Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Discussion of the New GUI design

    Scheduled Pinned Locked Moved Netgate Nexus
    57 Posts 20 Posters 3.6k Views 23 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • FireOdoF Online
      FireOdo @netblues
      last edited by

      @netblues said in Discussion of the New GUI design:

      @fireodo No worries.
      Actually both the new and the old are working at the same time, just on different ports.
      The new one is more or less experimental, it will take a few more releases to reach maturity, 4 sure.

      Thanks for the clarification.

      Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
      SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
      pfsense 2.9.0 CE
      Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

      M 1 Reply Last reply Reply Quote 0
      • M Offline
        Mission-Ghost @FireOdo
        last edited by

        @fireodo said in Discussion of the New GUI design:

        The new one is more or less experimental, it will take a few more releases to reach maturity, 4 sure.

        The press release read very differently.

        N 1 Reply Last reply Reply Quote 0
        • N Offline
          netblues @Mission-Ghost
          last edited by

          A few issues observed

          Haproxy, and haproxy stats should be reversed. Stats appears under configuration and is misleading.

          monitoring seems to be completely broken.

          All monitors are empty, no add or delete button.

          service monitoring. Only delete button available.

          And since I see not supported/license errors, I don't dare to change config while running rc in general.

          1 Reply Last reply Reply Quote 0
          • keyserK Online
            keyser Rebel Alliance @DominikHoffmann
            last edited by keyser

            @DominikHoffmann Finally got around to start testing the new UI and:

            1: OMG the speed and response is good - MUCH MUCH faster than the old UI - very welcome

            2: I have to agree on too much whitespace. The same information takes up too much space now and causes much scrooling.

            3: NOT a fan of the "hidden" save button, and the fact you have to use it on all non "rules" related pages. If you make a change on something already configured, you have to remember to go to the three lines dialog and select save. It's not clearly visible when changes are made that requires saving. If you navigate away by mistake all is lost.
            So on rules pages everything is saved as soon as you create/edit/delete it - everywhere else you have to click save otherwise your settings are lost.

            4: I'm going to miss the ability to change a LOT of rules and then finally select commit.... A LOT!

            I like where this is going, and I know most of the changes is really more a muscle memory training thing, so I won't comment on all the little things. But points 2-4 is more that a muscle memory thing - I think they need changing.

            PS: I assume a lot of the missing dashboard widgets will be available at some time as well? Is too sparse as it is now.

            Love the no fuss of using the official appliances :-)

            1 Reply Last reply Reply Quote 0
            • T Offline
              tkerr Netgate
              last edited by

              Hi everyone! I'm the GUI team lead, and have been working on this upgrade for a while now. First, thank you for all of your feedback! Up to this point, our primary focus has been getting the new GUI and API functionally equivalent to the old GUI. With how many pages and options exist in pfSense, there are sure to be some bugs we haven't found yet, and improvements to be made to the look and feel.

              We hear your comments about the whitespace, and are working on some better layouts. This has been complained about internally for a while, but our priority has been function over form (setting up interfaces and firewall rules are more important than looking pretty 😆).

              More dashboard widgets are coming! We are working on widgetizing as fast as possible, we selected some of the important widgets to get started, but they will all be here soon. Some widgets are basically the same as the status pages, but several are bespoke and require us to add to the API for support.

              If you don't like the save button being hidden, it can be changed in the settings menu (toolbox view->right-side toolbox).

              In 26.07, the Nexus sidebar is collapsible so it should take up a lot less room.

              Packages are also coming. Because of the way PHP works, packages basically inserted themselves into the existing code and just worked. The new architecture needed some tweaking to support package configuration, but it's mostly finished now.

              Locking the new GUI to Netgate official hardware was not our intention (and it does work on some non-Netgate boxes), things should improve in 26.07 and future releases. We do indeed plan to replace the PHP GUI with this one, so it should be supported on all boxes.

              We are working as fast as possible to improve the new GUI. Please continue to report any bugs you may encounter and share any feedback that you have!

              keyserK dennypageD 3 Replies Last reply Reply Quote 6
              • keyserK Online
                keyser Rebel Alliance @tkerr
                last edited by

                @tkerr Thank you for joining this thread, and I’ll do my utmost to help testing and trying things out, while keeping it constructive 🙏

                I really like where this is going in terms of speed and if focus soon turns to making it more “pleasant” in screenspace and looks, this is going to be really good for pfSense👏

                One thing - is it wise to use all ressources on starting with at one-to-one replica of the old UI? You have made some minor adjustments to keep things slightly more logical organised in 26.07s new UI, but:
                Some of the changes - while keeping the same organisation as before - also leads to more mouseclicks and navigation in the windows to complete a task. Perhaps rethinking some of the layout in the individual features menu windows would be optimal at this time (since things are changing anyways)?

                Love the no fuss of using the official appliances :-)

                T 1 Reply Last reply Reply Quote 0
                • dennypageD Offline
                  dennypage @tkerr
                  last edited by

                  @tkerr said in Discussion of the New GUI design:

                  Packages are also coming. Because of the way PHP works, packages basically inserted themselves into the existing code and just worked. The new architecture needed some tweaking to support package configuration, but it's mostly finished now.

                  Are you doing all the package conversions? Or are package maintainers? If maintainers, is there any doc we can look at? Or source examples?

                  FWIW, I note that one of the packages I maintain, Avahi, appears to have been converted. It’s showing up in the new UI as “mDNS”. Can we change the name back to Avahi please? I’m looking to deprecate Avahi, and I don’t want to Avahi to be confused with mDNS Bridge which is intended to replace Avahi. Thanks.

                  1 Reply Last reply Reply Quote 0
                  • T Offline
                    tkerr Netgate @keyser
                    last edited by

                    @keyser There are a couple reasons we started with the old design.

                    1. It's proven and tested layout. Sure it has issues, but it works.
                    2. We don't want to change too much at one time. You mentioned your muscle memory, some users know exactly how to get where they want to be. We didn't want to throw them a large visual change and a complete layout change.
                    3. The new GUI is very modular and much easier to change than the old one. I've always hated that the System Logs page is under Status rather than Diagnostics, and if/when we decide to change the menu around it's trivial to change the location (maybe 2 lines of code). Changing the layouts in the actual forms is a bit more complex, but still fairly trivial.

                    @dennypage we are doing all of the package conversions, there is nothing special that you need to do. I will get the name changed.

                    keyserK 1 Reply Last reply Reply Quote 1
                    • keyserK Online
                      keyser Rebel Alliance @tkerr
                      last edited by keyser

                      @tkerr Noted :-)

                      I would like to address the change with nexus and what now seems like builtin “packages”. Fx: the Avahi package that @dennypage used to maintain now seems to be builtin in Nexus and is no longer a package that can be uninstalled/removed.

                      Why not keep everything (including coreDNS and Threatgate) as packages that can be installed/upgraded individually as needed rather than “monolithing” everything inside the Nexus package?

                      EDIT: In fact, a good suggestion for the next release would be a focus on “modularization” for pfSense so as much as possible becomes it’s own module and can be installed/removed. Fx. If I go all in on CoreDNS, i’d like to be able to uninstall DNS Resolver and DNS forwarder. Maybe it’s also time to make KEA default and allow for 2 instances so you can run DHCP server one some interfaces, DHCP relay on other.

                      Love the no fuss of using the official appliances :-)

                      G 1 Reply Last reply Reply Quote 1
                      • G Offline
                        Gcon @keyser
                        last edited by Gcon

                        @netblues said in Discussion of the New GUI design:

                        @Gcon What virtualization?

                        Latest version of Proxmox (KVM/Qemu) with paid subscription on dual socket hardware with 256GB RAM and Mellanox 10Gig NICs. CPUs aren't the most current but can run the x86-64-v3 CPU profile fine - AVX512 not needed by any of our software just yet.

                        @tkerr said in Discussion of the New GUI design:

                        Locking the new GUI to Netgate official hardware was not our intention (and it does work on some non-Netgate boxes), things should improve in 26.07 and future releases. We do indeed plan to replace the PHP GUI with this one, so it should be supported on all boxes.

                        That is welcome. The last time I bumped into some compatibility issues with virtualization was when some really old boxes could only support the x86-64-v2 spec, and one of the docker containers migrated to MongoDB 5.x which required AVX, so had to bump things up to x86-64-v3. If you are reliant on AVX512 (in x86-64-v4) for Nexus then that will be an issue, as we won't refresh hypervisors to support this for some time (I blame AI datacentres making everything unaffordable).

                        @keyser said in Discussion of the New GUI design:

                        EDIT: In fact, a good suggestion for the next release would be a focus on “modularization” for pfSense so as much as possible becomes it’s own module and can be installed/removed. Fx. If I go all in on CoreDNS, i’d like to be able to uninstall DNS Resolver and DNS forwarder. Maybe it’s also time to make KEA default and allow for 2 instances so you can run DHCP server one some interfaces, DHCP relay on other.

                        Wholeheartedly support this. I installed BIND on pfSense for use as a secondary for the domain we use for the Let's Encrypt certs on our internal web tools, so if everything else goes to poo, I can still reference all the internal backup & recovery tools by DNS name instead of hunting for IP addresses. A colleague recently looked in "DNS Forwarder" and "DNS Resolver" and freaked when neither was ticked.

                        To be frank - DNS is a mess. Looking at my pfSense box right now I have under Services: "Bind DNS Server", "DNS Forwarder" and "DNS Resolver"- so much useless clutter. To make matters worse, there are critical DNS settings in the completely separate System / General Setup.

                        All DNS should live in one spot. Might as well be "Services / DNS". I'd put all the general stuff in there. But then you can install a package for dnsmasq (forwarding) Unbound (resolver), BIND or some other authoritative NS, then make installing of those packages mutually exclusive, and modify the options under Services / DNS to suit.

                        Agree about KEA - it's well time to make that the only DHCP option and remove ISC DHCP. Force it on pfSense CE as a test bed to iron out any final kinks. That's what that version should be for. Concurrent server and relay makes sense if you're a DHCP server for say a captive portal for guest users, but relay for other interfaces.

                        EDIT: This menu clutter goes much deeper than DNS though. For example "Captive Portal". I did use it YEARS ago before moving to another system. Since I am not using it - and will likely never use it - can it not be uninstalled? At least hide it in the menu. Just clutter. SNMP - that's another one. Everyone should be using SNMPv3 now. v1 and v2 should be dead. If you keep up with Cybersecurity trends - you would be nodding your heads. But the built-in SNMP menu doesn't support v3... weird. So I installed the NET-SNMP package for SNMPv3 support, and yet the baked-in "SNMP" menu item is still there. It's menu madness.

                        1 Reply Last reply Reply Quote 1
                        • keyserK Online
                          keyser Rebel Alliance @tkerr
                          last edited by

                          @tkerr Observed bugs in 26.07-RC - 20260801-1756:

                          Using the new UI has several issues when attempting to create new rules:

                          1: Attempting to add a rule from the top does not work if you have the anti-lockout setting enabled (default). Then you will be given the error "Failed to insert rule: insert rule error - unable to find insertion point.

                          2: You cannot set a "tagged" value under advanced on rules in the new UI - sort of defeats the purpose of zero trust egress mode. You have to use the old UI to set the tagged value. It saves the rule and says success. There is just no tagged value and advanced tagged setting saved.

                          bebdf07d-fac0-4f78-8038-d145059d4d3d-image.png

                          Love the no fuss of using the official appliances :-)

                          1 Reply Last reply Reply Quote 1
                          • C Offline
                            CarAnalogy @Mission-Ghost
                            last edited by

                            @Mission-Ghost I apparently don't have 5 reputation points so I can't simply click like, but I agree.

                            Came to the forum looking for this topic.

                            I like the idea but the dashboard is still very, very basic. The speed is indeed welcome but just about everything else, at this point, is a bit of a downgrade. I have the same bug with the traffic graph. They did seem to hit the highlights of the widgets I do use, but they don't seem to work.

                            I will be looking in to slowly rolling out Nexus as a controller platform, as it does seem to be decent for basic monitoring, which has been a missing checkbox.

                            I don't mean to be overly critical though, I do appreciate the reasoning and the modernization. I realize it's not near fully baked.

                            johnpozJ 1 Reply Last reply Reply Quote 3
                            • johnpozJ Offline
                              johnpoz LAYER 8 Global Moderator @CarAnalogy
                              last edited by

                              @CarAnalogy said in Discussion of the New GUI design:

                              I apparently don't have 5 reputation points

                              You do now - I went back and gave you on previous post, your at 7 now ;)

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 26.07 | Lab VMs 2.9.0, 26.07

                              1 Reply Last reply Reply Quote 0
                              • D Offline
                                danielvanderwal
                                last edited by

                                Hello Netgate team, I find the interface super fast, but as mentioned in the above comments, it's still very basic. Logging into the firewall on a mobile device is also pretty difficult. I hope these minor issues will be resolved soon. Keep up the great work on the API and GUI redesign!

                                • The login dialog does not fit in the mobile viewport.
                                • The breakpoints for the widgets are incorrect and result in overlapping.
                                • I'm running the latest version: 26.07-RELEASE - 20260807-1926.

                                pfsense_8443_login(Pixel 8).png
                                Screenshot 2026-08-14.png

                                1 Reply Last reply Reply Quote 0
                                • S Offline
                                  SlackerDude
                                  last edited by

                                  I just performed the upgrade this morning, and I still have the same interface. Before anyone asks, here are most of the specs on my hardware:
                                  Intel(R) Pentium(R) Silver N6005 @ 2.00GHz
                                  Current: 3093 MHz, Max: 1996 MHz
                                  4 CPUs : 1 package(s) x 4 core(s)
                                  AES-NI CPU Crypto: Yes (active)
                                  IPsec-MB Crypto: Yes (active)
                                  QAT Crypto: No
                                  32GB RAM

                                  System Status shows that pfnet-controller is not running, and I do not seem to be able to start it manually.

                                  That being said, while I cannot provide feedback on the appearance, I can report that the overall system feels a bit faster.

                                  tinfoilmattT S 2 Replies Last reply Reply Quote 0
                                  • tinfoilmattT Offline
                                    tinfoilmatt LAYER 8 @SlackerDude
                                    last edited by

                                    Netgate Nexus Options in the pfSense Plus GUI

                                    block out log on { ix0 } inet from any to any
                                    block out log on { ix0 } inet6 from any to any

                                    1 Reply Last reply Reply Quote 0
                                    • F Offline
                                      fdhabhar
                                      last edited by fdhabhar

                                      I was reading the announcement here. It says "Our goal is for everyone to be using the new GUI by the end of the year" but does that mean the PHP UI will be going away with the first 2027 release? Or just that Netgate would like users to be trying it by the end of the year? Because I feel like Nexus has a long way to go, at least quality-of-life wise. For example, When creating a new user in the PHP UI you can create a new certificate for that user as part of the process. Nexus doesn't offer that as far as I can tell. Is there a public punchlist of features to be added / bugs to fix available, or do we use this forum for that? https://www.netgate.com/blog/the-new-gui-for-pfsense-plus#:~:text=Our%20goal%20is%20for%20everyone%20to%20be%20using%20the%20new%20GUI%20by%20the%20end%20of%20the%20year
                                      php.png nexus.png

                                      T 1 Reply Last reply Reply Quote 0
                                      • T Offline
                                        tkerr Netgate @fdhabhar
                                        last edited by

                                        @fdhabhar This forum is the best place for now, I will talk to someone about getting a public redmine (I've been adding these to the internal one manually). We don't have a hard timeline for the switchover yet, but I would imagine a few more releases before we're fully ready. The faster people find these issues, the faster we can fix them.

                                        As for this specific issue, it should be fairly easy to implement (we already have a form for the certificates, we already have a certificate API, it's just a matter of gluing that together with the user form). We are actually planning to do a Nexus update very soon, fixing a few UI bugs, some VM support issues, etc. Since Nexus is a package, we can update it independently much more often.

                                        F tinfoilmattT 2 Replies Last reply Reply Quote 1
                                        • F Offline
                                          fdhabhar @tkerr
                                          last edited by

                                          @tkerr I can't thumbs up with <5 rep but thanks for the reply. Looking forward to watching this grow and evolve, keep up the hard work!

                                          1 Reply Last reply Reply Quote 2
                                          • tinfoilmattT Offline
                                            tinfoilmatt LAYER 8 @tkerr
                                            last edited by

                                            Can somebody give Trevor a Netgate forum badge?

                                            block out log on { ix0 } inet from any to any
                                            block out log on { ix0 } inet6 from any to any

                                            johnpozJ 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                                            Privacy Policy · Cookie Policy