Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Discussion of the New GUI design

    Scheduled Pinned Locked Moved Netgate Nexus
    34 Posts 16 Posters 1.5k Views 21 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      CQ-Tip @Mission-Ghost
      last edited by

      @Mission-Ghost
      Well said and I agree.

      1 Reply Last reply Reply Quote 0
      • G Offline
        Gcon
        last edited by

        What is annoying is this:
        Note: Virtual machines as well as some third-party platforms may not support the new GUI due to missing machine information required to correctly run the software.

        I run pfSense Plus on various virtualized setups. In all my setups I know exactly what CPU I have in each hypervisor and what the CPU and NIC hardware acceleration features are ("cat /proc/cpu" etc). I baseline all my VMs to x86-64-v3 so they can be migrated to anywhere.

        It feels patronising to not be told what features this new code requires from CPU, and possibly NIC. I understand that Netgate want to push their own hardware but c'mon - don't be like this.

        I don't want to play Russian Roulette where a forced update to this new GUI somewhere down the line leaves my current pfSense installs inoperable, and Netgate won't even give me the info so I can research if my current gear is compatible or not. I'm currently conducting a network re-evaluation right now to see whether to continue on with pfSense, or move all sites over to UBNT UDM-Pro-Max's and UCG's, and this sort of stuff is not making the case for pfSense any better.

        N KOMK 2 Replies Last reply Reply Quote 2
        • N Offline
          netblues @Gcon
          last edited by

          @Gcon What virtualization?

          ea8e7f8c-7250-424f-b6ee-5b87a6236095-image.png

          This is what I get under kvm

          Virtualization not supported.

          1 Reply Last reply Reply Quote 1
          • KOMK Offline
            KOM @Gcon
            last edited by

            @Gcon said in Discussion of the New GUI design:

            this sort of stuff is not making the case for pfSense any better

            Enshitification always gets worse, never better.

            @netblues That's hilarious. Locking a gui behind drm.

            N 1 Reply Last reply Reply Quote 2
            • N Offline
              netblues @KOM
              last edited by

              @KOM Well. after filling in a bogus serial number, it managed to start, but still see some errors.

              Since this is an rc I would suggest adding a few lines of code, so when no serial is found, just use a default bogus one.

              3 lines of code, maybe less.

              1 Reply Last reply Reply Quote 0
              • M marcosm moved this topic from webGUI
              • FireOdoF Offline
                FireOdo
                last edited by

                Hi, what happends if Nexus i not activated? What GUI is active?

                Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                pfsense 2.8.1 CE
                Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                N 1 Reply Last reply Reply Quote 0
                • N Offline
                  netblues @FireOdo
                  last edited by

                  @fireodo No worries.
                  Actually both the new and the old are working at the same time, just on different ports.
                  The new one is more or less experimental, it will take a few more releases to reach maturity, 4 sure.

                  FireOdoF 1 Reply Last reply Reply Quote 0
                  • D Offline
                    DominikHoffmann
                    last edited by

                    I was hoping to get people to provide some constructive input on specifics that could be changed in the new GUI, in order to make it better.

                    1 Reply Last reply Reply Quote 1
                    • FireOdoF Offline
                      FireOdo @netblues
                      last edited by

                      @netblues said in Discussion of the New GUI design:

                      @fireodo No worries.
                      Actually both the new and the old are working at the same time, just on different ports.
                      The new one is more or less experimental, it will take a few more releases to reach maturity, 4 sure.

                      Thanks for the clarification.

                      Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                      SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                      pfsense 2.8.1 CE
                      Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                      M 1 Reply Last reply Reply Quote 0
                      • M Offline
                        Mission-Ghost @FireOdo
                        last edited by

                        @fireodo said in Discussion of the New GUI design:

                        The new one is more or less experimental, it will take a few more releases to reach maturity, 4 sure.

                        The press release read very differently.

                        N 1 Reply Last reply Reply Quote 0
                        • N Offline
                          netblues @Mission-Ghost
                          last edited by

                          A few issues observed

                          Haproxy, and haproxy stats should be reversed. Stats appears under configuration and is misleading.

                          monitoring seems to be completely broken.

                          All monitors are empty, no add or delete button.

                          service monitoring. Only delete button available.

                          And since I see not supported/license errors, I don't dare to change config while running rc in general.

                          1 Reply Last reply Reply Quote 0
                          • keyserK Offline
                            keyser Rebel Alliance @DominikHoffmann
                            last edited by keyser

                            @DominikHoffmann Finally got around to start testing the new UI and:

                            1: OMG the speed and response is good - MUCH MUCH faster than the old UI - very welcome

                            2: I have to agree on too much whitespace. The same information takes up too much space now and causes much scrooling.

                            3: NOT a fan of the "hidden" save button, and the fact you have to use it on all non "rules" related pages. If you make a change on something already configured, you have to remember to go to the three lines dialog and select save. It's not clearly visible when changes are made that requires saving. If you navigate away by mistake all is lost.
                            So on rules pages everything is saved as soon as you create/edit/delete it - everywhere else you have to click save otherwise your settings are lost.

                            4: I'm going to miss the ability to change a LOT of rules and then finally select commit.... A LOT!

                            I like where this is going, and I know most of the changes is really more a muscle memory training thing, so I won't comment on all the little things. But points 2-4 is more that a muscle memory thing - I think they need changing.

                            PS: I assume a lot of the missing dashboard widgets will be available at some time as well? Is too sparse as it is now.

                            Love the no fuss of using the official appliances :-)

                            1 Reply Last reply Reply Quote 0
                            • T Offline
                              tkerr
                              last edited by

                              Hi everyone! I'm the GUI team lead, and have been working on this upgrade for a while now. First, thank you for all of your feedback! Up to this point, our primary focus has been getting the new GUI and API functionally equivalent to the old GUI. With how many pages and options exist in pfSense, there are sure to be some bugs we haven't found yet, and improvements to be made to the look and feel.

                              We hear your comments about the whitespace, and are working on some better layouts. This has been complained about internally for a while, but our priority has been function over form (setting up interfaces and firewall rules are more important than looking pretty 😆).

                              More dashboard widgets are coming! We are working on widgetizing as fast as possible, we selected some of the important widgets to get started, but they will all be here soon. Some widgets are basically the same as the status pages, but several are bespoke and require us to add to the API for support.

                              If you don't like the save button being hidden, it can be changed in the settings menu (toolbox view->right-side toolbox).

                              In 26.07, the Nexus sidebar is collapsible so it should take up a lot less room.

                              Packages are also coming. Because of the way PHP works, packages basically inserted themselves into the existing code and just worked. The new architecture needed some tweaking to support package configuration, but it's mostly finished now.

                              Locking the new GUI to Netgate official hardware was not our intention (and it does work on some non-Netgate boxes), things should improve in 26.07 and future releases. We do indeed plan to replace the PHP GUI with this one, so it should be supported on all boxes.

                              We are working as fast as possible to improve the new GUI. Please continue to report any bugs you may encounter and share any feedback that you have!

                              keyserK dennypageD 3 Replies Last reply Reply Quote 6
                              • keyserK Offline
                                keyser Rebel Alliance @tkerr
                                last edited by

                                @tkerr Thank you for joining this thread, and I’ll do my utmost to help testing and trying things out, while keeping it constructive 🙏

                                I really like where this is going in terms of speed and if focus soon turns to making it more “pleasant” in screenspace and looks, this is going to be really good for pfSense👏

                                One thing - is it wise to use all ressources on starting with at one-to-one replica of the old UI? You have made some minor adjustments to keep things slightly more logical organised in 26.07s new UI, but:
                                Some of the changes - while keeping the same organisation as before - also leads to more mouseclicks and navigation in the windows to complete a task. Perhaps rethinking some of the layout in the individual features menu windows would be optimal at this time (since things are changing anyways)?

                                Love the no fuss of using the official appliances :-)

                                T 1 Reply Last reply Reply Quote 0
                                • dennypageD Offline
                                  dennypage @tkerr
                                  last edited by

                                  @tkerr said in Discussion of the New GUI design:

                                  Packages are also coming. Because of the way PHP works, packages basically inserted themselves into the existing code and just worked. The new architecture needed some tweaking to support package configuration, but it's mostly finished now.

                                  Are you doing all the package conversions? Or are package maintainers? If maintainers, is there any doc we can look at? Or source examples?

                                  FWIW, I note that one of the packages I maintain, Avahi, appears to have been converted. It’s showing up in the new UI as “mDNS”. Can we change the name back to Avahi please? I’m looking to deprecate Avahi, and I don’t want to Avahi to be confused with mDNS Bridge which is intended to replace Avahi. Thanks.

                                  1 Reply Last reply Reply Quote 0
                                  • T Offline
                                    tkerr @keyser
                                    last edited by

                                    @keyser There are a couple reasons we started with the old design.

                                    1. It's proven and tested layout. Sure it has issues, but it works.
                                    2. We don't want to change too much at one time. You mentioned your muscle memory, some users know exactly how to get where they want to be. We didn't want to throw them a large visual change and a complete layout change.
                                    3. The new GUI is very modular and much easier to change than the old one. I've always hated that the System Logs page is under Status rather than Diagnostics, and if/when we decide to change the menu around it's trivial to change the location (maybe 2 lines of code). Changing the layouts in the actual forms is a bit more complex, but still fairly trivial.

                                    @dennypage we are doing all of the package conversions, there is nothing special that you need to do. I will get the name changed.

                                    keyserK 1 Reply Last reply Reply Quote 1
                                    • keyserK Offline
                                      keyser Rebel Alliance @tkerr
                                      last edited by keyser

                                      @tkerr Noted :-)

                                      I would like to address the change with nexus and what now seems like builtin “packages”. Fx: the Avahi package that @dennypage used to maintain now seems to be builtin in Nexus and is no longer a package that can be uninstalled/removed.

                                      Why not keep everything (including coreDNS and Threatgate) as packages that can be installed/upgraded individually as needed rather than “monolithing” everything inside the Nexus package?

                                      EDIT: In fact, a good suggestion for the next release would be a focus on “modularization” for pfSense so as much as possible becomes it’s own module and can be installed/removed. Fx. If I go all in on CoreDNS, i’d like to be able to uninstall DNS Resolver and DNS forwarder. Maybe it’s also time to make KEA default and allow for 2 instances so you can run DHCP server one some interfaces, DHCP relay on other.

                                      Love the no fuss of using the official appliances :-)

                                      G 1 Reply Last reply Reply Quote 1
                                      • G Offline
                                        Gcon @keyser
                                        last edited by Gcon

                                        @netblues said in Discussion of the New GUI design:

                                        @Gcon What virtualization?

                                        Latest version of Proxmox (KVM/Qemu) with paid subscription on dual socket hardware with 256GB RAM and Mellanox 10Gig NICs. CPUs aren't the most current but can run the x86-64-v3 CPU profile fine - AVX512 not needed by any of our software just yet.

                                        @tkerr said in Discussion of the New GUI design:

                                        Locking the new GUI to Netgate official hardware was not our intention (and it does work on some non-Netgate boxes), things should improve in 26.07 and future releases. We do indeed plan to replace the PHP GUI with this one, so it should be supported on all boxes.

                                        That is welcome. The last time I bumped into some compatibility issues with virtualization was when some really old boxes could only support the x86-64-v2 spec, and one of the docker containers migrated to MongoDB 5.x which required AVX, so had to bump things up to x86-64-v3. If you are reliant on AVX512 (in x86-64-v4) for Nexus then that will be an issue, as we won't refresh hypervisors to support this for some time (I blame AI datacentres making everything unaffordable).

                                        @keyser said in Discussion of the New GUI design:

                                        EDIT: In fact, a good suggestion for the next release would be a focus on “modularization” for pfSense so as much as possible becomes it’s own module and can be installed/removed. Fx. If I go all in on CoreDNS, i’d like to be able to uninstall DNS Resolver and DNS forwarder. Maybe it’s also time to make KEA default and allow for 2 instances so you can run DHCP server one some interfaces, DHCP relay on other.

                                        Wholeheartedly support this. I installed BIND on pfSense for use as a secondary for the domain we use for the Let's Encrypt certs on our internal web tools, so if everything else goes to poo, I can still reference all the internal backup & recovery tools by DNS name instead of hunting for IP addresses. A colleague recently looked in "DNS Forwarder" and "DNS Resolver" and freaked when neither was ticked.

                                        To be frank - DNS is a mess. Looking at my pfSense box right now I have under Services: "Bind DNS Server", "DNS Forwarder" and "DNS Resolver"- so much useless clutter. To make matters worse, there are critical DNS settings in the completely separate System / General Setup.

                                        All DNS should live in one spot. Might as well be "Services / DNS". I'd put all the general stuff in there. But then you can install a package for dnsmasq (forwarding) Unbound (resolver), BIND or some other authoritative NS, then make installing of those packages mutually exclusive, and modify the options under Services / DNS to suit.

                                        Agree about KEA - it's well time to make that the only DHCP option and remove ISC DHCP. Force it on pfSense CE as a test bed to iron out any final kinks. That's what that version should be for. Concurrent server and relay makes sense if you're a DHCP server for say a captive portal for guest users, but relay for other interfaces.

                                        EDIT: This menu clutter goes much deeper than DNS though. For example "Captive Portal". I did use it YEARS ago before moving to another system. Since I am not using it - and will likely never use it - can it not be uninstalled? At least hide it in the menu. Just clutter. SNMP - that's another one. Everyone should be using SNMPv3 now. v1 and v2 should be dead. If you keep up with Cybersecurity trends - you would be nodding your heads. But the built-in SNMP menu doesn't support v3... weird. So I installed the NET-SNMP package for SNMPv3 support, and yet the baked-in "SNMP" menu item is still there. It's menu madness.

                                        1 Reply Last reply Reply Quote 1
                                        • keyserK Offline
                                          keyser Rebel Alliance @tkerr
                                          last edited by

                                          @tkerr Observed bugs in 26.07-RC - 20260801-1756:

                                          Using the new UI has several issues when attempting to create new rules:

                                          1: Attempting to add a rule from the top does not work if you have the anti-lockout setting enabled (default). Then you will be given the error "Failed to insert rule: insert rule error - unable to find insertion point.

                                          2: You cannot set a "tagged" value under advanced on rules in the new UI - sort of defeats the purpose of zero trust egress mode. You have to use the old UI to set the tagged value. It saves the rule and says success. There is just no tagged value and advanced tagged setting saved.

                                          bebdf07d-fac0-4f78-8038-d145059d4d3d-image.png

                                          Love the no fuss of using the official appliances :-)

                                          1 Reply Last reply Reply Quote 1
                                          • C Offline
                                            CarAnalogy @Mission-Ghost
                                            last edited by

                                            @Mission-Ghost I apparently don't have 5 reputation points so I can't simply click like, but I agree.

                                            Came to the forum looking for this topic.

                                            I like the idea but the dashboard is still very, very basic. The speed is indeed welcome but just about everything else, at this point, is a bit of a downgrade. I have the same bug with the traffic graph. They did seem to hit the highlights of the widgets I do use, but they don't seem to work.

                                            I will be looking in to slowly rolling out Nexus as a controller platform, as it does seem to be decent for basic monitoring, which has been a missing checkbox.

                                            I don't mean to be overly critical though, I do appreciate the reasoning and the modernization. I realize it's not near fully baked.

                                            johnpozJ 1 Reply Last reply Reply Quote 3
                                            • First post
                                              Last post
                                            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                                            Privacy Policy · Cookie Policy