Firewall Upgrade - Installation Sequence Question
-
Hi all,
I am planning on replacing my current firewall hardware with new hardware in the near future. The current system system presently runs pfSense Plus 23.05.1. The replacement firewall hardware will all be new with the exception that I plan to reuse a 4 port 10Gbit SFP+ expansion card from the current system in the new system. I had some questions related to the new firewall installation and configuration restoration sequence. I realize that I'll have to start with pfSense CE again, but which of these two installation list of steps would make more sense given that I'm going to be swapping some hardware between the two systems?
Option 1:
- Install pfSense CE 2.7 on new system
- Upgrade new system to pfSense Plus 23.05.1
- Remove network card from old system and install in new system
- Restore current (23.05.1) configuration from old system to new system
Option 2:
- Install pfSense CE 2.7 on new system
- Remove network card from old system and install in new system
- Upgrade new system to pfSense Plus 23.05.1
- Restore current (23.05.1) configuration from old system to new system
Thanks in advance for your help, I really appreciate it.
-
@tman222
My money would be on Step-2.
When installing a new Netcard, my gut tells me that your NID (Netgate ID) would change.If you do Step-1 , you'd have to get a new NID in order to upgrade to plus.
And you'd prob. have to get another new NID, after installing the netcard.PS:
I'd already apply for a new NID (for the new box) now, you can always apply/use it later,during install./Bingo
-
J jimp moved this topic from Problems Installing or Upgrading pfSense Software on
-
Yup use option 2 otherwise you'll need to re-register a new NDI after swapping the NIC in.
-
Thank you both for your help! I wanted to follow up and let you know that Option 2 worked like a charm. I installed pfSense 2.7 CE, moved the NIC over to the new system, upgraded to pfSense Plus 23.05.1, and then restored the 23.05.1 config from the old system. The whole process probably took less than 30 minutes and everything was working fine by the end of it.
I only ran into two minor issues:
- After config restoration the udpbroadcastrelay package service refused to start. Disabling / Re-Enabling the package via its GUI configuration page solved the issue and the service started fine.
- I was greeted with a bunch of errors after the initial reboot that followed config restoration. These were mainly pfBlockerNG related. I use pfBlockerNG lists as aliases in firewall rules and these lists don't exist without the initial pfBlockerNG update (that downloads and creates them). Once I ran a manual pfBlockerNG update, the lists were created everything was fine going forward.
Overall I'm very impressed with how smoothly the hardware upgrade went - a big thank you to everyone at Netgate for making the installation and restoration process so seamless.