Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    23.05.1

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    24 Posts 11 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michmoor LAYER 8 Rebel Alliance @mcury
      last edited by

      @mcury said in 23.05.1:

      Packages used: pfBlockerNG, Wireguard, Softflowd, NUT, Acme and the others installed by default.

      Curious. What are you using as a NetFlow collector?

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      M 1 Reply Last reply Reply Quote 0
      • C
        Cabledude @mcury
        last edited by

        @mcury said in 23.05.1:
        Thanks for your report 😀

        As usual, uninstalled pfblockerNG, Softflowd and NUT before upgrading.

        New to uninstalling before upgrade. So let's say I were to follow your lead. Would I:

        • create config backup
        • uninstall packages like pfBlocker (is there a list of which packages should be uninstalled?)
        • perform upgrade
        • load config backup, so that the necessary packages are downloaded and installed automatically + their config is restored

        ?

        Thanks!

        Pete
        Home: SG-2100 + UniFi + Synology. SG-1100 retired
        Parents: SG-1100 + UniFi + Synology
        Testing: SG-1100 w/ 120GB SSD via ext USB (eMMC dead). Works great

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          The "remove all packages" part is more important for CE users making the gigantic leap from 2.6.0 to 2.7.0 and all the PHP and base OS changes that go with it. All our internal tests have been OK but we've had a few users report that some of their packages failed to update on the way to 2.7.0 and caused other issues.

          If you're going from 23.05 to 23.05.1 the risk is much, much lower.

          23.01 to 23.05.1 is probably still worth taking out packages for (PHP moved to 8.2) but still less risk than going from the old PHP 7.x code in 22.x up to 23.xx.

          And in terms of what to uninstall, uninstall them all unless a package is 100% necessary for your upstream connectivity somehow, and then leave only what is absolutely needed.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          C 1 Reply Last reply Reply Quote 1
          • M
            mcury @michmoor
            last edited by

            @michmoor said in 23.05.1:

            Curious. What are you using as a NetFlow collector?

            Graylog:

            b9af0a6e-38fa-4984-8e31-564faa574288-image.png

            dead on arrival, nowhere to be found.

            M 1 Reply Last reply Reply Quote 0
            • M
              michmoor LAYER 8 Rebel Alliance @mcury
              last edited by

              @mcury I dont want to pollute this thread with my graylog question but I am also pushing netflow to graylog but having trouble creating usable charts.
              You mind sharing the dashboard config? I assume you're doing an aggregation table and all that.
              Appreciate you @mcury

              Firewall: NetGate,Palo Alto-VM,Juniper SRX
              Routing: Juniper, Arista, Cisco
              Switching: Juniper, Arista, Cisco
              Wireless: Unifi, Aruba IAP
              JNCIP,CCNP Enterprise

              M 1 Reply Last reply Reply Quote 0
              • M
                mcury @michmoor
                last edited by

                @michmoor Sure, open a new thread and I'll share everything I have set it here..

                It's a simple setup, no aggregation.. It's working as a Syslog server for Synology, Unifi and pfSense.
                But I'm also exporting netflow from pfSense to Graylog.

                dead on arrival, nowhere to be found.

                1 Reply Last reply Reply Quote 1
                • keyserK
                  keyser Rebel Alliance
                  last edited by

                  Upgraded a 2100 and 6100 from 23.05 to 23.05.1 without issues (very quick update, no package reinstall).

                  Packages running: pfBlockerNG, Syslog-ng, tftp, lldpd, notes, NtopNG, Freeradius, Nut

                  Love the no fuss of using the official appliances :-)

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @keyser
                    last edited by

                    So I just pulled the trigger.. Took a current config backup, consoled in so could watch the upgrade - all smooth.

                    Took total of about 6 minutes on my 4860... Logging in now, seems all good.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    chudakC 1 Reply Last reply Reply Quote 0
                    • chudakC
                      chudak @johnpoz
                      last edited by

                      Upgraded to 23.05.1 with no issues

                      Did not uninstall any packages, including pfBlockerNG

                      1 Reply Last reply Reply Quote 0
                      • C
                        Cabledude @jimp
                        last edited by

                        @jimp thanks for clarifying. You say with pfSense Plus 23.05 to 23.05.1 the risk is much lower. So there still is a risk and some users here do uninstall.

                        I could make uninstalling packages a principle or standard workflow. Could you comment on the steps I listed above:

                        • create config backup
                        • uninstall packages like pfBlocker (is there a list of which packages should be uninstalled?)
                        • perform upgrade
                        • load config backup, so that the necessary packages are downloaded and installed automatically + their config is restored

                        Would you say this is it? Any alterations advised?

                        Thanks!

                        Pete
                        Home: SG-2100 + UniFi + Synology. SG-1100 retired
                        Parents: SG-1100 + UniFi + Synology
                        Testing: SG-1100 w/ 120GB SSD via ext USB (eMMC dead). Works great

                        1 Reply Last reply Reply Quote 0
                        • jimpJ
                          jimp Rebel Alliance Developer Netgate
                          last edited by

                          I wouldn't bother with the config restore, just install the packages again. The config restore is a fairly harsh way of saving a handful of clicks.

                          It will work, but it's like swatting a fly with a cannon.

                          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                          Need help fast? Netgate Global Support!

                          Do not Chat/PM for help!

                          johnpozJ C 2 Replies Last reply Reply Quote 2
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator @jimp
                            last edited by johnpoz

                            @jimp said in 23.05.1:

                            It will work, but it's like swatting a fly with a cannon.

                            But what if its robotic fly with steel plating? ;)

                            armor.jpg

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                            1 Reply Last reply Reply Quote 1
                            • C
                              Cylosoft
                              last edited by

                              For our 2.6 to 2.7 boxes I uninstalled PfBlocker and left all other packages. 23.05.1 I left all packages installed. I'm about 20 boxes in now and zero issues.

                              1 Reply Last reply Reply Quote 1
                              • F
                                FSC830
                                last edited by FSC830

                                To be honest: I did never uninstall a package prior updating. 🙄
                                Since 2.4.5 I am running the updates in current status.
                                I did only see one issue, but I cant remember if really a package was the culprit or something else.
                                And I remember that one update fails and I need to recover from recovery image.
                                Thats my fallback, I always request the recovery image from TAC prior updating.

                                Will update to 23.05.1 during weekend 😊 .
                                Appliance is a SG-3100

                                Regards

                                Edit: Update done, no issues. 😊

                                1 Reply Last reply Reply Quote 1
                                • C
                                  Cabledude @jimp
                                  last edited by Cabledude

                                  @jimp said in 23.05.1:

                                  I wouldn't bother with the config restore, just install the packages again. The config restore is a fairly harsh way of saving a handful of clicks.

                                  It will work, but it's like swatting a fly with a cannon.

                                  Ah okay, thank you. I assumed that package configuration (settings sections) would be reset to their defaults if packages are simply uninstalled and reinstalled, but if I understand you correctly the settings will be retained?
                                  So let's say I uninstall Avahi, perform update and reinstall Avahi, will the system have remembered the Avahi settings such as which interfaces, repeat packet across subnets etc.?

                                  Thank you

                                  Pete
                                  Home: SG-2100 + UniFi + Synology. SG-1100 retired
                                  Parents: SG-1100 + UniFi + Synology
                                  Testing: SG-1100 w/ 120GB SSD via ext USB (eMMC dead). Works great

                                  dennypageD jimpJ 2 Replies Last reply Reply Quote 0
                                  • dennypageD
                                    dennypage @Cabledude
                                    last edited by

                                    @Cabledude said in 23.05.1:

                                    So let's say I uninstall Avahi, perform update and reinstall Avahi, will the system have remembered the Avahi settings such as which interfaces, repeat packet across subnets etc.?

                                    Yes, Avahi's package settings will be retained.

                                    1 Reply Last reply Reply Quote 0
                                    • jimpJ
                                      jimp Rebel Alliance Developer Netgate @Cabledude
                                      last edited by

                                      @Cabledude said in 23.05.1:

                                      @jimp said in 23.05.1:

                                      I wouldn't bother with the config restore, just install the packages again. The config restore is a fairly harsh way of saving a handful of clicks.

                                      It will work, but it's like swatting a fly with a cannon.

                                      Ah okay, thank you. I assumed that package configuration (settings sections) would be reset to their defaults if packages are simply uninstalled and reinstalled, but if I understand you correctly the settings will be retained?
                                      So let's say I uninstall Avahi, perform update and reinstall Avahi, will the system have remembered the Avahi settings such as which interfaces, repeat packet across subnets etc.?

                                      Upgrading a package effectively uninstalls the old package and reinstalls the new version. Same as if you did it in two steps before/after a reboot.

                                      By default package configurations are retained in the firewall config file and only the metadata about the package is altered (e.g. the info about the package files, menus, tabs, plugins).

                                      There are a small number of packages which have an option to wipe their config on reinstall but that isn't their default behavior, you have to explicitly set them to clear the config.

                                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                                      Need help fast? Netgate Global Support!

                                      Do not Chat/PM for help!

                                      1 Reply Last reply Reply Quote 1
                                      • S SteveITS referenced this topic on
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.