Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Question about upgrade pfsense HA

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    7 Posts 3 Posters 759 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      sudo_su
      last edited by

      Hello,
      I have two pfSense instances installed in VM, configured with HA (High Availability). I want to upgrade from version 2.6.0 to 2.7.0.
      I'll be backing up the configuration, taking a snapshot of the machine and remove all package.
      I plan to start the upgrade on the pfSense instance that is currently the slave, but I have a question.
      Will upgrading the slave cause any issues when it tries to synchronize with the master, which is still running the old version?

      Thank you!

      S 1 Reply Last reply Reply Quote 0
      • S Offline
        SteveITS Rebel Alliance @sudo_su
        last edited by

        @sudo_su per the docs, yes since 2.7.x is FreeBSD 14:
        https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide-ha.html#pfsync-considerations

        That said I don't recall running into drop issues on the clusters we manage, going to 23.01, but I may not have been looking for it and I tend to do those at night anyway, and one router right after the other.

        Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
        Upvote ๐Ÿ‘ helpful posts!

        1 Reply Last reply Reply Quote 1
        • stephenw10S Offline
          stephenw10 Netgate Administrator
          last edited by

          The config only syncs primary to secondary. And it won't sync if the installed pfSense versions don't match.

          The states sync both ways but the states are valid between versions.

          S 1 Reply Last reply Reply Quote 1
          • S Offline
            SteveITS Rebel Alliance @stephenw10
            last edited by

            @stephenw10 said in Question about upgrade pfsense HA:

            the states are valid between versions.

            Is that new? The doc URL I linked states, "Versions of pfSense software with a different base OS version of FreeBSD cannot sync their states between each other."

            (But yes I perhaps misread the question as state sync not config sync.)

            Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
            Upvote ๐Ÿ‘ helpful posts!

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              Hmm, interesting. I'll have to check that.

              1 Reply Last reply Reply Quote 0
              • stephenw10S Offline
                stephenw10 Netgate Administrator
                last edited by

                Ah, between different base versions that would be an issue, yes. And that does apply here.

                Either way some time ago it used to be an issue and you needed to disable sync before upgrading. In any recent version though sync is disabled between incompatible versions so there is no need to do it.

                S 1 Reply Last reply Reply Quote 0
                • S Offline
                  sudo_su @stephenw10
                  last edited by

                  @stephenw10 said in Question about upgrade pfsense HA:

                  Ah, between different base versions that would be an issue, yes. And that does apply here.

                  Either way some time ago it used to be an issue and you needed to disable sync before upgrading. In any recent version though sync is disabled between incompatible versions so there is no need to do it.

                  hi,
                  Is it possible to see the status of this option, or is it in the pfSense code?

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.