Upgrade pfSense CE from 2.5.2 to 2.8.1 - Offline
-
Hi Netgate community,
I am using pfSense, running on an ESX host. All of my setup (i.e.: ESX server and pfSense) is running in a closed network, nested behind multiple corporate firewalls, and internet access at this level is strictly prohibited. I've asked for access, and it will not be allowed.
- How can I upgrade to a more recent version ?
- Any possibility to also install a few packages manually, like vmtools, iperf ?
--> I tried this for vmtools with no success https://forum.netgate.com/topic/163145/install-vm-tools-no-internet/5 (found the link to my exact version of pfsense 2.5.2)
I get a message that ld-elf.so.1 and another file is not found and required by pkg
Thank you.
-
@8drummer8 unfortunately there is no offline installer anymore, I'm very unhappy with this also.
Latest version you can install offline is 2.7.2, maybe pfSense is not anymore the right product for this case...https://atxfiles.netgate.com/mirror/downloads/
-
https://www.amazon.com/cellular-router/s?k=cellular+router
Or..
Connect this to the WIFI on your phone..
https://www.amazon.com/BrosTrend-600Mbps-Adapter-Wireless-WNA016/dp/B0118SPFCK/ref=sr_1_8?crid=2A8XSCH6H8W7J&dib=eyJ2IjoiMSJ9.ys4VFHTbITk3vqEDSdlWH8797N1ROlwn4EtP3EaHvYRL6qEGbGIO65c4wgC251jlXqwa5WyuwDYYRztUAB1VMaPC3Y3zXG3qfXtEo3LqhXP7msG21hIw46aZk_8KFhm_HlC1ja40Le1ZmjZVgx3b4rdFSkAT4fv_Up6k1R_pn6dxapCf231IIPpYNk3GwI0TFe7AUW8tUp3eWy7t3f_9zJZbWDXwfCNhSVVITp3-Iak.B91dfShf0DfPgVyULclfDXIOgL3bOj8W_B9ukhBCLHc&dib_tag=se&keywords=Ethernet+bridge&qid=1779310116&sprefix=ethernet+bridge%2Caps%2C195&sr=8-8
If you are in I.T. there is absolutely no reason you should not have a secondary method for obtaining internet access.
-
But, but—they're not just any firewalls in the way. It's multiple nested corporate firewalls! Maybe they do cellular jamming?
-
@tinfoilmatt LOL.. My bigger question is why someone that doesn't have cooperation with the actual I.T. department is trying to operate equipment on the network.. Id get fired for such a thing.
Im not a fan of the method that Netgate has chosen but there is always a way to get it done. If there is no way to update behind the "Corporate conglomerate firewall then there really then 2.7.2 works just fine. or take it off premises to update it.
Just seems like the OP is yet another account drummed up to complain about the update system.
-
@chpalmer said in Upgrade pfSense CE from 2.5.2 to 2.8.1 - Offline:
If you are in I.T. there is absolutely no reason you should not have a secondary method for obtaining internet access.
Unless it involves circumventing corporate security policy, assuming of course, one wants to keep their job and possibly stay out of a courtroom.
Many companies protect, or attempt to protect, their proprietary information at a level roughly equivalent government secret classification requirements. This includes logically or physically air-gapped networks.
Netgate's on-line-only installer/updater is incompatible with this security model and suggests Netgate has decided that losing this market is worth the alternative.
Or, maybe they haven't been inventive enough or willing to develop a way to make it work without the trade-off.
Setting oneself up to get fired by violating corporate policy over getting an update seems reckless. If OP values their employment, maybe they should look into getting a different firewall/router that can meet their requirements. Security costs money and their company has to be willing to pay for it.
-
@Mission-Ghost said in Upgrade pfSense CE from 2.5.2 to 2.8.1 - Offline:
Unless it involves circumventing corporate security policy
My SWAG is that the 1 post OP is already violating company policy by having their own network connected to the companies network.
But like I said.. my better guess is that this is just another bash on Netgate thread.
-
There hasn't been an offline upgrade option since we moved away from NanoBSD. Which was a long time ago... 2.3?
You can install 2.7.2 from the ISO but there is no way to upgrade to 2.8.1 without any connection at all.
You could download the required packages for VM tools and install them off-line if you're determined enough like:
https://pkg00-atx.netgate.com/pfSense_v2_7_2_amd64-pfSense_v2_7_2/All/pfSense-pkg-Open-VM-Tools-10.1.0_5%2C1.pkg
https://pkg00-atx.netgate.com/pfSense_v2_7_2_amd64-pfSense_v2_7_2/All/open-vm-tools-nox11-12.3.5%2C2.pkg -
@8drummer8 said in Upgrade pfSense CE from 2.5.2 to 2.8.1 - Offline:
I get a message that ld-elf.so.1 and another file is not found and required by pkg
That's because your system has at some point had internet access and has pulled in a newer pkg version. But that's expected. Use
pkg-staticinstead to avoid that and you should be able to install vm tools locally like:pkg-static add <path to local pkg files> -
It's funny how people can write anything bad about someone they do not know, without any reason.
Seems like many needs explanations to help me correctly. I manage OT networks. What I protect is an industry process control network. I'm totally legit doing what I'm doing, and I do have good communication with the corporate network IT folks. However, we all have our hands tied, because the company have put in place a very strict cybersecurity policy, which applies the so called "purdue model". Google it, and find images, my firewall is dealing with L3-L2-L1.
There is a way to the internet... but it's block and prohibited. It's not that I can't figure out a way of bypassing the security, I could, but if I do, I'll just lose my job, period.
From the good answers that I got, it seems I will need to move away from Netgate/pfSense in the future. And I understand that 2.7.2 is the last version I'll be able to upgrade to.
-
You're using free software in an apparent commercial setting. Either migrate to pfSense Plus and take this up with Netgate through the proper channel. Or take it up with your boss.
-
That's true. You could contact our sales guys to discuss options for Plus offline install.
-
@stephenw10 said in Upgrade pfSense CE from 2.5.2 to 2.8.1 - Offline:
There hasn't been an offline upgrade option since we moved away from NanoBSD. Which was a long time ago... 2.3?
You can install 2.7.2 from the ISO but there is no way to upgrade to 2.8.1 without any connection at all.
You could download the required packages for VM tools and install them off-line if you're determined enough like:
https://pkg00-atx.netgate.com/pfSense_v2_7_2_amd64-pfSense_v2_7_2/All/pfSense-pkg-Open-VM-Tools-10.1.0_5%2C1.pkg
https://pkg00-atx.netgate.com/pfSense_v2_7_2_amd64-pfSense_v2_7_2/All/open-vm-tools-nox11-12.3.5%2C2.pkgA few years ago, I had access to internet for updates, but the policies have changed since...
I'll use these links.@stephenw10 said in Upgrade pfSense CE from 2.5.2 to 2.8.1 - Offline:
@8drummer8 said in Upgrade pfSense CE from 2.5.2 to 2.8.1 - Offline:
I get a message that ld-elf.so.1 and another file is not found and required by pkg
That's because your system has at some point had internet access and has pulled in a newer pkg version. But that's expected. Use
pkg-staticinstead to avoid that and you should be able to install vm tools locally like:pkg-static add <path to local pkg files>with this command to install them.
Thank you @stephenw10
@Mission-Ghost said in Upgrade pfSense CE from 2.5.2 to 2.8.1 - Offline:
@chpalmer said in Upgrade pfSense CE from 2.5.2 to 2.8.1 - Offline:
If you are in I.T. there is absolutely no reason you should not have a secondary method for obtaining internet access.
Unless it involves circumventing corporate security policy, assuming of course, one wants to keep their job and possibly stay out of a courtroom.
Many companies protect, or attempt to protect, their proprietary information at a level roughly equivalent government secret classification requirements. This includes logically or physically air-gapped networks.
Netgate's on-line-only installer/updater is incompatible with this security model and suggests Netgate has decided that losing this market is worth the alternative.
Or, maybe they haven't been inventive enough or willing to develop a way to make it work without the trade-off.
Setting oneself up to get fired by violating corporate policy over getting an update seems reckless. If OP values their employment, maybe they should look into getting a different firewall/router that can meet their requirements. Security costs money and their company has to be willing to pay for it.
You've understand my situation. Based on your comment, I do think I'll need to find another firewall solution for the future.
-
@stephenw10 said in Upgrade pfSense CE from 2.5.2 to 2.8.1 - Offline:
That's true. You could contact our sales guys to discuss options for Plus offline install.
At one of my site, I've actually just bought a pair of Netgate 8200, running 25.11.1 and I'll be facing the same issue when I'll want to update them...
-
Actually, @stephenw10 told you literally just ten minutes ago that that's not necessarily the case.
-
Nobody making good use of pfSense CE cares what firewalll solution you use.
-
I've got my answer from the sale department:
Unfortunately, pfSense Plus does require internet access for installation, migration, and upgrades, and there is not a supported workaround for fully air-gapped environments at this time.
Let me know if you have any other questions.
Best regards,
I'll have find a different solution for the future.
Case closed.
-
I'm sure Netgate is weeping.
-
@tinfoilmatt why does every single post you did was to bash on me ? did I insulted you in any way ?
I'm not even saying anything wrong about pfSense... I was searching for a solution, explaining my situation, I don't see anything wrong about it. You obviously didn't have any for me, so why did you stop here ? Next time you need attention, please do the forum a favour and keep your negative comments for yourself, otherwise; we'll be pleased to read your positives ones. -
How did I bash on and insult you?
Would you say you did an adequate job of looking into your 'issue' prior to making this post?
Do you think you're making me feel ashamed or something?
Tell your employer to enjoy the free software for as long as their company continues using it, buddy!

Privacy Policy · Cookie Policy