :)

              --- 23.01 ---
              Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
              Kingston DDR4 2666MHz 16GB ECC
              2 x HyperX Fury SSD 120GB (ZFS-mirror)
              2 x Intel i210 (ports)
              4 x Intel i350 (ports)

              1 Reply Last reply Reply Quote 0
              • P
                pfsjap last edited by

                I noticed that Netgate_Firmware_Upgrade package version 0.51 was available and updated. Updated package didn't work ("This function is not available for this hardware model"). Only after that I noticed that version 22.01 was available and this message.

                Is it sufficient to remove Netgate_Firmware_Upgrade before upgrading to 22.01, or should I remove all packages?

                I have arpwatch, Netgate_Firmware_Upgrade, pfBlockerNG-devel and snort installed.

                S 1 Reply Last reply Reply Quote 0
                • provels
                  provels last edited by

                  I'll probably hate myself in the morning, but I can't help myself! ๐Ÿ‘จโ€๐Ÿš’

                  Peder

                  MAIN - pfSense+ 23.01-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD
                  BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                  provels 1 Reply Last reply Reply Quote 0
                  • S
                    SteveITS @pfsjap last edited by

                    @pfsjap said in pfSense Plus version 22.01 and pfSense CE version 2.6.0 Software are Now Available!:

                    Only after that I noticed that version 22.01 was available

                    You really don't want to install packages from a newer version as they may try to install dependencies like a newer PHP, that the newer pfSense version already has, and really mess things up. I'm guessing that one might not have many system dependencies so you may be OK? I really don't know. I double checked a couple Netgate routers and they don't even have that package so I don't think it's required for anything.

                    Per https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide-prepare.html#packages, "The safest practice is to remove all packages before upgrading to a new release. The upgrade process will handle packages automatically, but packages are frequently a source of problems. To ensure a smooth upgrade, note the installed packages, remove them, perform the upgrade, and then reinstall when the upgrade is complete." That's what I've been doing, at least with most "more intrusive" packages like pfBlocker and Suricata/Snort.

                    Do note if you have pfBlocker geoIP aliases that removing the package removes the alias...don't lock yourself out.

                    Steve

                    Only install packages for your version, or risk breaking it. If yours is older, select it in System/Update/Update Settings.
                    When upgrading, let it finish; do not reboot early. Allow 10-15 minutes, or more depending on packages and device speed.

                    R P 2 Replies Last reply Reply Quote 1
                    • R
                      r801248 @SteveITS last edited by

                      Upgrade from 2.5.2 to 2.6.0 was smooth and painless on my Supermicro E200-9B.
                      Thank you Netgate!

                      1 Reply Last reply Reply Quote 0
                      • provels
                        provels @provels last edited by

                        @provels said in pfSense Plus version 22.01 and pfSense CE version 2.6.0 Software are Now Available!:

                        I'll probably hate myself in the morning, but I can't help myself! ๐Ÿ‘จโ€๐Ÿš’

                        No problems here. Built a new VM and restored my BU. Cake.๐Ÿ‘

                        Peder

                        MAIN - pfSense+ 23.01-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD
                        BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                        1 Reply Last reply Reply Quote 0
                        • S
                          skogs last edited by

                          2.6.x RC > 2.6.0 > 22.01 all worked flawlessly.
                          Excellent work.

                          1 Reply Last reply Reply Quote 0
                          • S
                            skogs @gnordoff last edited by

                            @gnordoff I noted about an 80% increase in memory usage also, but it seems to have returned to normal after running for a little while.
                            Guessing it isn't a 'hard' increase and may only be a few lingering post install cache things.

                            1 Reply Last reply Reply Quote 0
                            • occamsrazor
                              occamsrazor last edited by

                              Upgraded 2.5.2 CE to 2.6 and all went smoothly so far. It took a long time to download some of the packages, "appearing" to be stuck on some. I just mention that to anyone upgrading to just sit tight.
                              The only thing was at the end of the process I got this, which may be no issue and the system seems to be working, but looked a bit odd....

                              The process will require 98 MiB more space.
                              [1/1] Upgrading pfSense-kernel-pfSense from 2.5.2 to 2.6.0...
                              [1/1] Extracting pfSense-kernel-pfSense-2.6.0: .......... done
                              ===> Keeping a copy of current kernel in /boot/kernel.old
                              cp: /boot/kernel/.pkgtemp.fuse.ko.XlEg8vpsQuvv: No such file or directory
                              cp: /boot/kernel/.pkgtemp.if_tun.ko.Lt0bFuqEiOK0: No such file or directory
                              cp: /boot/kernel/.pkgtemp.if_igb.ko.QuxZvbFyEDZd: No such file or directory
                              cp: /boot/kernel/.pkgtemp.if_ixlv.ko.r7T3rOyFZyBn: No such file or directory
                              cp: /boot/kernel/.pkgtemp.if_tap.ko.eCXM6IY0M4M6: No such file or directory
                              pkg-static: DEINSTALL script failed
                              >>> Removing unnecessary packages... done.
                              System is going to be upgraded.  Rebooting in 10 seconds.
                              Success
                              

                              pfSense CE on Qotom Q355G4 8GB RAM/60GB SSD
                              Ubiquiti Unifi wired and wireless network, APC UPSs
                              Mac OSX and IOS devices, QNAP NAS

                              1 Reply Last reply Reply Quote 1
                              • P
                                pfsjap @SteveITS last edited by

                                @steveits Removed only Netgate_Firmware_Upgrade package, upgraded to 22.01, reinstalled Netgate_Firmware_Upgrade. Upgrade went smoothly except for the seemingly cosmetic message "pkg-static: DEINSTALL script failed" before rebooting.

                                Then I upgraded firmware to CORDOBA-02.02.00.00t, this went smoothly, too.

                                Good work by the Netgate folks.

                                1 Reply Last reply Reply Quote 0
                                • C
                                  churchtechguy last edited by

                                  First of all thanks for all your hard work!!
                                  I did encounter an issue after upgrading from 2.5.2 to 2.6.0. It appears that any rules I had set to match "Diffserve Code Point" values started erroring out when the ruleset is loaded. I tried several combinations and it seems that the only ones that were causing errors were ones set with csX markings (I was matching on cs7).

                                  Here's my exact error message:

                                  There were error(s) loading the rules: /tmp/rules.debug:278: illegal tos value 56 - The line in question reads [278]: match log on { WAN_Group } inet proto udp from any to any port $Zoom_UDP tos "56" ridentifier 1589829693 queue (qLowDelay) label "USER_RULE: Zoom Uploads (match CS7 audio dscp)
                                  

                                  I'm not sure where I should request help or post about this on the forums... I didn't have this issue prior to the upgrade.

                                  C 1 Reply Last reply Reply Quote 0
                                  • C
                                    churchtechguy @churchtechguy last edited by

                                    I was able to reproduce and correct this error by manually editing my config.xml file. I filed a bug report here....

                                    https://redmine.pfsense.org/issues/12803

                                    1 Reply Last reply Reply Quote 0
                                    • W
                                      Waqar.UK last edited by

                                      Great update - went smoothly. Took under 15 minutes: Qotom i5-5250U, 8GB RAM and 120 GB SSD (circa 2% used). ISP: VM 200Mbit down, get 200.

                                      1 Reply Last reply Reply Quote 0
                                      • K
                                        kaj last edited by

                                        The update from version 2.5.2-RELEASE (amd64) to 2.6.0-RELEASE (amd64) with the following hardware: Qotom Q878GE Intel(R) Core(TM) i7-8550U CPU 16 GByte RAM and 256 Gbyte mSata SSD took smoothly within 5 to 10 minutes. The following packages have been updated: acme, apcupsd, Cron, freeradius3, iperf, Lightsquid, mailreport,nut, openvpn-client-export, pfBlockerNG-devel, squid, squidguard. It doesn't get any better than that. Thank you for the successful update process and greetings from Germany

                                        Thank you very much for the great work

                                        kaj

                                        1 Reply Last reply Reply Quote 0
                                        • G
                                          guardian last edited by

                                          I just upgraded from 2.5.2 to 2.6.0, and it appeared to go well, except that I can no longer access the serial console by logging in as root. I can still login with ssh, to the user id that I use with the webgui, but I don't get the menu.

                                          Is this expected behavior, or a bug?
                                          How can I access the serial menu over ssh?

                                          If you find my post useful, please give it a thumbs up!
                                          pfSense 2.6.0-RELEASE-CE

                                          S R 2 Replies Last reply Reply Quote 0
                                          • S
                                            skogs @guardian last edited by

                                            @guardian sounds like you made a legitimate login at some point that isn't admin/root. Might need to re-create it (even though it is there) to get the login script and such back for the 'new' user.
                                            Guessing have to install sudo and stuff, as normal user wouldn't have root access.
                                            I think the textual menu is provided by /etc/rc.initial

                                            1 Reply Last reply Reply Quote 0
                                            • R
                                              rcoleman-netgate Netgate Administrator @guardian last edited by rcoleman-netgate

                                              @guardian try running

                                              /etc/rc.initial
                                              

                                              to get the menu. Only 'admin' gets the menu by default. If you have disabled this account it is now reflective in the SSH connection with the 2.6 update.

                                              --
                                              Ryan
                                              Repeat (after me): MESH IS THE DEVIL! MESH IS THE DEVIL!
                                              Requesting firmware for your Netgate device? https://go.netgate.com
                                              Switching: Mikrotik, Netgear, Extreme
                                              Wireless: Aruba, Ubiquiti

                                              1 Reply Last reply Reply Quote 0
                                              • R
                                                robbyjhons540 Banned last edited by

                                                This post is deleted!
                                                1 Reply Last reply Reply Quote 0
                                                • J
                                                  jwg014 last edited by

                                                  HI,

                                                  any Idea how to deal with CVE-2022-0778 in the case e.g. HaProxy use inside pfSense?
                                                  BR Johannes

                                                  jimp 1 Reply Last reply Reply Quote 0
                                                  • jimp
                                                    jimp Rebel Alliance Developer Netgate @jwg014 last edited by

                                                    @jwg014 said in pfSense Plus version 22.01 and pfSense CE version 2.6.0 Software are Now Available!:

                                                    any Idea how to deal with CVE-2022-0778 in the case e.g. HaProxy use inside pfSense?

                                                    HAProxy would only be affected if you have it configured to accept client certificates as a form of authentication. Which is possible, but rare in practice. If you have concerns about that, move the service inside a VPN where it's much more protected. As far as we can tell so far, VPNs are not likely to be as much of an issue as there are other hurdles attackers would have to overcome before the certificates come into play (e.g. TLS key protecting OpenVPN in addition to certificate auth.), and several VPN types and configs don't use certificates at all (e.g. WireGuard). We're still checking into it and keeping an eye on what people find, though.

                                                    Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                                                    Need help fast? Netgate Global Support!

                                                    Do not Chat/PM for help!

                                                    1 Reply Last reply Reply Quote 2
                                                    • D
                                                      doppyforever79 Banned last edited by

                                                      This post is deleted!
                                                      1 Reply Last reply Reply Quote 1
                                                      • D
                                                        doppyforever79 Banned last edited by

                                                        This post is deleted!
                                                        1 Reply Last reply Reply Quote 0
                                                        • Unpinned by  M mleighton 
                                                        • U
                                                          urbanovits @mleighton last edited by

                                                          @mleighton Were to report a security issue ?
                                                          Need a contact info, I'm not going to put on public.

                                                          jimp 1 Reply Last reply Reply Quote 0
                                                          • jimp
                                                            jimp Rebel Alliance Developer Netgate @urbanovits last edited by

                                                            @urbanovits said in pfSense Plus version 22.01 and pfSense CE version 2.6.0 Software are Now Available!:

                                                            @mleighton Were to report a security issue ?
                                                            Need a contact info, I'm not going to put on public.

                                                            https://www.netgate.com/security has the relevant contact information and procedures for reporting security issues.

                                                            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                                                            Need help fast? Netgate Global Support!

                                                            Do not Chat/PM for help!

                                                            1 Reply Last reply Reply Quote 0
                                                            • First post
                                                              Last post