pfSense Plus Software Version 24.11 is here!
-
I went ahead and upgraded to 24.11 yesterday and overall things went fairly smoothly. Ran into a few issues along the way, some of which have already been documented in other posts:
- Higher CPU usage when viewing dashboard:
https://forum.netgate.com/topic/190824/cpu-load-on-1100
- “Another instance of pfSense-upgrade is running” - saw this as well when when I first tried to upgrade. Error went away after waiting a couple minutes:
https://forum.netgate.com/topic/195329/huh-another-instance-of-pfsense-upgrade-is-running
- FreeRadius BlastRADIUS warnings in the System Logs - not sure yet how to mitigate these; have started a thread:
https://forum.netgate.com/topic/195376/freeradius-blastradius-warning-in-system-logs-how-to-mitigate
- Abnormally high
SERVFAIL
messages from DNS look ups after upgrading - these were high enough that websites would regularly fail to load. I'm still investigating the cause as everything worked fine in pfSense 24.03 and prior versions. I do see that unbound was upgraded from 1.19.3 to 1.22.0 so perhaps some changes were made that resulted in this behavior. For now the workaround that has helped to get rid of the excessiveSERVFAIL
errors, has been to explicitly disable IPv6 in unbound by settingdo-ip6
tono
in the Custom options section (I don't currently use IPv6 so this should not cause any issues). However, more investigation will be needed.
Overall though this has been a great release - thanks Netgate team for all your hard work!
-
@mwatch Updated a 4200 to this release about six hours ago. Saw the same “Another instance of pfSense-upgrade is running” strangeness others have reported, though that clearly must be the fault of the prior release (24.03) not this one. Otherwise, smooth upgrade and no problems noted since then. The dashboard widgets fill in noticeably more quickly than in 24.03. I don't see any indication of increased CPU load, although I use a fairly minimal set of widgets.
-
@SwissSteph ignore the countdown timer. Upgrades take from a few minutes to 10-15 minutes or so depending on disk write speed and CPU power, and whether one removes packages first (per the upgrade guide).
After a half hour if you still see the timer, connect a console cable, do not just power off.
-
@SteveITS
Thank you for this message and your advice, I'll keep it to the letter. For me and this new version everything went very well.
I also got the message “Another instance of pfSense-upgrade is running”, I rebooted pfsense and the message was no longer present)I also switched to “KEA”, thanks to your encouragement ... all OK for me
-
I already posted not starting Squid/SquidGuard-services. Tried many ways to repair - all failed. Same picture at my 4100 and 6100. So I killed and deinstalled both programs. RIP - shame. I "cleaned" the 4100 from all programs and functions I could find failiure messages about.
Both devices show significantly higher CPU-load when using GUI than I have ever seen before. Value fluctuates strongly and often reaches 100% - even with only small dataflows through the device. Monitoring graph of temperature over 2 day shows normal values.
No packet loss is documented.
May be the CPU-load is only high while using the GUI ? 2-days graph does not show problems ... but it is propably not able to register quick fluctuation.I hope that 100%-CPU-load phases do not shorten the CPUs lifetime or leads to other problems I did not notice yet...
-
@delphin_007 re: CPU, there are a few threads on that. Check with the dashboard not visible, or see https://forum.netgate.com/topic/195325/sg2100-100-cpu-usage-post-upgrade-to-24-11/7.
-
@SteveITS Thanks for hints ! I looked over other threads.
So I leave it as "GUI-behavior".
As long as there are no problems at my Netgates I use GUI dayly only for seconds to get the "OK"-impression. -
One issue is that after WAN IP renew (which works) the KEA DHCP service stopped and I had to start it up manually.
-
-
Has anyone else had issues editing or adding domain overrides in dnsmasq in 24.11? I can add hosts and update custom options but domains don't update.
-
Yes, replicated that. https://redmine.pfsense.org/issues/15890